[OT] Virus turns files and folders into exe?

English support forum

Moderators: Hacker, petermad, Stefan2, white

Post Reply
ismanpa
Junior Member
Junior Member
Posts: 31
Joined: 2005-02-17, 16:21 UTC

[OT] Virus turns files and folders into exe?

Post by *ismanpa »

Hello,

This has happened for the second time!

I transfer files and directories between two computers via a USB drive. All files that were not in directories were turned into exe files as wll as two directories with the names of '11' and '12' (named after the classes of my students).

Please, help.
User avatar
Hacker
Moderator
Moderator
Posts: 13144
Joined: 2003-02-06, 14:56 UTC
Location: Bratislava, Slovakia

Post by *Hacker »

Hello ismanpa,
A log file would be helpful here.

Roman
Mal angenommen, du drückst Strg+F, wählst die FTP-Verbindung (mit gespeichertem Passwort), klickst aber nicht auf Verbinden, sondern fällst tot um.
User avatar
MVV
Power Member
Power Member
Posts: 8711
Joined: 2008-08-03, 12:51 UTC
Location: Russian Federation

Post by *MVV »

Looks more like some virus puts its EXE copies to USB stick... Did files keep original contents?
User avatar
comrade
Junior Member
Junior Member
Posts: 12
Joined: 2014-10-26, 03:34 UTC
Location: Russian Federation

Post by *comrade »

A Process Monitor trace will show what is running the files. Get Process Monitor from http://www.sysinternals.com/
User avatar
karlchen
Power Member
Power Member
Posts: 4605
Joined: 2003-02-06, 22:23 UTC
Location: Germany

Post by *karlchen »

Hello, ismanpa.

MVV is right. Your system has been infected by some malware. Cf. virus creates a .EXE file for each folder name. It leads here: Virus Issue foldername.exe

Please, clean your machine and mark this thread with [Total Commander acquitted].

Cheers,
Karl
ismanpa
Junior Member
Junior Member
Posts: 31
Joined: 2005-02-17, 16:21 UTC

Post by *ismanpa »

Hello,

Thank you everyone.

Arira found viruses; Malwarebytes too as well as ClamWin (the last one only reported they were inaccessible otherwise the files were the same in all three)(Sadly, Emsisoft Emergency Kit did not detect the flash drive).

I monitor my computers regularly and there has been no report about anything mal...

I have noticed that this happened before once too after using the flash drive on a Linux Mint machine which is very strange. I will keep watching this.

The drive is now formatted.

Thank you all for the help!
User avatar
karlchen
Power Member
Power Member
Posts: 4605
Joined: 2003-02-06, 22:23 UTC
Location: Germany

Post by *karlchen »

Hello, IsManPa,

you tell that several AV products detected malware on your machine. but you do not say that the same AV products cleaned the machine, i.e. reported success on eliminating the malware.
As the malware has infected the machine, it will not go away on its own accord. It must be removed.
Cleaning the affected pendrive alone is not sufficient. The malware is still lurking somewhere and the symptoms will return confirming the infection has not been cured.
And I highly doubt that it was a Linux Mint system which brought the malware to your pendrive. Unless, well, unless, someone managed to make a Windows malware function properly on Wine and provided the Linux Mint machine had Wine in use.

Cheers,
Karl
ismanpa
Junior Member
Junior Member
Posts: 31
Joined: 2005-02-17, 16:21 UTC

Post by *ismanpa »

Hello everybody,

I have cleaned the computers and formatted the pen drive. I also think it is highly improbable that a Linux machine infected the drive.

How do I mark Total Commander acquitted?

Thank you!
User avatar
karlchen
Power Member
Power Member
Posts: 4605
Joined: 2003-02-06, 22:23 UTC
Location: Germany

Post by *karlchen »

Hi, ismanpa.

The request to mark Total Commander acquitted was merely a joke. :wink:
So kindly ignore it.

Cheers,
Karl
ismanpa
Junior Member
Junior Member
Posts: 31
Joined: 2005-02-17, 16:21 UTC

Post by *ismanpa »

Ok, Karl :)

If you had put a smiley after it, I would have guessed it perhaph :)

I have found the cause of infection: I gave the drive to a colleague of mine to copy it.

Sorry for the trouble!
karlchen wrote:Hi, ismanpa.

The request to mark Total Commander acquitted was merely a joke. :wink:
So kindly ignore it.

Cheers,
Karl
Post Reply