Author Topic: A possible virus!!  (Read 1954 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
A possible virus!!
« on: July 19, 2016, 03:12:20 AM »
Hello people. Yesterday, I went to a photocopying business to make a reparation. I put my pendrive in a PC which is used by many people, that is many pendrives are put there. When I got home, I put my pendrive in my PC and I realized that all files had became in shortcuts. I had already seen this problem and I knew that it was by a virus. I decided to scan the pendrive with the Avast antivirus but it didn't found nothing. Thus, I proceeded to open "cmd.exe" to see the hidden files in my pendrive and I found a strange file whose name is:

radB5A02.tmp.gpast.vbs

All shortcurts refer to it!! Is it a virus?

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: A possible virus!!
« Reply #1 on: July 19, 2016, 05:22:56 AM »
Possibly; you can submit the file to VirusTotal.org for testing.


Download MCShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives

Plug in the drive and McShield will start a scan
Select logs and then copy/paste it to your next post
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: A possible virus!!
« Reply #2 on: July 19, 2016, 07:04:07 AM »
It is not a virus but a trojan.
Trojan-Dropper.VBS.Agent

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: A possible virus!!
« Reply #3 on: July 19, 2016, 10:14:59 AM »
Possibly; you can submit the file to VirusTotal.org for testing.
He means   www.virustotal.com


REDACTED

  • Guest
Re: A possible virus!!
« Reply #4 on: July 19, 2016, 03:16:29 PM »
Hello, thanks for your answers! I did you said me, dbrisendine, and McShield detected a virus. The analisis log is:

MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2016.2.21.1 / Windows 7 <<<


19/07/2016 10:03:13 > Unidad G: - análisis comenzó (MAURO ~7617 MB, FAT32 memoria flash )...

>>> G:\autorun.inf > Sospechoso > Renombrado. (MD5: 224afb5b1fc646f14d9ad95755a71f82)


=> Archivos sospechosos : 1/1 renombrado.

____________________________________________

::::: Tiempo del análisis: 2min 29seg ::::::
____________________________________________