Jump to content
Sign In to follow this  
JP Schriefer

Is this really a virus?

14 posts in this topic Last Reply

Highlighted Posts

Posted:
Last Online:  
 

Somedays ago I downloaded some things on STEX and everything works fine. Today I was doing a back up to my Plugins when Avast warning these three files in the red rectangle as virus. Seeing I downloaded them in 16/07 I know it's from here. Do you know if it is really a virus and I can delete it? Because they are .EXE files and the BATs I downloaded was not .EXE. And they are the same file as you can see, it's like if I had downloaded it three times, it's really strange.

 

ntAWXm2.png


  Edited by Cyclone Boom  

Topic moved (seeing as this is not directly about SC4).

Imagem

"If you fall I'll be there"
                     -The Floor

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

It might be a virus; your web browser should have a history of all downloads to your computer and their source.

 

I would verify the source and check where it was from and what it was supposed to be. In the meantime I'd send them to quarantine or the Recycle Bin until you know for sure, just to be safe.


My MD on SC4Devotion (updated first)
And Here on Simtropolis
NAM Associate

"My mother always told me, 'Elwood, you can be two things in this world...you can either be Oh So Smart, or Oh So Pleasant.'

Well, for years I was smart. I recommend pleasant."
-Elwood P. Dowd, Harvey

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

The prefix "IMG_xxxx" looks like the format of an image taken from a camera. Though I'd be very careful about this. Viruses can sometimes aim to make a file appear as another type, when it's clearly an application. Seeing as you have the Windows setting "hide extensions for known file types" enabled, it'd be hard to change the extension by accident.

Have you tried uploading it to VirusTotal? This will scan the file with multiple virus scanners to give a second opinion.


Quick Links

“SimCity 4 is not just a game, but a tool driven by our own imagination and creativity.”

Buy me a coffee

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Have you tried scanning your computer with a malware scanner? If the files were malware, then they'd most likely pop up during the scan - along with the option to delete them.


N0icqd8.jpg

“The deeper I go into myself the more I realize that I am my own enemy.”  ― Floriano Martins         Member of the NAM Team

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Funny files should at least be quarantined until you can get more information.  A screen shot should simply be a PNG or BMP.  I would under no circumstances open them except under special circumstances off-line.

  • Like 1

Beware: Emancipated user.  No Windoze for me.
The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
If you always do what you've always done, you'll mostly get what you've always got.
JohnNewSig.gif
"We have met the enemy, and he is us" - Walt Kelly

Come join us at the Moose Factory

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

They look inherently suspicious and if Avast says they are malicious I would believe it. If Avast has a built-in mechanism to remove such things, use that. Otherwise you can try deleting them manually although that may not completely or permanently remove any damage, depending on how nasty whatever you've got is.

 

If you know or can figure out which specific STEX files you downloaded that day, do please notify the STEX staff about it so they can investigate. If an offending file can be identified, it will be removed.

 

Meanwhile it is also possible that this is a symptom of something which you previously caught from elsewhere, that infected those files after they were downloaded. Note that they were last modified more than 15 hours after the other exe files you have in that folder. Did you download more stuff from the STEX at 2 PM on the 16th, or was it all the night of the 15th?


If you always take the same road, you will never see anything new.
If you can read this, you deserve a cookie.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Do you have a history of which files you downloaded on this day and which sites you visited, otherwise it's impossible to be 100% sure to find the cause.


The best things in life are not the ones you get for money (Albert Einstein)

The BLSMM Thread: Where SC4 Discoveries Abound

The answer to all your questions is: Ask Paul Pedriana

STEX-Rules

Share this post


Link to post
Share on other sites
  • Original Poster
  • Posted:
    Last Online:  
     

    Just clarifying,

     

    I downloaded again all files from STEX I downloaded that day and no virus was found \o/, the virus was really in the same time I was on STEX (16 july, 14:07). The other files you saw in image are 'last modify' in 15 july because I just paste them there from my pen drive, I have them a long time.

    So, I was checking the historic when I noticed that in the same time I was on STEX I was in a suspicious chat on Facebook, a random user (looks fake) sent me a message with a file in the chat, I didn't opened it, but I'm almost sure it saved on my computer automatically. The last folder I downloadede something was in Plugin folder so the virus installed there, I think that's the unique explanation for it then.

    Ckecked in the site Cyclone Boom said and it says it's a dangerous file indeed.

    Thank all of you for your attention :)

    and sorry about the confusion :D


    Imagem

    "If you fall I'll be there"
                         -The Floor

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    It's a good idea to turn off automatic downloads.  As in, the dialogue window should pop up and you manually name and save every file.  That way nothing sneaks in.

     

    I also recommend Malwarebytes as a secondary anti-virus program.

    • Like 2

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    Couldn't agree more.  Nothing, but nothing, is automatic on my system when it comes to the Internet, not even emergency fixes.  If I don't control the process nothing gets on my machine.


    Beware: Emancipated user.  No Windoze for me.
    The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

    Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
    Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
    If you always do what you've always done, you'll mostly get what you've always got.
    JohnNewSig.gif
    "We have met the enemy, and he is us" - Walt Kelly

    Come join us at the Moose Factory

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    And I cannot stress often enough how important it is to deactivate the option "hide extension for known file types". I could slap every single person responsible for this stupid and dangerous default setting (!) to the moon and back a hundred times, and then some. This is nothing but an open invitation to all kinds of fraud, trickery, and computer crime, as is an automatic donwload function or any other kind of auto-run or auto-execution feature. Carefully avoiding these can be more important than an AV software because it prevents problems from occurring in the first place rather than trying to fix what has already happened.

    • Like 3

    -=| You can choose a ready guide in some celestial voice ||| If you choose not to decide you still have made a choice |=-
    -=| You can choose from phantom fears and kindness that can kill ||| I will choose a path that's clear - I will choose free will |=-

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    ^ Well said, my (now) fine feathered dinosaur.  One of the things I like about Linux is the fact that anything in a file name after a dot is treated the same as the rest of the file name.  It is only some application software that is concerned with silly external "file types".  The system looks at the data, not at the name.


    Beware: Emancipated user.  No Windoze for me.
    The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

    Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
    Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
    If you always do what you've always done, you'll mostly get what you've always got.
    JohnNewSig.gif
    "We have met the enemy, and he is us" - Walt Kelly

    Come join us at the Moose Factory

    Share this post


    Link to post
    Share on other sites
  • Original Poster
  • Posted:
    Last Online:  
     

    Actually I only active automatic download when I need files in STEX. By an unlucky last time that happened.


    Imagem

    "If you fall I'll be there"
                         -The Floor

    Share this post


    Link to post
    Share on other sites
    Posted:
    Last Online:  
     

    Strange.  In any case, I hope you won't do any more automatic downloading.


    Beware: Emancipated user.  No Windoze for me.
    The teacher opens the door but the student must enter himself. - Ancient Chinese Saying

    Every minute of hate in which one indulges oneself is sixty seconds of happiness lost.
    Music expresses that which cannot be put into words and that which cannot remain silent. -- Victor Hugo
    If you always do what you've always done, you'll mostly get what you've always got.
    JohnNewSig.gif
    "We have met the enemy, and he is us" - Walt Kelly

    Come join us at the Moose Factory

    Share this post


    Link to post
    Share on other sites

    Sign In or register to comment...

    To comment in reply, you must be a community member

    Sign In  

    Already have an account? Sign in here.

    Sign In Now

    Create an Account  

    Sign up to join our friendly community. It's easy!  

    Register a New Account

    Sign In to follow this  

    • Recently Browsing   0 members

      No registered users viewing this page.

    ×

    Thank You for the Continued Support!

    Simtropolis depends on donations to fund site maintenance costs.
    Without your support, we just would not be in our 24th year online!  You really help make this a great community. *:thumb:

    But we still need your support to stay online. If you're able to, please consider a donation to help us stay up and running. This helps sustain a platform where we can share our community creations for years to come.

    Make a Donation, Get a Gift!

    Expand your city with the best from the Simtropolis Exchange.
    Make a Donation and get one or all three discs today!

    STEX Collections

    By way of a "Thank You" gift, we'd like to send you our STEX Collector's DVD. It's some of the best buildings, lots, maps and mods collected for you over the years. Check out the STEX Collections for more info.

    Each donation helps keep Simtropolis online, open and free!

    Thank you for reading and enjoy the site!

    More About STEX Collections