Gaming [Threat Detected]

[M]artin

.
OP
Member
Joined
Nov 7, 2006
Messages
3,658
Trophies
0
Age
34
XP
995
Country
United States
A few days ago, a friend of mine plugged in her flash drive into my desktop. ESET instantly popped up with the message below:

2nc47xf.png


She's accessed her flash drive through my desktop on a number of occasions and ESET never gave us any problems. I choose "Delete" and ESET hasn't been giving us any problems since then. However, I'm still curious as to what it was on that flash drive that caused this, and should I be concerned?
 

Lee79

Hyper...Active...Team Fortress 2 Addict
Member
Joined
Jul 29, 2007
Messages
920
Trophies
0
Age
44
Location
ctf_2fort
Website
steamcommunity.com
XP
240
Country
Autorun.inf (An INF file or Setup Information file is a plain text file used by Microsoft Windows for installation of software and drivers.) is a autorun file so when you plug it in it will auto run some software and try and install it on your PC could be legit or could be a virus so NOD32 flag it to protect your computer.
 

[M]artin

.
OP
Member
Joined
Nov 7, 2006
Messages
3,658
Trophies
0
Age
34
XP
995
Country
United States
da_head said:
well if it detected it, then there should be no worries amirite?

but wth is eset? never heard of it.

ESET Software. I'm currently using ESET Smart Security.

QUOTE(Lee79 @ May 17 2009, 03:14 PM) Autorun.inf (An INF file or Setup Information file is a plain text file used by Microsoft Windows for installation of software and drivers.) is a autorun file so when you plug it in it will auto run some software and try and install it on your PC could be legit or could be a virus so NOD32 flag it to protect your computer.
Thanks. I flagged it. I have a flash drive similar to the one she used and it never contained any embedded Autorun software or anything like that IIRC, most likely not safe.
 

Salamantis

Well-Known Member
Member
Joined
Feb 20, 2007
Messages
1,942
Trophies
0
XP
397
Country
Canada
da_head said:
well if it detected it, then there should be no worries amirite?

but wth is eset? never heard of it.
ESET is the company that makes Smart Security and NOD32.

EDIT: Martin beat me by a few seconds, damn
tongue.gif
 

Lee79

Hyper...Active...Team Fortress 2 Addict
Member
Joined
Jul 29, 2007
Messages
920
Trophies
0
Age
44
Location
ctf_2fort
Website
steamcommunity.com
XP
240
Country
If you have a copy of the file "Autorun.inf" you can open it with Notepad and it should tell you the files it is trying to install.

For example this Autorun.inf file on my PC's HDD (i did a search for "*.inf" files the * is used as a wildcard, any name) looks like this when I open it with notepad

Code:
[autorun]
icon=App.ico
open=CodecInstaller.exe

Which means it auto runs the CodecInstaller.exe when it is executed
 

FlatFrogger

Well-Known Member
Member
Joined
Apr 20, 2007
Messages
291
Trophies
0
Age
113
Website
Visit site
XP
161
Country
Lee79 said:
If you have a copy of the file "Autorun.inf" you can open it with Notepad and it should tell you the files it is trying to install.

For example this Autorun.inf file on my PC's HDD (i did a search for "*.inf" files the * is used as a wildcard or any name) looks like this when I open it with notepad

Code:
[autorun]
icon=App.ico
open=CodecInstaller.exe

Which means it auto runs the CodecInstaller.exe when it is executed


This.

Its worth finding out of if its a real threat or its a false detect, if its the latter submit it for analysis.
 

Law

rip ninjacat that zarcon made me
Member
Joined
Aug 14, 2007
Messages
4,128
Trophies
0
Age
32
Location
‭jerkland
Website
www.twitch.tv
XP
334
Country
I remember something similar that was happening on the college PCs, whenever you would put a flashdrive in it would copy an autorun.inf file and a folder onto it, and then when you placed the flashdrive into another computer it would copy the autorun.inf and the folder somewhere onto the hard drive. Cycle repeats, thousands of computers infected. I think it was rather harmless, though.

Find out where else your friend has been using their flashdrive, those computers might still be infected. I remember my AVG was bitching at me for a while about it, literally everytime I got home from college and used my flashdrive in my laptop. Stopped using my flashdrive at college, never happened again.
 

zeromac

Finally reached 1000 posts EXACTLY
Member
Joined
Mar 7, 2009
Messages
2,192
Trophies
0
Age
27
Location
Earth
Website
Visit site
XP
272
Country
wait.. im not trying to freak you out our anything but wasn't that the april 1st supposed virus? it could spread by flash drive and when u plug in a flash drive into ur comp there would mysterysly be another folder that would instantly open
 

moodswinger

Well-Known Member
Member
Joined
Sep 6, 2008
Messages
237
Trophies
1
Age
34
XP
128
Country
@ zeromac, I think we need 1 more evidence to confirm that, did the icon of the flash drive turned into a "folder" icon? Cause if it did, it probably is the Conficker worm.
 

xcalibur

Gbatemp's Chocolate Bear
Member
Joined
Jun 2, 2007
Messages
3,163
Trophies
0
Age
33
Location
Sacred Heart
XP
727
Country
Law said:
I remember something similar that was happening on the college PCs, whenever you would put a flashdrive in it would copy an autorun.inf file and a folder onto it, and then when you placed the flashdrive into another computer it would copy the autorun.inf and the folder somewhere onto the hard drive. Cycle repeats, thousands of computers infected. I think it was rather harmless, though.

Find out where else your friend has been using their flashdrive, those computers might still be infected. I remember my AVG was bitching at me for a while about it, literally everytime I got home from college and used my flashdrive in my laptop. Stopped using my flashdrive at college, never happened again.

Yeah I had that same one only it disallowed access to task manager and folder options and it duplicated each folder by creating a shortcut to itself inside the folder.
If it has "new folder.ink" at the root, its probably this.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Psionic Roshambo @ Psionic Roshambo:
    Batman joined the Trans Justice League
    +2
  • Sicklyboy @ Sicklyboy:
    based af
    +2
  • Sonic Angel Knight @ Sonic Angel Knight:
    Forget the base, get on the roof.
  • K3Nv2 @ K3Nv2:
    Is that a bat in your buckle or are you just happy to have me
  • Psionic Roshambo @ Psionic Roshambo:
    Wonder "Woman" lol you wonder if they are a woman?
  • Psionic Roshambo @ Psionic Roshambo:
    The Riddler has questions...
  • K3Nv2 @ K3Nv2:
    Played a little of snow day glad I didn't spend $30
  • K3Nv2 @ K3Nv2:
    It's asthetic is okay maybe a good $10 grab
  • Psionic Roshambo @ Psionic Roshambo:
    Lol is it a game about doing cocaine?
  • K3Nv2 @ K3Nv2:
    Probably in pvp
  • Psionic Roshambo @ Psionic Roshambo:
    I tried Balders Gate II on the PS2 a few minutes ago, not bad lol
  • Psionic Roshambo @ Psionic Roshambo:
    My back catalog of games is like that scene at the end of Indiana Jones where the arc of the covenant is being stored in a giant ass warehouse
  • K3Nv2 @ K3Nv2:
    At least I can will my game catalog to family members
    +1
  • K3Nv2 @ K3Nv2:
    It's your problem now bitches
  • Psionic Roshambo @ Psionic Roshambo:
    Put it in your will that in order to receive any money they have to beat certain games, hard games and super shitty games...
  • Psionic Roshambo @ Psionic Roshambo:
    Say 20 bucks per Ninja Gaiden on the NES lol 60 bucks for all 3
  • Psionic Roshambo @ Psionic Roshambo:
    People you like "Beat level 1 of Ms Pacman" lol
  • K3Nv2 @ K3Nv2:
    Hello kitty ds is required
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Beat Celebrity Death Match on the PS1 omg tried it earlier today .... Absolutely trash
  • Psionic Roshambo @ Psionic Roshambo:
    Like -37 out of 10
  • Psionic Roshambo @ Psionic Roshambo:
    One of the worst games I have ever played
  • K3Nv2 @ K3Nv2:
    Make them rank up every cod game out
  • K3Nv2 @ K3Nv2:
    "Now I know why he took his own life"
    K3Nv2 @ K3Nv2: "Now I know why he took his own life"