• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Folder named Virus

Joined
Oct 9, 2020
Messages
14 (0.01/day)
Processor Ryzen 3700x
Motherboard Gigabyte B450 Aorus Pro
Memory Corsair Vengeance Pro 16GB 3200MHz
Video Card(s) RTX 2070
Display(s) 35" Ultrawide 4K Aoc Agon AG352UCG6
Mouse Logitech G502 Proteus Spectrum
Keyboard Razer Ornata Chroma
Software Win 10 x64
Hello. I hope im not In the wrong section. I found by accident a folder named Virus on my android phone. It was created on 8th January 2021. Inside there are many files called deletme_01_08_01_30 and they all have exactly 50mb. I use my phone only for yt and spotify. I did a scan with Malwarebytes, Kaspersky and ESET for android and the result showed no infected files. But this is so weird having a folder called Virus and some suspicious files..I connected the phone to a older laptop that I dont use anymore and scanned the files on virustotal.com and the files were infected. I didnt find not even one result on google about someone having a folder named virus. This is so weird. I regulary clean my phone for junk files and folders and this folder wasnt there. What do you guys think about all of this?
 

Attachments

  • Screenshot-20210116-013335.png
    Screenshot-20210116-013335.png
    102.7 KB · Views: 91
Joined
Aug 15, 2016
Messages
486 (0.17/day)
Processor Intel i7 4770k
Motherboard ASUS Sabertooth Z87
Cooling BeQuiet! Shadow Rock 3
Memory Patriot Viper 3 RedD 16 GB @ 1866 MHz
Video Card(s) XFX RX 480 GTR 8GB
Storage 1x SSD Samsung EVO 250 GB 1x HDD Seagate Barracuda 3 TB 1x HDD Seagate Barracuda 4 TB
Display(s) AOC Q27G2U QHD, Dell S2415H FHD
Case Cooler Master HAF XM
Audio Device(s) Magnat LZR 980, Razer BlackShark V2, Altec Lansing 251
Power Supply Corsair AX860
Mouse Razer DeathAdder V2
Keyboard Razer Huntsman Tournament Edition
Software Windows 10 Pro x64
Open the file in a hex editor and read the header to know with what you're dealing with. Could be an application, compressed file, etc. Post a screenshot of the first 4 bytes.

Edit: If you want, send me one of those files in PM, I'll investigate.
 
Last edited:
Joined
Oct 9, 2020
Messages
14 (0.01/day)
Processor Ryzen 3700x
Motherboard Gigabyte B450 Aorus Pro
Memory Corsair Vengeance Pro 16GB 3200MHz
Video Card(s) RTX 2070
Display(s) 35" Ultrawide 4K Aoc Agon AG352UCG6
Mouse Logitech G502 Proteus Spectrum
Keyboard Razer Ornata Chroma
Software Win 10 x64
Open the file in a hex editor and read the header to know with what you're dealing with. Could be an application, compressed file, etc. Post a screenshot of the first 4 bytes.
I never used Hex before, I dont know if i screenshoted the right thing or not. Looks empty although it has 50mb.I also tried to open the file with notepad but nothing appeared although the scroll bar was going down and getting bigger so it was loading something... Also, isnt it weird it has no extension?
 

Attachments

  • Untitled.jpg
    Untitled.jpg
    343.4 KB · Views: 82
Joined
Aug 15, 2016
Messages
486 (0.17/day)
Processor Intel i7 4770k
Motherboard ASUS Sabertooth Z87
Cooling BeQuiet! Shadow Rock 3
Memory Patriot Viper 3 RedD 16 GB @ 1866 MHz
Video Card(s) XFX RX 480 GTR 8GB
Storage 1x SSD Samsung EVO 250 GB 1x HDD Seagate Barracuda 3 TB 1x HDD Seagate Barracuda 4 TB
Display(s) AOC Q27G2U QHD, Dell S2415H FHD
Case Cooler Master HAF XM
Audio Device(s) Magnat LZR 980, Razer BlackShark V2, Altec Lansing 251
Power Supply Corsair AX860
Mouse Razer DeathAdder V2
Keyboard Razer Huntsman Tournament Edition
Software Windows 10 Pro x64
Yeah, no info so far, you should send the file to me in PM.
 
Joined
Oct 9, 2020
Messages
14 (0.01/day)
Processor Ryzen 3700x
Motherboard Gigabyte B450 Aorus Pro
Memory Corsair Vengeance Pro 16GB 3200MHz
Video Card(s) RTX 2070
Display(s) 35" Ultrawide 4K Aoc Agon AG352UCG6
Mouse Logitech G502 Proteus Spectrum
Keyboard Razer Ornata Chroma
Software Win 10 x64
Joined
Aug 15, 2016
Messages
486 (0.17/day)
Processor Intel i7 4770k
Motherboard ASUS Sabertooth Z87
Cooling BeQuiet! Shadow Rock 3
Memory Patriot Viper 3 RedD 16 GB @ 1866 MHz
Video Card(s) XFX RX 480 GTR 8GB
Storage 1x SSD Samsung EVO 250 GB 1x HDD Seagate Barracuda 3 TB 1x HDD Seagate Barracuda 4 TB
Display(s) AOC Q27G2U QHD, Dell S2415H FHD
Case Cooler Master HAF XM
Audio Device(s) Magnat LZR 980, Razer BlackShark V2, Altec Lansing 251
Power Supply Corsair AX860
Mouse Razer DeathAdder V2
Keyboard Razer Huntsman Tournament Edition
Software Windows 10 Pro x64
It's a dummy file with no data at all. Now I'm wondering what generated these.
 
Joined
Jul 25, 2006
Messages
12,147 (1.87/day)
Location
Nebraska, USA
System Name Brightworks Systems BWS-6 E-IV
Processor Intel Core i5-6600 @ 3.9GHz
Motherboard Gigabyte GA-Z170-HD3 Rev 1.0
Cooling Quality case, 2 x Fractal Design 140mm fans, stock CPU HSF
Memory 32GB (4 x 8GB) DDR4 3000 Corsair Vengeance
Video Card(s) EVGA GEForce GTX 1050Ti 4Gb GDDR5
Storage Samsung 850 Pro 256GB SSD, Samsung 860 Evo 500GB SSD
Display(s) Samsung S24E650BW LED x 2
Case Fractal Design Define R4
Power Supply EVGA Supernova 550W G2 Gold
Mouse Logitech M190
Keyboard Microsoft Wireless Comfort 5050
Software W10 Pro 64-bit
I would simply rename the folder to virus-delete and use the phone as normal for awhile. If nothing is broken, delete the folder. I would not open any of those files.
 
Joined
Oct 9, 2020
Messages
14 (0.01/day)
Processor Ryzen 3700x
Motherboard Gigabyte B450 Aorus Pro
Memory Corsair Vengeance Pro 16GB 3200MHz
Video Card(s) RTX 2070
Display(s) 35" Ultrawide 4K Aoc Agon AG352UCG6
Mouse Logitech G502 Proteus Spectrum
Keyboard Razer Ornata Chroma
Software Win 10 x64
I would simply rename the folder to virus-delete and use the phone as normal for awhile. If nothing is broken, delete the folder. I would not open any of those files.
Well there isn't any way to open them...they dont have any extension. I scanned them with 5 differenti anti-malware apps and uploaded them on virustotal.com and they are not infected. I think they are some sort of logfiles or dummy files with nothing inside. I deleted them and changed my passwords. But why the hell would the person that is behind the malware would name the folder Virus and make it so obvious ? Im a bit worried that since it could write on my phone's internal storage probably it also had the ability to read...
 
Joined
Jul 25, 2006
Messages
12,147 (1.87/day)
Location
Nebraska, USA
System Name Brightworks Systems BWS-6 E-IV
Processor Intel Core i5-6600 @ 3.9GHz
Motherboard Gigabyte GA-Z170-HD3 Rev 1.0
Cooling Quality case, 2 x Fractal Design 140mm fans, stock CPU HSF
Memory 32GB (4 x 8GB) DDR4 3000 Corsair Vengeance
Video Card(s) EVGA GEForce GTX 1050Ti 4Gb GDDR5
Storage Samsung 850 Pro 256GB SSD, Samsung 860 Evo 500GB SSD
Display(s) Samsung S24E650BW LED x 2
Case Fractal Design Define R4
Power Supply EVGA Supernova 550W G2 Gold
Mouse Logitech M190
Keyboard Microsoft Wireless Comfort 5050
Software W10 Pro 64-bit
Im a bit worried that since it could write on my phone's internal storage probably it also had the ability to read...
Just because the files were there, I would not automatically assume the offender could read your personal files or harder still, send copies of them back "home".

It actually sound like someone was be mischievous rather than malicious. Still, I am not very familiar with Android malware so at this point, with all the scans you did and with them all coming up clean, plus the fact your changed your passwords, I think you are safe. But it would still be wise to check for unfamiliar files every so often.

I would also make sure you disable Bluetooth and wifi when not using them.
 
Joined
Oct 9, 2020
Messages
14 (0.01/day)
Processor Ryzen 3700x
Motherboard Gigabyte B450 Aorus Pro
Memory Corsair Vengeance Pro 16GB 3200MHz
Video Card(s) RTX 2070
Display(s) 35" Ultrawide 4K Aoc Agon AG352UCG6
Mouse Logitech G502 Proteus Spectrum
Keyboard Razer Ornata Chroma
Software Win 10 x64
Yes, I will keep an eye on suspicious file/folder names and do some regular scans. Thanks everyone, thread can be closed as far as I'm concerned.
 
Top