PDA

View Full Version : a.exe, autorun.inf and TROJ-GEN files



AQ_admin
11-05-2009, 05:06 PM
My Patriot XT 4Gb USB drive is working fine under WXPSP2. However there is a persistent file named a.exe which I cannot delete.

If I delete a.exe, it somehow immediately recreates itself, plus doing this also coincidentally creates an autorun.inf file. Then, whenever I plug the USB into my computer, my TrendMicro reports that autorun.inf contains a virus/malware file "TROJ_GEN.8X0939". I can then have Trend delete autorun.inf and it leaves a.exe alone. Then everything is fine whenever I plug the USB into my computer. However, if I try to delete a.exe, the cycle starts all over again.

The USB does display an Explorer window automatically whenever inserted, whether a.exe alone is present or if autorun.inf is also present. So I've settled on having TrendMicro delete autorun.inf, since it seems unnecessary.

I am trying to decide if TrendMicro is incorrectly diagnosing autorun.inf as containing a truly dangerous TROJ_GEN or if it is simply misinterpreting things. It seems to see a.exe as non-threatening, but since a.exe seems related to the creation of autorun.inf as described above, I'm wondering where a.exe came from.

Is a.exe something Patriot includes on the USB? If not, can you advixe how I can format the USB or delete a.exe permanently?

Patriot_Ben
11-05-2009, 07:30 PM
Hi,

Please check your registered email address. Sent you the low level format that might alleviate the issue...


The most common fixes of this tool are for: drives that develop multiple bad sectors, write-protected, or stubborn viruses, drives that are detected in “My Computer” but are not accessible, or drives that become extremely slow due to degradation over time.

AQ_admin
11-06-2009, 03:00 PM
Ben, I did not receive the file. Is it possible it had an "exe" extension and maybe it got stripped along the way by some filters? I can PM you an alternate GMail account - let me know. Thanks!
Alan

Patriot_Ben
11-06-2009, 11:32 PM
Hello,

We are experiencing technical difficulties with our email server.

I have sent you the tool from the temporary registered email address of Patriot.Memory.09@Gmail.com.

AQ_admin
11-09-2009, 04:50 PM
Ben, that tool successfully cleared a.exe from my Patriot device.

I could then observe the a.exe file being inserted again into the the Patriot device by my computer whenever I insert it into my USB ports. This does not happen when inserting the Patriot device into USB ports of other computers in the office, so I conclude my computer is the source of the malware and I can now focus my efforts there.

Thanks for your help,

Alan

Patriot_Ben
11-09-2009, 06:04 PM
No Problem Alan. Let me know if you any further issues.