Strange exe files in downloaded zip, virus?

Steph

Multi Many Tasks man
Retired Moderator
Joined
Sep 1, 2002
Messages
18,162
Location
Pont de l'Arn, FRANCE
I've seen in several of the unit animations I downloaded recently a lot of zip files containing exe files with strange names, such as DFldklm.exe.

This morning, I had a major crash of my system. I quickly reinstall Windows, but now EVERY file on EVERY drive has a size of 0 kb.

So... I was wondering what are these exe files in the zip. Am I the only one to have them? Do you have them to folks? Could it be a virus?

I wonder if it's an exe that is added by a virus that I already have on my HD, if the files themselves could contain a virus, or if they have a good reason to be there. What are they then?
 
In google I had no hit with "DFldklm.exe". Can you tell us some of the units you have recently downloaded that contained that zip-file and where you have downloaded them?
 
I've used a random name. I'm not sure of the exact name. It's just a bunch of letters with no meaning.

And no, I cannot tell you in what files they are, as I wrote EVERY file has a size of 0 kb and cannot be opened anymore.

That includes all the files for my mod, my website, and the source code of SSS :mad:
 
I wonder if it's an exe that is added by a virus that I already have on my HD, if the files themselves could contain a virus, or if they have a good reason to be there. What are they then?
That would be my guess, that is something you allready had on your harddrive. Since you are seeing exe's being made chances are it is some kind of trojan.
 
With the catch-words "0 kb files" I got a lot of hits in google:

Some of the first reports I received, concerned about a virus that activated the "SysDref.exe." Of course you have all my sympathies and I hope you have some close-in-time-backups of your sabotaged files.
 
So far, I've found several reports to. But all just say "I've lost all my files, recovery doesn't work".

I've seen no solution to the problem.

I've tried a data recovery tool. They can recover the files... With 0 kb... So useless.

I can try a raw data recovery, but then I just have the files without any name. So it's useless to restore the structure of a website...

For the source code it's worse, the data recovery tools I have do not work at all with that.
 
What a tragedy. :undecide:

2 weeks ago I had a HD crash, but I`ve recovered all of my files with R-Studio 4.1. Hope you will recover your database. :(
 
Oh no...SSS is lost??? this is a tragedy...

I am sorry this has happened to you Steph...of all people I see your HD lost as the worst

please say this didnt happen from a file here...??
 
SSS is not lost. We have several copies. However, the work I did recently to port it to XNA is lost.
And more importantly, I'm wrecked and I'm not sure I4ll find agin the motivation to continue SSS or my mod.
It will take weeks simply to assess the damage..

I'm not sure where it came from. What I can tell you is I had strange exe file within a lot of the zip or rar files on my HD. But I can't tell if they were in the file I downloaded, or if they were added later.
I can however confirm they are a virus, apparently Win32/drefir - F.

So:
- Do not download anything for me
- If you see a strangely named exe in one of the file you downloaded from here, immediately take the necessary antivirus precaution.
 
ive been looking around as many tech sites as i can find and leaving my thread where ive been it sounds like the same problem as yourself, heres a copy of my message...

its a bit long this but im always seeing ppl want to know the full story to get to the bottom of the problem so heres the whole thing. please do take the time to read as im in serious trouble if i cannot solve my problem, thanks for your time
i am currently working as a freelance graphic designer specialising in 3d studio max animations, thierfore i have got a lot of very important files of many different types including .psd .jpg .tif .avi and some far less know such as 3d studio max files, motion capture files and premier pro files etc... my problem began a couple of days ago, i am ussually very careful with scanning downloaded software but i was under pressure to finish a clients job off and i really needed to edit some video files in a way that my normal editing software dosent allow. cut a long story short i ran a setup file without running a virus check on it and soon after my network went down. i reset my pc to find it wouldnt restart after many attempts of on / off / wait a min / on (tried all safe mode/last good config/normal) it finally started back up everything seemed fine at 1st glance i figured it must be the software and so did a system restore to make sure all was ok. the system started up again and so i set about looking on the internet for some other software but IE didnt start up, i then tried opening a document to find it wasnt readable. i soon noticed that nothing worked, all my files are visible in thier respective folders but every single file has a size of 0kb and nothing except basic windows functions work. i proceeded to reinstall windows on a seperate partition that i didnt mind losing and that solved the IE problem but all my files on my other dirves are still 0kb. i figured that the software must somehow have messed up the MFT of my NTFS drives and so i set about finding some software to help recover the files, i have tried the demo versions of: data doctor recovery, easy recovery, r-studio, active@ file recovery, media recover and recover my files. all except the last 1 just find the files at 0kb or totally miss the more important rare file types. recover my files does find the missing files but it cannot find thier titles so im left with a jumbled list of files without any order this is a big problem as my animations are saved as frames and so there is probably around 1/4 million images from various animations all jumbled up, it looks like a excessivly hard jigsaw puzzle with 250000 images many of which ave next to no noticeable difference i really dont have the time to solve that mess.
so thats the problem and the question is...
does anybody have a clue how i can fix the file structure of my NTFS drives keeping the directorys intact and restoring all file types not just well known types, i know the files are there ive not overwritten anything and "recover my files" can see them, i dont mind paying for software to do the repairs as long as it is going to do the job.
apperciate any help that can be offered, thanks for reading
Steve C
 
I can however confirm they are a virus, apparently Win32/drefir - F.
From what I have found that is an e-mail and IRC worm/virus.

Once again I feel sorry for your huge loss and I hope recovery is possible.
 
You were predicting a 1 year or so release date for your new civ3 mod project. DId the files from this get erased? If so you don't have to say it, I guess we can saftly asume that project has meet an untimely end. WHat a bad bid of business indeed.
 
Wow better be careful this thing sounds scary, I hope I'm not unfortunate enough to get it. :scared:

I hope that both Steph and steve_c are able to recover some of your stuff and get back on your feet.

Shall I start the conspiracy theory that Firaxis thought SSS was just looking too cool and deemed it a legitimate threat to the Civilization franchise so they had to send in their ninja haXorz to plant a virus on Steph's hard drive. :mischief:
 
The mod is not really lost, as I uploaded an update recently to the website, it should be safe, except the virus may be in it, so I'll have to be careful when I'll try to get it back.

Also, the data recovery software I used managed to get most of the doc and excel files, I need time to sort everything, but most of the design doc are safe.

It's not so good for SSS: I have a copy of the code, but everything I did in the last weeks to port it to XNA is lost.

The program I did for the character generation for my RPG is probably definitely lost :(

As well as the source code for SBB...
 
Back
Top Bottom