Reply
Thread Tools
Posts: 235 | Thanked: 89 times | Joined on Oct 2009 @ italy
#1
Hi to all, I found a KLIZAVI directory into Mydocs with these 2 files inside: Desktop.ini and sapun.exe
Is a virus?
Do I've to delete it?
Thank you
__________________
If you found my post useful please thank me, I appreciate!
 
Posts: 77 | Thanked: 176 times | Joined on Dec 2009 @ Hamburg, Germany
#2
That must be a folder that you have (accidentally) copied onto the device. .exe files don't run on the N900. So you can keep it there or just delete it (if you don't need it).
__________________
Finally something useful for the N900's front camera:
My face tracking game
And a little 3d display demo
 

The Following 2 Users Say Thank You to jfk For This Useful Post:
giannoug's Avatar
Posts: 334 | Thanked: 171 times | Joined on Dec 2009
#3
Yeap, it is a virus.

http://www.google.com/search?q=sapun.exe

A computer virus though
 

The Following 3 Users Say Thank You to giannoug For This Useful Post:
Posts: 92 | Thanked: 13 times | Joined on Nov 2009 @ leicester UK
#4
files with .exe extensions are for windoze. It might be a virus, but if it is a virus, you can rest assured it is a windoze virus, just don't run the sapun.exe file in windoze.
 
Posts: 235 | Thanked: 89 times | Joined on Oct 2009 @ italy
#5
Thank you guys, I delete it!
__________________
If you found my post useful please thank me, I appreciate!
 
ysss's Avatar
Posts: 4,384 | Thanked: 5,524 times | Joined on Jul 2007 @ ˙ǝɹǝɥʍou
#6
scan your windows too, sounds like it's filthy!
__________________
Class .. : Power User
Humor .. : [#####-----] | Alignment: Pragmatist
Patience : [###-------] | Weapon(s): Galaxy Note + BB Bold Touch 9900
Agro ... : [###-------] | Relic(s) : iPhone 4S, Atrix, Milestone, N900, N800, N95, HTC G1, Treos, Zauri, BB 9000, BB 9700, etc

Follow the MeeGo Coding Competition!
 

The Following 2 Users Say Thank You to ysss For This Useful Post:
Posts: 3,428 | Thanked: 2,856 times | Joined on Jul 2008
#7
Originally Posted by ysss View Post
scan your windows too, sounds like it's filthy!
This. Virus files, especially winblows virus files, are not going to magically some day just go "OH LOOK! I'll get on this N900 through Osmosis!"

It got on there somehow.. and my first thought would be any Windows systems you've ever hooked up to or transferred files from has got itself a cold.
__________________
If I've helped you or you use any of my packages feel free to help me out.
-----------------------------------------------------------------------------------
Maintaining:
pyRadio - Pandora Radio on your N900, N810 or N800!
 

The Following User Says Thank You to fatalsaint For This Useful Post:
Posts: 284 | Thanked: 75 times | Joined on Nov 2009
#8
It must be a clever virus if it made its way to your MyDocs and not just whatever root shows up when connected via usb. Delete delete delete
 
Posts: 126 | Thanked: 77 times | Joined on Feb 2010 @ UK
#9
Seems your not the only one...
Another infection

Scan, clean, disinfect & quarantine any removeable devices, such as memory cards, USB drives / dongles, external hdd's. Its a nasty virus that binds itself to the autorun.inf file, so everytime you plug in or unplug a usb dongle for example, it replicates itself immediately.
Just cause its deleted from your N900, doesn't mean to say its perminately gone.
I recommend you take the following steps:-

Download Flash_Disinfector.exe by sUBs and save it to your desktop

* Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
* The utility may ask you to insert your flash drive and/or other removable drives. Do so and allow the utility to clean up those drives as well.
* Wait until it has finished scanning and then exit the program.
* Reboot your computer when done.

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

Now download but do not yet run ComboFix
* It must be saved to your desktop, do not run it *
* Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well*
* Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser*


Once this is done rename the combofix.exe file on your desktop (lets call it george)
Double click on george.exe to start the program

* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes. (The Recovery Console option will appear for 2 seconds each time you boot. You need do nothing and your regular windows will load normally. Its added in case something goes wrong so you can get on the system and fix it.)

* Caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.
Once finished re-activate your protection programs at this time

You should run Flash Disinfector on usb drives and on any others you have lying around (and then scan them with avira). Remember it's not just usb drives but cameras and ipods and anything that plugs into your usb port and has its own memory. Another program you might want to try is Autorun Eater. It stay resident and watches for autoruns.

That should fix things up
 

The Following User Says Thank You to james174 For This Useful Post:
Posts: 235 | Thanked: 89 times | Joined on Oct 2009 @ italy
#10
thank you james174. I haven't this kind of problem because I use linux on my pc too. This virus come from a key of my friend.. I'll alert him to follow your instruction.
thank you again
__________________
If you found my post useful please thank me, I appreciate!
 

The Following User Says Thank You to maemo.it For This Useful Post:
Reply


 
Forum Jump


All times are GMT. The time now is 08:04.