rad Posted January 9, 2017 Posted January 9, 2017 Teacher has presented me with this 32GB USB, as can be seen the files are showing all weird. (This is plugged into an offline laptop BTW) I have scanned the drive using MSE, no virus' found. A Google search does point to using an older USB supported drive This sort of thing usually happens when you plug in flash disk to old PCs (Pentium IV or lower) or on PC's internal card reader with USB port. Apparently, some old USB controllers (those that were manufactured before 4-GB flash storage were developed) simply do not support USB drives larger than 2GB. As a result, the files get corrupted. from here virus - Files names in pen drive turned into gibberish text - Super User Has anyone else seen this, it has only affected/effected files larger than 50Mb and also renamed (what appears to be) folders too.
Fazza Posted January 9, 2017 Posted January 9, 2017 You need to scan the computer the user uses for Malware/Ransomware as it could be that the infected machine has done something to the files but not tried to transmit/distribute itself on to the memory stick.
Garacesh Posted January 9, 2017 Posted January 9, 2017 Ransomware tends to encrypt with standard latin characters and a common file extension type, so at-a-glance I'd say this is unlikely to be the cause. Combine that with the fact that many of the files are missing creation/modified dates (again, ransomware would modify the files so you'd see reasonably-sequential modify datetimes) I'd suggest this is corruption. Scan-'n'-nuke to be safe.
Meldrew Posted January 9, 2017 Posted January 9, 2017 I have seen something very similar with a corrupted memory stick, way before ransomware was a thing. Meldrew.
rad Posted January 9, 2017 Author Posted January 9, 2017 Its not ransomeware as this tends to change the file extension and normally goes through complete folders. It hasnt done this.
difinity Posted January 9, 2017 Posted January 9, 2017 I'd guess at failing NAND. Cheap memory stick or branded ?
JoeBloggs Posted January 9, 2017 Posted January 9, 2017 Ransomware tends to encrypt with standard latin characters and a common file extension type, so at-a-glance I'd say this is unlikely to be the cause. Combine that with the fact that many of the files are missing creation/modified dates (again, ransomware would modify the files so you'd see reasonably-sequential modify datetimes) I'd suggest this is corruption. Scan-'n'-nuke to be safe. This for sure!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now