u/Coldcoat0_0

Does this file has virus ? Really Interesting one.

Does this file has virus ? Really Interesting one.

So I was searching for some books to download and then came across a pdf on Google drive . It had a link to a downloader site https://pulse(dot)datastreamforge5(dot)cyou/nirali+prakashan+books+pdf+free+download.zip? . So clicked on it and it downloaded a 7z file. As I wasn't able to unzip it using inbuilt archiver,so installed 7z and extracted it. So usually here I'm bit cautious so I check the files in it without extracting it but I wasn't able to view it.

Then I uploaded the zip to virustotal , but wasn't able to check it as it has 3mb limit for archived files with password. So instead I just went ahead and extracted it , and then automatically got this prompted on my screen.

So apparently windows stopped it from executing but I don't know yet if it has caused any damage.Please let me know if it's safe or not and what should I do?

Edit: So I just extracted the .7z file in my mobile and zipped it again without password (as the unzipped version is around 800mb exe file) so zipped it without password and uploaded it to to virustotal. The virustotal analysis - https://www.virustotal.com/gui/file/7af47fffc2014f6f72981dc9860cb6048ba1bcd09f15ff2786a3bf1a0c87a0d0/summary

Edit 2: Just for everyone to know I didn't ran the exe file explicitly, the popup appeared just after I extracted the .7z using 7-zip.I didn't knew it had exe file in it untill I extracted it and the popup appeared.I mostly use virustotal to scan the downloaded files which are suspicious, and this time too I used it but virustotal don't support password protected archives more than 3mb, thus here I am in this subreddit.

Btw it's clarified by now it's a virus.So thanks for helping me out guys.

Note: The image I have attached resembles to the popup I got I can't remember it exactly but i remember it had don't run button below :)

u/Coldcoat0_0 — 3 days ago