0

Since yesterday, I have noticed that through Windows Form an application called Velo.exe creates many subfolders (2-3 per minute, see photo) in the Temp folder with the same file called Velo.exe inside: I have tried to stop the instance of Windowsformapp, but the application always restarts. What is the problem? What can I do to solve the problem? I have uploaded one of the Velo.exe files here. I have been told that it could be a trojan virus.

enter image description here

Here is the log I find in \AppData\Local\Microsoft\CLR_v4.0\UsageLogs\Velo.exe.log:

1,"fusion","GAC",0 1,"WinRT","NotApp",1 3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\System\43b97e99fab55055761ec7618b2bf77b\System.ni.dll",0 3,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\System.Drawing\98b511e858932d0d2ded15adaa4551a5\System.Drawing.ni.dll",0 3,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\ba73c84262a3c3e850b5811664dd4b05\System.Windows.Forms.ni.dll",0

7
  • What exactly is your question? If you suspect it's a trojan take the necessary steps to remove it from your system.
    – Ramhound
    Commented Jan 18, 2022 at 13:48
  • I've tried everything and run scans, remove the file, clean up logs, but the application always reactivates: what can I do to get rid of it?
    – qwertxyz
    Commented Jan 18, 2022 at 13:50
  • It would be helpful if you uploaded the binary to something more mainstream like VirusTotal
    – Ramhound
    Commented Jan 18, 2022 at 14:33
  • Here: virustotal.com/gui/file/…
    – qwertxyz
    Commented Jan 18, 2022 at 14:36
  • I would use AutoRuns and the registry editor to see how the application is being automatically installed, while the behavior is odd, the fact only off brand security vendors are detecting it as malicious tells me it's not actually malicious. '
    – Ramhound
    Commented Jan 18, 2022 at 14:54

0

You must log in to answer this question.

Browse other questions tagged .