Jump to content
AlStar

Chestie ciudata cu VirusTotal

Recommended Posts

In dimineata asta, umblam pe ici colo pe net, si primesc un mesaj pe messenger. Am dat click pe link, mi-a aparut sa salvez, da' idiotu' de mine m-am grabit si-am dat si save si run. Si brusc mi-am dat seama ca-i virus, pentru ca linkul primit pe messenger era: Foto li8...

L-am scanat pe VT si initial era detectat de vreo 7 AV-uri, dar nu si de Kaspersky sau Avast (pe care-l folosesc). Vreo juma' de ora mai tarziu, vad acolo, pe VT up-to-date report, si de data asta era detectat doar de 6 AV-uri. Acum am scanat fisieru' iar si e detectat doar de 5. Cum ma-sa? Ca e acelasi fisier.

Link to comment
Share on other sites

Da, e acelasi fisier. Pentru ca VT imi spunea ca este un report mai actualizat al fisierului.

LE: Am dat o scanare cu MBAM, mi-a gasit vreo 2 fisere cu TrojanDownloader. Si cred c-am scapat de el.

LE2.: Deci, din ce observ, cred la fiecare descarcare, fisieru' e diferit :-??, iar la scanare pe VT, dupa cum am spus, devine nedetectat, desi initial e detectat.

Edited by AlStar
Link to comment
Share on other sites

uitete te dupa: "jusched.exe" (are setate atributele hidden+system)

in "C:\WINDOWS\"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Java developer Script Browse: "C:\WINDOWS\jusched.exe"

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\Java developer Script Browse: "C:\WINDOWS\jusched.exe"

Link to comment
Share on other sites

uitete te dupa: "jusched.exe" (are setate atributele hidden+system)

in "C:\WINDOWS\"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Java developer Script Browse: "C:\WINDOWS\jusched.exe"

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\Java developer Script Browse: "C:\WINDOWS\jusched.exe"

MBAM a gasit ce zici tu si a sters. Singurul jusched.exe care-l mai am e in Program Files, in directorul Java. Cica ar fi updater-u.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...