[ Olt @ 27.09.2013. 18:25 ] @
Pozdrav,
danas sam preko Facebook-a skinuo zip file za koji mi je rečeno da je slika. Kada sam ga raspakovao video sam da ima exenziju PIF. Pomislio sam da je to nekakva slika sa mobilnog telefona i pokušao da pokrenem ali se ništa nije otvorilo. Skenirao sam file na Virus Total i dobih jedan loš rezultat od mogućih 45, antivirus : Malwarebytes pokazuje Spyware.Zbot.ED
Molim za pomoć.

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 19:21:02, on 27-Sep-13
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16686)

FIREFOX: 23.0.1 (en-US)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
C:\PMAIL\Programs\winpm-32.exe
F:\Download\HijackThis.exe
C:\program files\avira\antivir desktop\ipmGui.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Nvtmru] "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\User\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [HKCU] C:\Windows\system32\install\explorer.exe
O4 - HKLM\..\Policies\Explorer\Run: [Policies] C:\Windows\system32\install\explorer.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies] C:\Windows\system32\install\explorer.exe
O4 - HKUS\S-1-5-21-1519396848-2328306014-80833226-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1519396848-2328306014-80833226-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O20 - AppInit_DLLs: C:\PROGRA~1\NVIDIA Corporation\NvStreamSrv\rxinput.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 4603 bytes

[ Olt @ 27.09.2013. 21:24 ] @
Malopre sam uradio rescan na VirusTotalu i sada su otkrivena još dva pogotka.
Kaspersky Trojan.Win32.Llac.dnnn

AhnLab-V3 Trojan/Win32.Badur
Da li sam mogao da zarazim sistem pokretanjem fajla iz Total Commandera?


[Ovu poruku je menjao Olt dana 27.09.2013. u 22:34 GMT+1]
[ Goran Mijailovic @ 27.09.2013. 21:43 ] @
Skini Kaspersky trial i uradi full scan, ocisti sve sto pronadje.

Citat:
Da li sam mogao da zarazim sistem pokretanjem fajla iz Total Commandera?


Verovatno, jos pod admin privilegijama.
[ Olt @ 28.09.2013. 12:49 ] @
Hvala Gorane,
Skinuo sam Kaspersky Pure 3.0 Trial, uradio full scan ali nije ništa pronađeno sem tog PIF fajla koji je stavljen u karantin. Da li to znači da nema zaraze?

Uradio sam novu analizu na VirusTotal i pojavila su se još dva pogotka:
AntiVir TR/Llac.dnnn
Panda Suspicious file
[ Goran Mijailovic @ 28.09.2013. 14:18 ] @
Sacekaj nekoliko dana taj .Llac.dnnn izgleda da je nesto novo. Ostavi Kaspersky nek odradi svoj trial.
[ Olt @ 28.09.2013. 14:28 ] @
Hoću, hvala Gorane. Ako bude nekakvih promena, napisaću.