Specificially https://en.z-lib.gs/

I downloaded some pdfs from there and according to virustotal and some pdf online scanner i tried, they have something possibly malicious going on in them. I already deleted them but i opened them in firefox pdf reader. I dont have acrobat installed.

Scanning my system with malwarebytes now, but nothing is finding anything wrong and I havent seen any suspicious activity.

Here is the analysis itself.

https://www.virustotal.com/gui/file/f3140c932ab57256a8438eba31d18e4baee1413e7ec23d93b1c1f5194b6dea95/behavior

I’m starting to panic, please help if you have any advice


Thank you all, you are wonderful people

  • reksas@sopuli.xyzOP
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    2 days ago

    I’m not sure what to look for if there is something hidden. I cant tell if there are any odd processes but everything seems to be signed correctly. There is nothing odd in C root either and i wouldnt know what to look for from the folders. There are no odd installed applications either.

    I have had similar scare before when I installed a game I downloaded from skidrow reloaded website.(over year ago) The installer did something with cmd window, something about system image, i dont remember anymore. The file was also too big for scanner to scan and I dont think virustotal accepted it either due to size. However, I did system restore after that.

    I also asked an acquittance who works in some tech company to help, even showed the install process to him, but he said it didnt seem dangerous. I have also been running r-kill occasionally and doing scans with hitmanpro’s early detection but they havent found anything either. I have also been occasionally monitoring things with tools from sysinternals but I’m not sure if i would even notice if anything was odd.