All Activity
- Past hour
-
Molto interessante. Fino ad ora non ho riscontrato problemi. Per il momento c'è il post di un moderatore qualificato e non ci resta che attendere sviluppi, che potrebbero essere imminenti. La prudenza è d'obbligo ma come ripeto, al momento non riscontro problemi. Ti ringrazio della preziosa informazione.
-
Роман joined the community
-
Extremely Disappointed With the Latest VPN Update!
mokaz replied to Mehrnaz's topic in Kaspersky VPN Secure Connection
Yeah let's be clear, they haven't made lots of friends out of this. Talking positively about anything technology related these days is hard, Kaspersky was on my list -- this proven to be a cheap & reputation hitting move in my regards. So long ! - Today
-
adastmin started following Помоги расшифровать самую страшную групировку LYNX
-
Помоги расшифровать самую страшную групировку LYNX
adastmin posted a topic in Вопросы, связанные с вирусами и шифровальщиками
Помоги расшифровать самую страшную групировку LYNX файлы зашифрованы и расширение у всех LYNX. Также сигнатура в файле: -
adastmin joined the community
-
Berny started following YouTube and home banking screen goes black and then returns to normal after a few seconds
-
latest version of VPN can't finish to install
NicoCase replied to NicoCase's topic in Kaspersky VPN Secure Connection
problem solved @Igor Kurzin , to enable the install, i had not just to "pause" KAspersky security, but to close it completely ! -
harlan4096 started following YouTube and home banking screen goes black and then returns to normal after a few seconds
-
fabiodanzetta started following YouTube and home banking screen goes black and then returns to normal after a few seconds
-
YouTube and home banking screen goes black and then returns to normal after a few seconds
fabiodanzetta posted a topic in Kaspersky: Basic, Standard, Plus, Premium
Hi everyone, Something strange happened to me yesterday and today: Yesterday, once I logged into my home banking site, the screen suddenly went black, even the mouse pointer was invisible, and after a few seconds everything returned to normal and the site was visible again. Today, the same thing happened while I was watching a music video on YouTube. As for home banking, I didn't use Safe Money, but in general, I installed the Chrome extension and set it to block data collection and banners. Thank you all. -
Danel joined the community
-
Deni5c joined the community
-
problème VPN depuis la dernière mise à jour novembre 2025
scraft replied to leonardeau's topic in Pour particuliers
Merci pour votre réponse. Je vais attendre les prochains jours/semaines pour obtenir la mise à jour qui résoudra probablement le problème. Bon week-end :)) -
kaspersky plus Kaspersky VPN Secure Connection
Longlife replied to Frank_L's topic in Für Privatanwender
Würde vorschlagen ein Ticket beim Support zu eröffnen. -
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
Lê Huy Hoàng replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
I understand that these are currently only my hypotheses, so I am seeking confirmation and assessment from the community. Furthermore, I have taken the step of submitting a request to Kaspersky Technical Support regarding this issue. -
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
andrew75 replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
On what basis do you draw this conclusion? None of the above suggests this. -
pikoff110 joined the community
-
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
Lê Huy Hoàng replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
I have been doing that for a while. For most accounts involving personal security, I use two-factor authentication (2FA) and unique, random passwords (which I store in the Enpass application). However, the hacker exploited this by utilizing an App Password for access, which bypasses 2FA. Furthermore, the Enpass application itself is installed on this very device. -
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
Berny replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
If you suspect a brute force login cancel email and switch to an Authenticator app or sms ? -
harlan4096 started following URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
-
Isabell Dachs joined the community
-
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
Lê Huy Hoàng replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
As you said, that's why I emphasized that this is an AI-powered product. The connection test result from my computer: C:\Users\hoang>netstat -ano | findstr ESTABLISHED TCP 127.0.0.1:49671 127.0.0.1:57083 ESTABLISHED 5664 TCP 127.0.0.1:49671 127.0.0.1:58190 ESTABLISHED 5664 TCP 127.0.0.1:49671 127.0.0.1:60717 ESTABLISHED 5664 TCP 127.0.0.1:49671 127.0.0.1:61434 ESTABLISHED 5664 TCP 127.0.0.1:49671 127.0.0.1:63858 ESTABLISHED 5664 TCP 127.0.0.1:50576 127.0.0.1:50577 ESTABLISHED 5664 TCP 127.0.0.1:50577 127.0.0.1:50576 ESTABLISHED 5664 TCP 127.0.0.1:57083 127.0.0.1:49671 ESTABLISHED 15832 TCP 127.0.0.1:58190 127.0.0.1:49671 ESTABLISHED 15832 TCP 127.0.0.1:60717 127.0.0.1:49671 ESTABLISHED 15832 TCP 127.0.0.1:61434 127.0.0.1:49671 ESTABLISHED 15832 TCP 127.0.0.1:63858 127.0.0.1:49671 ESTABLISHED 15832 TCP 192.168.1.20:51834 4.145.79.80:443 ESTABLISHED 5728 TCP 192.168.1.20:52977 4.1.82.185:443 ESTABLISHED 5664 TCP 192.168.1.20:54839 79.133.168.9:443 ESTABLISHED 5664 TCP 192.168.1.20:55155 79.133.168.9:443 ESTABLISHED 5664 TCP 192.168.1.20:55794 185.201.3.101:443 ESTABLISHED 5664 TCP 192.168.1.20:56194 212.5.110.163:443 ESTABLISHED 10984 TCP 192.168.1.20:56198 185.201.1.202:443 ESTABLISHED 5664 TCP 192.168.1.20:57174 82.202.184.185:443 ESTABLISHED 5664 TCP 192.168.1.20:57486 142.250.197.202:443 ESTABLISHED 15832 TCP 192.168.1.20:58380 199.165.136.100:443 ESTABLISHED 7304 TCP 192.168.1.20:58953 4.145.79.81:443 ESTABLISHED 5728 TCP 192.168.1.20:60420 4.145.79.82:443 ESTABLISHED 16972 TCP 192.168.1.20:60708 20.50.201.203:443 ESTABLISHED 16972 TCP 192.168.1.20:62190 40.74.78.229:443 ESTABLISHED 19460 TCP 192.168.1.20:62195 185.201.3.101:443 ESTABLISHED 5664 TCP 192.168.1.20:64597 65.109.109.243:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:51763 [2001:4860:4860::8888]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:53218 [2404:6800:4005:817::200e]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:54584 [2404:6800:4008:c13::bc]:5228 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:54700 [2404:6800:4005:817::200e]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:54874 [2001:4860:4860::8888]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:56561 [2404:6800:4005:805::200e]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:57338 [2404:6800:4005:805::200e]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:57649 [2803:f800:53::3]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:59536 [2001:4860:4860::8888]:443 ESTABLISHED 15832 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:61934 [2603:1047:1:188::80]:443 ESTABLISHED 16972 TCP [2402:800:6195:ec43:d05c:566a:9e1c:a1d8]:65204 [2404:6800:4005:81e::200a]:443 ESTABLISHED 15832 The process 5664 belongs to Kaspersky. The reason I suspect my computer has been compromised is that while my computer was online and I was not actively using it, I received emails regarding Microsoft login OTP and password change OTP. I am certain that I did not log in to my account on multiple devices, which led me to suspect that my computer was compromised (despite running Kaspersky). -
After the new update, my internet experience is completely ruined..
mhnproject replied to xnvisible's topic in Kaspersky VPN Secure Connection
6 Dec 2025 ! No new update ! No fix ! -
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
andrew75 replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
-
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
Schulte replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
Nice AI-generated text. Can you please repost that in your own words? There are a few inconsistencies. For example, what data was transferred to the unknown IP? Was it taken into account that Kaspersky essentially acts as a proxy? Who claims that the IP belongs to Russia (it is actually located in Frankfurt, Germany)? With further information, it might be possible to make a statement, but not yet. -
URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
Berny replied to Lê Huy Hoàng's topic in Virus and Ransomware related questions
@Lê Huy Hoàng Weclome. Please reach out to the Kaspersky Technical Support team via https://support.kaspersky.com/b2c -
Lê Huy Hoàng started following URGENT SUPPORT REQUEST: ADVANCED STEALER MALWARE INJECTION INTO KASPERSKY PROCESS (Revised for AI Credit)
-
1. Initial Context and Symptoms Infection Vector: Likely initiated by running a cracked tool/software. Symptoms: Received unsolicited Microsoft one-time codes and password reset emails. Security Setup: The affected machine runs Windows 10/11 with Kaspersky running in real-time (no alerts). 2. Technical Findings (Forensics) The following critical findings were discovered not through manual user inspection, but through an AI-assisted diagnostic process: AI-Guided Diagnostics: I used an AI Assistant to analyze suspicious system behavior after initial self-detection failed. The AI guided me through terminal commands (such as netstat -ano and tasklist) to map network connections to running processes. Crucial Discovery (The Compromise): The diagnostic process identified a highly suspicious external connection associated with PID 5752. Mapping PID 5752 confirmed it belongs to the Kaspersky (32 bit) process. The connection was directed to a foreign, non-Kaspersky IP: 81.19.104.253 (in Russia). Conclusion: This provides strong evidence that a Stealer/Trojan malware used Process Injection to hide and operate within the trusted Kaspersky process space, thus neutralizing the protection and exfiltrating data. 3. Damage Assessment and Actions Taken Data Compromise: High risk that the Enpass Master Password and local files have been compromised. Immediate Actions: Network Disconnection: Permanently disconnected the machine from the internet. Emergency Password Change: Changed all critical passwords using a separate, trusted device. Future Plan: Planning a full, clean Windows reinstall. 4. Request to Kaspersky Experts I am seeking the community's and Kaspersky's official guidance on: Confirming the validity of this AI-assisted finding regarding Process Injection into the Kaspersky process. Guidance on how to formally report this sample and the associated C2 IP (81.19.104.253) for analysis by Kaspersky Labs. Any recommended steps for advanced artifact analysis that should be performed before the system is completely wiped.
-
Grogu_35 started following VPN Problem
-
Arkadaşlar sorunun çözümü yok 10 gündür düzeltemediler global forumda kısacası çözmeye çalışıyoruz dediler tahminimce bu sorun 1 ay sürcek gibime geliyor.
-
c115 joined the community
-
Lê Huy Hoàng joined the community
-
153 started following Kaspersky Android flags Samsung Internet as trojan
-
Kaspersky Android flags Samsung Internet as trojan
153 replied to K0908's topic in Virus and Ransomware related questions
Got the exact same problem. Kaspersky scan can froze for hours and shows warning on the trojan in Samsung Internet app when clicked. I'm surprised it's not been resolved yet. It's really billions of customers affected so it's most likely a false alert and is not corrected in data base. I did re-install the app when got the warning right from Google play store but got the same warning when Kaspersky scanned. I also had the same warning about Trojan in Samsung Wallet few months ago but I don't really use this app so just deleted it. Now I think it also was a false flag. I wonder if somebody at Kaspersky lab doesn't like Samsung 🤔 -
153 joined the community
-
TOD TV Detecting VPN and Blocking Access
Berny replied to ahmed 995's topic in Kaspersky VPN Secure Connection
@ahmed 995 Welcome. Please reach out to the Kaspersky Technical Support team via https://support.kaspersky.com/b2c and include as many technical details as possible. -
-
Subscribed to Kaspersky Plus but no VPN funtionalities in android APP
Visconti12 replied to justval012's topic in Kaspersky: Basic, Standard, Plus, Premium
That's my issue as well, right after a clean installation of K-Premium 21.23.6.614(a). -
kaspersky plus Kaspersky VPN Secure Connection
B.F. replied to Frank_L's topic in Für Privatanwender
Hab mehrmals neu installiert, VPN funktioniert nur sehr langsam, auf manchen Seiten überhaupt nicht. DuckDuck Go nimmt nur komplett eingegeben Internetseiten, z.B. www. ...... .de . Suchmaschine funktioniert überhaupt nicht. -
Subscribed to Kaspersky Plus but no VPN funtionalities in android APP
Zoidberg replied to justval012's topic in Kaspersky: Basic, Standard, Plus, Premium
I have the same issue. Did you find a way to fix it so far?