<?xml version="1.0"?>
<rss version="2.0"><channel><title>Virus and Ransomware related questions Latest Topics</title><link>https://forum.kaspersky.com/forum/virus-and-ransomware-related-questions-157/</link><description>Virus and Ransomware related questions Latest Topics</description><language>en</language><item><title>Webmail server blocked</title><link>https://forum.kaspersky.com/topic/webmail-server-blocked-58903/</link><description><![CDATA[<p>
	Hi, we operate a webmail server at webmail.de.opalstack.com. One of our customers reports that Kaspersky Endpoint Security is flagging the server as a <span style="background-color:#ffffff;color:#465a69;font-size:14px;">threat of data loss.</span>
</p>

<p>
	I believe this is the result of a recently-compromised mailbox belonging to one of our customers. That mailbox has been secured and the webmail server itself has no issues.
</p>

<p>
	Can this server please be unflagged?
</p>
]]></description><guid isPermaLink="false">58903</guid><pubDate>Fri, 15 May 2026 07:37:43 +0000</pubDate></item><item><title>Website Blacklist Removal</title><link>https://forum.kaspersky.com/topic/website-blacklist-removal-58881/</link><description><![CDATA[<p>
	One of my perfectly legit websites is flagged as "phishing", can you remove it from blacklist?<br />
	See screenshots atteched
</p>

<p>
	www.anypro.it
</p>

<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_05/photo_2026-05-11_15-56-20.jpg.06fc4ff1c5187fd4e26a970c62c554fb.jpg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="38937" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_05/photo_2026-05-11_15-56-20.thumb.jpg.4a872f796ed4aa3f38ac25563f7e428a.jpg" data-ratio="31.6" width="500" class="ipsImage ipsImage_thumbnailed" alt="photo_2026-05-11_15-56-20.jpg"></a></p>
<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_05/photo_2026-05-11_15-53-05.jpg.c2d5534f5404e1df3a533c7d80c45533.jpg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="38938" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_05/photo_2026-05-11_15-53-05.thumb.jpg.e79dc69a19a61bc83dc1c5604085b94b.jpg" data-ratio="51.8" width="500" class="ipsImage ipsImage_thumbnailed" alt="photo_2026-05-11_15-53-05.jpg"></a></p>]]></description><guid isPermaLink="false">58881</guid><pubDate>Mon, 11 May 2026 14:18:01 +0000</pubDate></item><item><title>False Positive: OmenCore.exe detected as Trojan-Downloader.MSIL.Krocomain.abp and deleted</title><link>https://forum.kaspersky.com/topic/false-positive-omencoreexe-detected-as-trojan-downloadermsilkrocomainabp-and-deleted-58870/</link><description><![CDATA[<p>
	Hello Kaspersky Team and Community,
</p>

<p>
	I am reaching out to request an expert analysis / false positive investigation for the file OmenCore.exe, which Kaspersky is detecting as a Trojan and automatically deleting.
</p>

<p>
	<span class="ipsEmoji">🖥️</span> System Information
</p>

<p>
	Operating System: Windows 11 Pro 24H2 (Build 26100.8328)
</p>

<p>
	Kaspersky Product: Kaspersky Premium 21.25.7.504 (Latest version, all databases up to date)
</p>

<p>
	<span class="ipsEmoji">🛡️</span> Kaspersky Detection Details
</p>

<p>
	FieldValue
</p>

<p>
	ResultDeleted
</p>

<p>
	TypeTrojan
</p>

<p>
	Detection NameTrojan-Downloader.MSIL.Krocomain.abp
</p>

<p>
	AccuracyExact
</p>

<p>
	Threat LevelHigh
</p>

<p>
	Object TypeFile
</p>

<p>
	Object NameOmenCore.exe
</p>

<p>
	<span class="ipsEmoji">📋</span> What is OmenCore?
</p>

<p>
	OmenCore is an open-source, modern, lightweight control center that replaces HP OMEN Gaming Hub. It is built with .NET 8 and WPF, providing professional-grade hardware control without bloat, telemetry, or mandatory sign-ins.
</p>

<p>
	Key features include:
</p>

<p>
	Custom fan curves with temperature breakpoints
</p>

<p>
	WMI BIOS control for HP OMEN laptops
</p>

<p>
	Real-time monitoring with live CPU/GPU temperature history charts
</p>

<p>
	Per-fan telemetry and Embedded Controller (EC) access
</p>

<p>
	Official Links:
</p>

<p>
	<span class="ipsEmoji">🌐</span> Website: https://omencore.pages.dev/
</p>

<p>
	<span class="ipsEmoji">📂</span> GitHub Repository (Open Source): https://github.com/theantipopau/omencore
</p>

<p>
	<span class="ipsEmoji">⚠️</span> The developer's own antivirus note states: "Some AV products flag OmenCore's kernel driver as suspicious — this is a known false positive for hardware utilities that use low-level driver access."
</p>

<p>
	Known detections by other vendors (all considered false positives):
</p>

<p>
	Windows Defender → HackTool:Win64/WinRing0
</p>

<p>
	Bitdefender → Gen:Application.Venus.Cynthia.Winring
</p>

<p>
	These detections are triggered because OmenCore uses WinRing0 (a well-known open-source kernel driver) to access hardware-level features like EC registers and fan control — which is standard practice for hardware monitoring utilities.
</p>

<p>
	<span class="ipsEmoji">🔍</span> VirusTotal Analysis
</p>

<p>
	I have uploaded the file to VirusTotal for independent verification:
</p>

<p>
	<span class="ipsEmoji">🔗</span> VirusTotal Link: https://www.virustotal.com/gui/file/cb2b4b95226fd479aad7333c2090b23f35b92b1058d699baf7023752359bd0f7?nocache=1
</p>

<p>
	SHA-256: cb2b4b95226fd479aad7333c2090b23f35b92b1058d699baf7023752359bd0f7
</p>

<p>
	Please review the detection ratio — the majority of engines show the file as clean.
</p>

<p>
	<span class="ipsEmoji">❓</span> My Request
</p>

<p>
	I believe this is a false positive detection. OmenCore is an open-source, community-trusted application hosted on GitHub with full source code transparency. It uses low-level WMI BIOS and EC (Embedded Controller) access via WinRing0 driver, which may trigger heuristic-based detections.
</p>

<p>
	I kindly request the Kaspersky analysts to:
</p>

<p>
	<span class="ipsEmoji">✅</span> Review the file and the VirusTotal report
</p>

<p>
	<span class="ipsEmoji">✅</span> Examine the open-source GitHub repository for full code transparency
</p>

<p>
	<span class="ipsEmoji">✅</span> Confirm whether this is a false positive
</p>

<p>
	<span class="ipsEmoji">✅</span> If confirmed, update the Kaspersky signature database to whitelist this application
</p>

<p>
	Thank you very much for your time and support. I look forward to your analysis.
</p>
]]></description><guid isPermaLink="false">58870</guid><pubDate>Sun, 10 May 2026 12:55:56 +0000</pubDate></item><item><title>False positive blocking legitimate SaaS bargi.app &#x2014; multi-tenant login URLs flagged as data leak threat</title><link>https://forum.kaspersky.com/topic/false-positive-blocking-legitimate-saas-bargiapp-%E2%80%94-multi-tenant-login-urls-flagged-as-data-leak-threat-58865/</link><description><![CDATA[<p>
	Hello Kaspersky Team and Community,
</p>

<p>
	I'm the owner of bargi.app, a legitimate B2B SaaS for pub and bar management, developed by my company Byte Livre (Brazil). The product was launched on May 8, 2026.
</p>

<p>
	Kaspersky Endpoint Security for Windows is blocking tenant-specific login pages with the following message:
</p>

<p>
	- Message: "Evitamos o acesso a um site que pode causar vazamento de dados"<br />
	- Reason: "ameaça de perda de dados"<br />
	- Detection method: Kaspersky Security Network<br />
	- Detection date: 08/05/2026<br />
	- Blocked by: Web Threat Protection
</p>

<p>
	Blocked URLs (multi-tenant login pattern bargi.app/{tenant-slug}/login):
</p>

<p>
	- https://bargi.app/teste-pub-starter/login<br />
	- https://bargi.app/teste-pub-pro/login<br />
	- https://bargi.app/teste-pub-business/login<br />
	- https://bargi.app/beer-and-code/login
</p>

<p>
	Important: the root domain (https://bargi.app) and the master login page (https://bargi.app/login) are NOT blocked — only the tenant-specific subpaths.
</p>

<p>
	Context:<br />
	This is a standard multi-tenant SaaS architecture (similar pattern used by Slack, Notion, Linear, etc.). Each customer (pub/bar) has their own URL slug to access their administrative panel. These are legitimate login pages for real paying customers — not phishing.
</p>

<p>
	I understand the recent domain registration (May 2026) combined with the /slug/login URL pattern likely triggered heuristic classification by Kaspersky Security Network. However, I confirm:
</p>

<p>
	- bargi.app is legally registered and owned by Byte Livre<br />
	- The application is a real B2B SaaS product with valid customers<br />
	- Valid SSL/TLS certificate (Let's Encrypt) is in place<br />
	- No phishing, credential harvesting, or malicious behavior<br />
	- Company information and contact are publicly available
</p>

<p>
	I have already submitted reanalysis requests through OpenTIP for the affected URLs.
</p>

<p>
	Could a moderator please escalate this to the Virus Lab / Data Loss Threats Protection Group, so the domain bargi.app and the URL pattern bargi.app/*/login can be whitelisted?
</p>

<p>
	This false positive is preventing legitimate customers from accessing the service.
</p>

<p>
	Screenshots of the Kaspersky block message are attached below for reference.
</p>

<p>
	Thank you very much for your help.
</p>

<p>
	Best regards,<br />
	Marcos Vinicius<br />
	Byte Livre — Software Architect &amp; Founder<br />
	https://bargi.app
</p>

<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_05/WhatsAppImage2026-05-08at17_09_06.jpeg.4f21748e61e6f8d76a0714f969f8b40a.jpeg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="38906" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_05/WhatsAppImage2026-05-08at17_09_06.thumb.jpeg.c66b5a3ef1a866ed16637418b4638368.jpeg" data-ratio="58.6" width="500" class="ipsImage ipsImage_thumbnailed" alt="WhatsApp Image 2026-05-08 at 17.09.06.jpeg"></a></p>
<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_05/WhatsAppImage2026-05-08at21_23_32.jpeg.43f94552cf75a81cf50a6bbf3f4d209e.jpeg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="38907" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_05/WhatsAppImage2026-05-08at21_23_32.thumb.jpeg.12e50d93034ef3e22fa067f793c0b9b6.jpeg" data-ratio="75.2" width="500" class="ipsImage ipsImage_thumbnailed" alt="WhatsApp Image 2026-05-08 at 21.23.32.jpeg"></a></p>]]></description><guid isPermaLink="false">58865</guid><pubDate>Sat, 09 May 2026 00:49:36 +0000</pubDate></item><item><title>My Linux server was infected with .sorry ransomware.</title><link>https://forum.kaspersky.com/topic/my-linux-server-was-infected-with-sorry-ransomware-58813/</link><description><![CDATA[<p>
	I recently had my Linux server infected with ransomware that changed all the files on my website to .sorry.
</p>

<p>
	I need help because some of the files that were changed were very old and I don't have a backup.
</p>

<p>
	I've attached a file for analysis. Thank you.<br />
	<br />
	<a href="https://drive.google.com/file/d/1P9onLouCZCy7i1ai-_mBZ_zyyPQies6O/view?usp=sharing" rel="external nofollow">https://drive.google.com/file/d/1P9onLouCZCy7i1ai-_mBZ_zyyPQies6O/view?usp=sharing</a>
</p>
]]></description><guid isPermaLink="false">58813</guid><pubDate>Thu, 30 Apr 2026 20:18:04 +0000</pubDate></item><item><title>False Positive: tranquilityforge.com flagged as Phishing on VirusTotal</title><link>https://forum.kaspersky.com/topic/false-positive-tranquilityforgecom-flagged-as-phishing-on-virustotal-58761/</link><description><![CDATA[<p>
	Hi Kaspersky team,
</p>

<p>
	Kaspersky is flagging my site as Phishing on VirusTotal, but this is a false positive.
</p>

<p>
	Canonical URL: <span>https://www.tranquilityforge.com/</span><br />
	Note: <span>https://tranquilityforge.com/</span> permanently redirects (301) to the canonical www host.
</p>

<p>
	This is a legitimate small-business website for mentoring services (Tranquility Forge Mentoring). No credential harvesting, malware, or phishing behavior. All scans indicate the site is clean. The site is publicly reachable over HTTPS.
</p>

<p>
	Please re-check and remove the negative classification.
</p>

<p>
	Thank you,<br />
	Micah
</p>
]]></description><guid isPermaLink="false">58761</guid><pubDate>Fri, 24 Apr 2026 21:50:28 +0000</pubDate></item><item><title>Do exist processing error false positive?</title><link>https://forum.kaspersky.com/topic/do-exist-processing-error-false-positive-58730/</link><description><![CDATA[<p>
	I pretty much log to internet and use It for gaming. Tonight after I already have logged into Steam, while I was waiting for daily task of rootkit scan to occurr before went to start playing something.
</p>

<p>
	I've looked in report page and was checking each component detailed report section when I've noticed 'file antivirus' category. It have displayed two 'processing error' on high alert (colored in red). Went to verify myself each of these files and 0 object could not be scanned.
</p>

<p>
	Object name: WmiPrvSE.exe gives the following error as 'Not processed' and object pathfind is: searchms:display=name=Resultados%20da%20Pesquisa%20em%20wbem&amp;crumb=Qualquertexto%3AWmiPrvSE&amp;crumb=location:C%3A%5CWindows%5CSysyem32%5Cwbem\WmiPrvSE.exe
</p>

<p>
	 
</p>

<p>
	Object name: smartscreenps.dll gives the following error as 'Processing error'
</p>

<p>
	And the object pathfind is:
</p>

<p>
	C:\Windows\System32
</p>

<p>
	 
</p>

<p>
	I have looked inside quarantine section and there are no files whatsoever. I have started a series of procedure accordingly to 'KS Standard ender' articles like running a fullscan, to erasing manually these files (which I didn't since they have been normal for Yeats before Tonight)
</p>

<p>
	I hardly think my antivirus is corrupted because it is constantly searching for data bank updates.
</p>

<p>
	What I am doing in my reach is to restart the computer, and run Fullscan. However I have noticed Kaspersky Standard 21.24.8.522(b) did not gave the same alert while I am still running Fullscan. Only happen when I execute 'Selective scan' or 'mouse Quick action scan' to verify these files.
</p>

<p>
	 
</p>

<p>
	My question is:
</p>

<p>
	These alerts were they false positives? Because these system files have been laying around since 2022-2024 and I don't know If I should be worried.
</p>

<p>
	 
</p>

<p>
	 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2026_04/IMG_20260420_234755.jpg.fa93b0c08fabaa5023e9cf3aff461217.jpg" data-fileid="38670" data-fileext="jpg" rel=""><img alt="IMG_20260420_234755.jpg" class="ipsImage ipsImage_thumbnailed" data-fileid="38670" data-ratio="50" style="height:auto;" width="500" data-src="https://forum.kaspersky.com/uploads/monthly_2026_04/IMG_20260420_234755.thumb.jpg.e9ad8cf9d22e68a21b9b9e4eafa389c0.jpg" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>
]]></description><guid isPermaLink="false">58730</guid><pubDate>Tue, 21 Apr 2026 03:26:16 +0000</pubDate></item><item><title>File not ignored</title><link>https://forum.kaspersky.com/topic/file-not-ignored-58685/</link><description><![CDATA[<p>
	I have a file(s) that the anti-virus shows as having a virus. It does not, however as a keyboard scanner app, Kasperky thinks it does.
</p>

<p>
	Every time the notification comes up on accessing the folder the file is in my file manager, I am unable to ignore both the notification or add it to the exclusions list.
</p>

<p>
	Seems to get added but the notification still comes up the next time. How do I stop the false positive notifications?
</p>
]]></description><guid isPermaLink="false">58685</guid><pubDate>Tue, 14 Apr 2026 22:55:26 +0000</pubDate></item><item><title>Kapersky block many pirates sites</title><link>https://forum.kaspersky.com/topic/kapersky-block-many-pirates-sites-58620/</link><description><![CDATA[<p>
	Since I have installed Kaspersky standard latest version, some of sites I like to visite are blocked without possibility to allow me decide if yes or no I want to visite these sites. Users should always have the option to visit a site, and no have to turn off Kaspersky for that. Even if I add sites exclusion in anti banner, sites are still blocked. Can you please unblock these sites:
</p>

<p>
	removed
</p>

<p>
	removed
</p>
]]></description><guid isPermaLink="false">58620</guid><pubDate>Sat, 04 Apr 2026 19:40:00 +0000</pubDate></item><item><title>My code software was infected with a virus.</title><link>https://forum.kaspersky.com/topic/my-code-software-was-infected-with-a-virus-58618/</link><description><![CDATA[<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2026_04/image.png.cb063b5c09f65e935c6975744cd40dcc.png" data-fileid="38460" data-fileext="png" rel="">My code software was claimed to have a virus, and then a pop-up window prompted whether to handle it. After clicking on it, even after reinstalling the software, its functions could no longer be used normally.<img class="ipsImage ipsImage_thumbnailed" data-fileid="38460" data-ratio="53.60" width="500" alt="image.thumb.png.8db5ab56822873f29a9d26c94d90c383.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_04/image.thumb.png.8db5ab56822873f29a9d26c94d90c383.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><img class="ipsImage ipsImage_thumbnailed" data-fileid="38461" data-ratio="14.29" width="203" alt="image.png.89172e65368eaed4a802bcde9c251d45.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_04/image.png.89172e65368eaed4a802bcde9c251d45.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" />
</p>
<p>
	The virus alert message is: PDM: Trojan.Win32.Generic
</p>
<p>
	How can I solve this problem?
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">58618</guid><pubDate>Sat, 04 Apr 2026 13:03:00 +0000</pubDate></item><item><title>Cant get rid of a HEUR warning Kaspersky Standard</title><link>https://forum.kaspersky.com/topic/cant-get-rid-of-a-heur-warning-kaspersky-standard-58529/</link><description><![CDATA[<p>
	Very strange one (to me), illustrated in attache file. Thats the message I get up, but Ive run a complete deep scan and Ive individually scanned the files its pointing towards with Malware Bytes (with no reports) and all I'm getting on the Kaspersky scan is one file not processed .. which is the main file on the screenshot Ive shown.  Research tells me its fake trojan email warnings.  Ive tried the options to resolve and ignore and the pc just hangs.
</p>

<p>
	Should I just add to exclusions, if indeed it allows me to do that.  I'm fairly sure theres nothing on the PC, and emails are regularly deleted anyway
</p>

<p>
	Windows 11 PC, betterbird (Ive just changed to betterbird from mailbird so its a bit of a coincidence that this has happened after never having happened before
</p>

<p>
	Thanks 
</p>

<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_03/Screenshot(344).png.b75bfe85562e1265a712830cd1781a4f.png" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="38308" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/Screenshot(344).thumb.png.36a21fe10914312945a2c67cf8ae41cc.png" data-ratio="37.8" width="500" class="ipsImage ipsImage_thumbnailed" alt="Screenshot (344).png"></a></p>]]></description><guid isPermaLink="false">58529</guid><pubDate>Thu, 26 Mar 2026 10:15:05 +0000</pubDate></item><item><title>My API has been marked as phishing by Kaspersky Internet Security</title><link>https://forum.kaspersky.com/topic/my-api-has-been-marked-as-phishing-by-kaspersky-internet-security-58522/</link><description><![CDATA[<p>
	Hello,
</p>

<p>
	The API for our website, api.apexyama.com, has been incorrectly marked as a phishing threat by Kaspersky Internet Security.
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2026_03/image.png.8bcd41d0bfa1e3c8b6d4ee733b2e469c.png" data-fileid="38302" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38302" data-ratio="46.00" width="500" alt="image.thumb.png.13cd983a44a8067c54b077cc8e7fb2d3.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/image.thumb.png.13cd983a44a8067c54b077cc8e7fb2d3.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	I can assure you that we are not involved in any phishing activity. I am entirely willing to share the source code of our website privately if it is needed to remove this false-positive detection.
</p>

<p>
	We are a company based in Turkey, and we process transactions through iyzico, a leading payment provider that is also utilized by Amazon. I am happy to provide any official company documents to verify our identity, if necessary.
</p>

<p>
	Thanks in advance!
</p>
]]></description><guid isPermaLink="false">58522</guid><pubDate>Wed, 25 Mar 2026 12:46:19 +0000</pubDate></item><item><title>False Positive: incorrectly flagged as phishing by Kaspersky</title><link>https://forum.kaspersky.com/topic/false-positive-incorrectly-flagged-as-phishing-by-kaspersky-58519/</link><description><![CDATA[<p>
	Our domain, <span><span style="color:inherit;">swapped.com</span></span>, is being flagged as a false positive. (<a href="https://opentip.kaspersky.com/swapped.com/?tab=lookup" rel="external nofollow">https://opentip.kaspersky.com/swapped.com/?tab=lookup</a>) 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" data-fileext="png" data-fileid="38296" href="https://forum.kaspersky.com/uploads/monthly_2026_03/Skrmbillede2026-03-25kl_11_32_48.png.108c5f1d6b1272015c48bf40a831b08a.png" rel=""><img alt="Skrmbillede2026-03-25kl_11_32_48.thumb.png.60177549d97abcba20a6468371712ee7.png" class="ipsImage ipsImage_thumbnailed" data-fileid="38296" data-ratio="48.60" style="height:auto;" width="500" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/Skrmbillede2026-03-25kl_11_32_48.thumb.png.60177549d97abcba20a6468371712ee7.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
	We have reported the false positive several times, but got no answer: <a href="https://forum.kaspersky.com/topic/kaspersky-how-to-report-false-positive-22328/" rel="">https://forum.kaspersky.com/topic/kaspersky-how-to-report-false-positive-22328/</a> <br />
	We do not impersonate other brands and do not request wallet seed phrases or credentials outside our authenticated flow.<br />
	<br />
	Swapped has been running since 2022. We are regulated company, regulated by the Financial authorities in Denmark, Norway, Australia, Canada, and the US.<br />
	We are a regulated VASP and Digital Currency Exchange. We are MiCA compliant and have been in the industry for 4+ years at this point.<br />
	<br />
	We have not been involved in any phishing activity, and the block that Kaspersky applies to Swapped materially negatively affects our business operations. Hereby kindly requesting that you remove our domain from the blacklist.<br />
	<br />
	You can find our registrations with financial regulators below.<br />
	<br />
	Denmark: <span style="color:inherit;"><a href="https://virksomhedsregister.finanstilsynet.dk/virksomhed-under-tilsyn-en.html?v=B513844C-D285-EC11-A2D7-005056907186" rel="external nofollow" style="color:#1264a3;">https://virksomhedsregister.finanstilsynet.dk/virksomhed-under-tilsyn-en.html?v=B513844C-D285-EC11-A2D7-005056907186</a></span><br />
	Norway:  <span style="color:inherit;"><a href="https://www.finanstilsynet.no/en/finanstilsynets-registry/details/?id=248545" rel="external nofollow" style="color:#1264a3;">https://www.finanstilsynet.no/en/finanstilsynets-registry/details/?id=248545</a></span><br />
	Canada: Visit <span style="color:inherit;"><a href="https://fintrac-canafe.canada.ca/msb-esm/reg-eng" rel="external nofollow" style="color:#1264a3;">https://fintrac-canafe.canada.ca/msb-esm/reg-eng</a></span> and look up 'Swapped APS'<br />
	Australia: Swapped ApS is a registered Digital Currency Exchange under AUSTRAC in Australia with registration number DCE100879379-001.<br />
	US: Visit <span style="color:inherit;"><a href="https://www.fincen.gov/resources/msb-state-selector" rel="external nofollow" style="color:#1264a3;">https://www.fincen.gov/resources/msb-state-selector</a></span> and look up 'Swapped' as the legal name.
</p>
]]></description><guid isPermaLink="false">58519</guid><pubDate>Wed, 25 Mar 2026 10:43:58 +0000</pubDate></item><item><title>False Positive Moza Updater / MaintenanceTool</title><link>https://forum.kaspersky.com/topic/false-positive-moza-updater-maintenancetool-58525/</link><description><![CDATA[<p>
	I was just about to update the "Moza Pit House" software, but during installation, MaintenanceTool.exe and MOZA Updater.exe were "detected" as PDM:Trojan.Win32.Generic. According to the internet, other antivirus providers have already encountered this problem with older versions.<br />
	When I try to restore the files, I get a message saying the folder no longer exists, even though I can open the file path. Now I have to reinstall the software.
</p>

<p>
	Even when I reinstall it, I'm asked to update, and Kaspersky wants to delete the data again.
</p>

<p>
	I uploaded the files to VirusTotal, since I'm not sure if I'm allowed or should upload them here.
</p>

<p>
	MOZA Updater.exe 989ee1bfdc8cdcc4cab4f69511634f85613442ed10d012863dc4b43849f373d9
</p>

<p>
	MaintenanceTool.exe 5026591e471cd9367ceb13765c6c95448b723f3039fe461136d6ab3cfc22de91
</p>
]]></description><guid isPermaLink="false">58525</guid><pubDate>Wed, 25 Mar 2026 16:53:17 +0000</pubDate></item><item><title>Can't remove powershell.exe marked as Trojan, HEUR:Trojan-Downloader.BAT.Agent.gen</title><link>https://forum.kaspersky.com/topic/cant-remove-powershellexe-marked-as-trojan-heurtrojan-downloaderbatagentgen-58411/</link><description><![CDATA[<p>
	<strong><em>I'm not using English Kaspersky.</em></strong><br />
	<strong>Issue: </strong>powershell.exe repetitively marked as trojan, unable to remove completely.<br />
	<strong>OS: </strong>Windows 11<br />
	Kaspersky Plus
</p>

<p>
	<strong>Context:</strong> Seems to be a trojan I got from running a bad .exe
</p>

<p>
	<br />
	<strong>Full process:</strong>
</p>

<p>
	First running yesterday (Windows security detected and removed the supposed trojan right away)but haven't started until the first startup of today, powershell ran weird commands, my discord account was the first to get infected. Has already changed password, so far other account hasn't been infected yet. powershell hasn't started up ever since even if I were to try to restart my pc.
</p>

<p>
	 A ScreenImage.png was created in temp folder, seems to be updated regularly, first generated the same time I started up my pc, I haven't restarted the pc since started doing a full scan with kaspersky, not sure whether it's stopped because of the scan or screenshots only taken after startup.
</p>

<p>
	It seems that a registry key was removed related to powershell? I did find a suspicous powershell registry key manually but wasn't sure whether it's geniune, no longer find it, (kaspersky may had removed the very same registry.)<br />
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2026_03/image.png.484a635ef4edfb685b7f1d3933ea7b6d.png" data-fileid="38060" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38060" data-ratio="16.80" width="500" alt="image.thumb.png.73b62b48f6ca14bed7a234dae881d962.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/image.thumb.png.73b62b48f6ca14bed7a234dae881d962.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a><br />
	<br />
	<br />
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2026_03/image.png.9f05f223a33d6981fd75f16a2ce88a0b.png" data-fileid="38059" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38059" data-ratio="59.80" width="500" alt="image.thumb.png.48541a4b429efbb33cdf70ac417b1a0b.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/image.thumb.png.48541a4b429efbb33cdf70ac417b1a0b.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	I'm not sure how should I proceed next, any help would be appreciated, can provide more information if needed.
</p>
]]></description><guid isPermaLink="false">58411</guid><pubDate>Sat, 14 Mar 2026 07:19:51 +0000</pubDate></item><item><title>Kaspersky Android flags Samsung Internet as trojan</title><link>https://forum.kaspersky.com/topic/kaspersky-android-flags-samsung-internet-as-trojan-56961/</link><description><![CDATA[<p>
	All of sudden, it flags Samsung Internet as Trojan as in the picture.
</p>

<p>
	It only asked me to block it, then navigate me to the app setting. You CANT block Samsung Internet if you want to browse internet. Right? Then the report says no threats found.
</p>

<p>
	I tried Avast and Bitdefender, none of them detected anything.
</p>

<p>
	Another false positive?
</p>

<p>
	 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2025_10/KAV1.jpg.93a4c4e796d5866c4c90b7acab8eac7f.jpg" data-fileid="35471" data-fileext="jpg" rel=""><img alt="KAV 1.jpg" class="ipsImage ipsImage_thumbnailed" data-fileid="35471" data-ratio="216.45" style="height:auto;" width="231" data-src="https://forum.kaspersky.com/uploads/monthly_2025_10/KAV1.thumb.jpg.89254096c3cf467de1b16ef8b6a9fb8c.jpg" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2025_10/KAV2.jpg.e40938abcbfb75ea49265cff30a04933.jpg" data-fileid="35472" data-fileext="jpg" rel=""><img alt="KAV 2.jpg" class="ipsImage ipsImage_thumbnailed" data-fileid="35472" data-ratio="216.45" style="height:auto;" width="231" data-src="https://forum.kaspersky.com/uploads/monthly_2025_10/KAV2.thumb.jpg.0e1b717a325df39906b208fe6fbf8fcd.jpg" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>
]]></description><guid isPermaLink="false">56961</guid><pubDate>Sun, 26 Oct 2025 16:36:41 +0000</pubDate></item><item><title>Kaspersky Standard seems to cause an issue with Workona Tab Manager</title><link>https://forum.kaspersky.com/topic/kaspersky-standard-seems-to-cause-an-issue-with-workona-tab-manager-58402/</link><description><![CDATA[<p>
	 
</p>

<p>
	O/S = Windows 11
</p>

<p>
	ARV = Kaspersky Standard v21.24.8.422(a)
</p>

<p>
	 
</p>

<p>
	I use <a href="https://microsoftedge.microsoft.com/addons/detail/tab-manager-by-workona/gdfnelpciiajgjenlapgkdcjpcfpfpob" rel="external nofollow">Workona Tab Manage</a>r every day.  Today, when I rebooted my laptop I was bit startled to see that rather than load my tabs, Kaspersky decided to block this action.   Is this a an Edge Chromium or Kaspersky issue?
</p>

<p>
	 
</p>

<p>
	<a class="ipsAttachLink ipsAttachLink_image" href="https://forum.kaspersky.com/uploads/monthly_2026_03/Kasperski-workona.png.1513e3aaaf10a4e7edc47aaffbea92f0.png" data-fileid="38048" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" data-fileid="38048" data-ratio="71.60" width="500" alt="Kasperski-workona.thumb.png.2a4218c148364c7df188144f06673f05.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/Kasperski-workona.thumb.png.2a4218c148364c7df188144f06673f05.png" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" /></a>
</p>

<p>
	 
</p>
]]></description><guid isPermaLink="false">58402</guid><pubDate>Thu, 12 Mar 2026 14:46:17 +0000</pubDate></item><item><title>Kaspersky Plus removed my mic software</title><link>https://forum.kaspersky.com/topic/kaspersky-plus-removed-my-mic-software-58353/</link><description><![CDATA[<p>
	Hey, so I have a Shure MV6, and been using the MOTIV mix software to run my mic with all its settings for a long time, today I load up my PC and suddenly Kaspersky feels the software is a risk and wants to remove it and all its files. It wouldn't allow me to stop the removal and just straight up removed it. My PC got forcefully rebooted, at which point my PC wouldn't recognize my login credentials, I found a fix for that part which was simply restarting my PC several times until it worked... weird but true... MOTIV Mix has had no updates so nothing has changed on their end.. It wont allow me to add it to the trusted list, wont allow me to re-install it. It just removes the file when I try to re-install it. <br />
	<br />
	I've lost all my settings for my mic (which took hours to get set up and just right).. To some this might not be a "big thing", but I rely on that software for my live streams and recordings. <br />
	<br />
	Why would Kaspersky suddenly want to remove it after all this time? Its one of the most popular software's for Microphones especially if you own a Shure Mic.<br />
	<br />
	This has happened with other software in the past and at this point making me reconsider renewing my account. 
</p>
]]></description><guid isPermaLink="false">58353</guid><pubDate>Sun, 08 Mar 2026 18:00:36 +0000</pubDate></item><item><title>Michael Swift</title><link>https://forum.kaspersky.com/topic/michael-swift-58236/</link><description><![CDATA[<p>
	Hi, I’ve used Kaspersky for donkey’s years without any problems, last year I had to move to the new version, Kaspersky Standard.
</p>

<p>
	All seemed well until in the Notification Centre Status, Recommendations 2, and Protection 39 Objects.
</p>

<p>
	The Recommendations are fixed and vanish but the 39 Objects remain, I’ve tried all the Resolve all options but nothing removes them.
</p>

<p>
	My previous Kaspersky, KIS, version worked perfectly but this one is very confusing.
</p>

<p>
	HELP!
</p>
]]></description><guid isPermaLink="false">58236</guid><pubDate>Thu, 19 Feb 2026 13:30:08 +0000</pubDate></item><item><title>Milhares de detec&#xE7;&#xF5;es ap&#xF3;s atualiza&#xE7;&#xE3;o do banco de dados do Kasper</title><link>https://forum.kaspersky.com/topic/milhares-de-detec%C3%A7%C3%B5es-ap%C3%B3s-atualiza%C3%A7%C3%A3o-do-banco-de-dados-do-kasper-58312/</link><description><![CDATA[<p>
	<span>Hoje, após atualizar o banco de dados do Kaspersky, meu computador passou a apresentar milhares de detecções de vírus. O antivírus começou a identificar como maliciosos até mesmo arquivos e programas do próprio Windows.</span>
</p>

<p>
	 
</p>

<p>
	<span>Depois que realizei as varreduras e permiti que o antivírus removesse ou colocasse em quarentena os arquivos detectados, o sistema operacional acabou sendo corrompido e passou a apresentar falhas graves.</span>
</p>

<p>
	 
</p>

<p>
	<span>Consegui analisar o primeiro arquivo que foi detectado como vírus no VirusTotal através do link abaixo:</span>
</p>

<p>
	<span>https://www.virustotal.com/gui/file/f7a6eb1d9e42c7b678fcd4ec457b352a0ea5baf18a608742acb24863f70fb9ea/detection</span>
</p>

<p>
	 
</p>

<p>
	<span>Minha dúvida é: esse arquivo poderia ter sido responsável por infectar milhares de outros arquivos no sistema, ou há possibilidade de ter ocorrido um falso positivo após a atualização do antivírus?</span>
</p>

<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_03/p1.jpeg.b39f8409cab3000e7266570def94f9e2.jpeg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="37876" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/p1.thumb.jpeg.ba8d9b7a00fd8607f39b24a7576f5908.jpeg" data-ratio="133.33" width="375" class="ipsImage ipsImage_thumbnailed" alt="p1.jpeg"></a></p>
<p><a href="https://forum.kaspersky.com/uploads/monthly_2026_03/p2.jpeg.d86ef03a4efe958f34e0e5d60c3a87e3.jpeg" class="ipsAttachLink ipsAttachLink_image" ><img data-fileid="37877" src="https://forum.kaspersky.com/applications/core/interface/js/spacer.png" data-src="https://forum.kaspersky.com/uploads/monthly_2026_03/p2.thumb.jpeg.637e6a7baf4929824ed59c3b445e0efd.jpeg" data-ratio="133.33" width="375" class="ipsImage ipsImage_thumbnailed" alt="p2.jpeg"></a></p>]]></description><guid isPermaLink="false">58312</guid><pubDate>Tue, 03 Mar 2026 03:04:12 +0000</pubDate></item><item><title>HEUR:Trojan.VBS.SAgent.gen - Thunderbird infection</title><link>https://forum.kaspersky.com/topic/heurtrojanvbssagentgen-thunderbird-infection-58293/</link><description><![CDATA[<p>
	Hi, I just noticed that my computer has been infected by a trojan called "HEUR:Trojan.VBS.SAgent.gen", and I can't remove it via Kapersky...The trojan is found in the inbox file in Thunderbird. So it's not a file that I can remove (it's all code). Kapersky stated that these two files are the source of the Trojan (they are not found as an e-mail attachment in my inbox, it's all code in the inbox file in Thunderbird):<br />
	<br />
	P000009384:Emirates_Marble-pdf.gz and P000009384:Emirates_Marble-pdf.vbs<br />
	<br />
	So I'm simply wondering how I should go about to remove this trojan from my computer?<br />
	<br />
	Source:<br />
	<a href="https://threats.kaspersky.com/en/threat/HEUR:Trojan.VBS.SAgent.gen/" rel="external nofollow">https://threats.kaspersky.com/en/threat/HEUR:Trojan.VBS.SAgent.gen/</a>
</p>
]]></description><guid isPermaLink="false">58293</guid><pubDate>Sat, 28 Feb 2026 14:03:59 +0000</pubDate></item><item><title>Website False Positive</title><link>https://forum.kaspersky.com/topic/website-false-positive-58277/</link><description><![CDATA[<p>
	We've had an issue witht he site (https://patriotgolf.com) a few days ago and have already fixed it. We've added and subscribed to Wordfence to monitor any logins and changes on the site. We've also worked with our server provider to setup cloudflare and secure the site on their end. All admin user credentials have been updtaed with stonger logins. We've recently scanned on sitelock and wordfence and the website comes back clean now.
</p>

<p>
	We hope to hear from you soon. Thanks!
</p>
]]></description><guid isPermaLink="false">58277</guid><pubDate>Wed, 25 Feb 2026 20:19:24 +0000</pubDate></item><item><title>Website false positive?</title><link>https://forum.kaspersky.com/topic/website-false-positive-58278/</link><description><![CDATA[<p>
	Find <span>https://nswpedia.com/nintendo-switch-roms</span> got positive on Kaspersky as <a href="https://click.kaspersky.com/?hl=zh-Hans-CN&amp;customization=&amp;link=securelist&amp;vn=HEUR:Trojan.Script.MalCrack.gen&amp;serial=3A1B8DC6-B456-4EA8-85C3-8EB5E602B9EF&amp;hwid=FFFF57AF-9155-B496-DBC9-0D8FA9F8E661&amp;acaid=2271&amp;syst=Microsoft%20Windows%2011%2010.0.28020%20Service%20Pack%200%20Build%2028020&amp;pid=256-Win&amp;version=21.20.8.505&amp;hotfix=0" rel="external nofollow" style="background-color:#ffffff;border:0px;color:#157664;font-size:16px;padding:0px;vertical-align:baseline;">HEUR:Trojan.Script.MalCrack.gen</a> .
</p>

<p>
	However, <a href="https://www.virustotal.com/gui/url/65758c5365c663134ad1f7fa0af657096a4a8924f3d6ff5e5cce7f1a3c3c6abf" rel="external nofollow">https://www.virustotal.com/gui/url/65758c5365c663134ad1f7fa0af657096a4a8924f3d6ff5e5cce7f1a3c3c6abf</a> only two showed positive while this report on Kaspersky showed as good website, <a href="https://opentip.kaspersky.com/https%3A%2F%2Fnswpedia.com%2Fnintendo-switch-roms/?tab=web" rel="external nofollow">https://opentip.kaspersky.com/https%3A%2F%2Fnswpedia.com%2Fnintendo-switch-roms/?tab=web</a> . Is it a false positive?
</p>
]]></description><guid isPermaLink="false">58278</guid><pubDate>Wed, 25 Feb 2026 20:28:41 +0000</pubDate></item><item><title>False Positive: Site (Detected as Malicious/Spam)</title><link>https://forum.kaspersky.com/topic/false-positive-site-detected-as-maliciousspam-58257/</link><description><![CDATA[<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	Hello,<span><span></span></span>
</div>

<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	My website<span> </span><strong>https://intimchat.org</strong><span> </span>is currently flagged as "Malicious" or "Spam" by the Kaspersky engine on VirusTotal.<span><span></span></span>
</div>

<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	<strong>Context:</strong><br />
	The site was previously affected by a third-party malicious script (<code dir="ltr" style="background-color:#f0f2f5;border-color:#f0f2f5;border-style:solid;border-width:1px;font-size:14px;padding:2px 4px;">ntvpforever.com</code>), which caused the detection. I have performed a complete security audit, and the malicious code has been<span> </span><strong>entirely removed</strong>.<span><span></span></span>
</div>

<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	<strong>Verification:</strong><span><span></span></span>
</div>

<ol style="background-color:#ffffff;color:#0a0a0a;font-size:16px;padding:0px;">
	<li style="padding:0px;">
		<span><strong>Google Search Console:</strong><span> </span>No security issues found, the site is clean.</span>
	</li>
	<li style="padding:0px;">
		<strong><span style="background-color:#ffffff;color:#221a14;font-size:16px;">SOCRadar Cyber Intelligence: </span></strong><span style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">Already re-evaluated and cleared the domain</span>
	</li>
	<li style="padding:0px;">
		<span><strong>Current state:</strong><span> </span>The site is safe, no redirects or phishing.</span><span><span></span></span>
	</li>
</ol>

<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	I have already submitted several requests via<span> </span><strong>OpenTIP</strong><span> </span>(using this account), but the detection remains. Could you please manually re-verify the domain and update its status?<span><span></span></span>
</div>

<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	VirusTotal link: [<a href="https://www.virustotal.com/gui/url/7723120cd219943527b02ea9c8711933b61bbb93509cb64ff2d5a594524079bc?nocache=1" rel="external nofollow">https://www.virustotal.com/gui/url/7723120cd219943527b02ea9c8711933b61bbb93509cb64ff2d5a594524079bc?nocache=1</a>]<span><span></span></span>
</div>

<div style="background-color:#ffffff;color:#0a0a0a;font-size:16px;">
	Thank you!
</div>
]]></description><guid isPermaLink="false">58257</guid><pubDate>Mon, 23 Feb 2026 08:26:06 +0000</pubDate></item><item><title>RakhniDecryptor questions</title><link>https://forum.kaspersky.com/topic/rakhnidecryptor-questions-58258/</link><description><![CDATA[<p>
	Back in 2019 my QNAP NAS was hacked and many files were encrypted with ransomware.
</p>

<p>
	Fortunately it was possible to unencrypt them.  I no longer have the PC I used to do this but I am pretty sure I used Kaspersky RakhniDecryptor and this would have been in 2020.
</p>

<p>
	I've now discovered I missed unencrypting a folder with about 1500 files.  I think this was because there were too many files on the NAS to unencrypt at once so I needed to divide files into batches and through my own sloppiness, I missed a folder.
</p>

<p>
	I've tried to re-do the unencryption using the latest version of Kaspersky RakhniDecryptor and came across the following:
</p>

<p>
	- the original files were encrypted with the extension ".encrypt". The current version of Kaspersky RakhniDecryptor doesn't seem to recognise this.  It does seem to recognise the suffix ".encrypted".  I can change the file extension to ".encrypted" but would prefer not do have to do this. Can Kaspersky RakhniDecryptor not recognise files with extension "encrypt" because I am pretty sure it could back in 2020.
</p>

<p>
	- I ran Kaspersky RakhniDecryptor on a small batch of files with extension changed to ".encrypted" and eventually it did find the password to decrypt and this is stored in the log file.  However I did this on a PC I borrowed for a short time (I now have a Mac at home, not a PC) and have got another PC to do the rest of the files and needed to reinstall Kaspersky RakhniDecryptor.  I couldn't see a way to provide the decryption password to Kaspersky RakhniDecryptor.  Is this possible? 
</p>

<p>
	- 
</p>
]]></description><guid isPermaLink="false">58258</guid><pubDate>Mon, 23 Feb 2026 11:50:26 +0000</pubDate></item></channel></rss>
