-
Posts
4974 -
Joined
-
Last visited
Posts posted by harlan4096
-
-
Welcome to Kaspersky Community.
Please, provide K. product version installed.
Also, check if You have installed and running an app called: HostAppService.exe (very suspicious)... check with Windows msconfig.exe tool the services and apps running during Windows Start:
-
1
-
-
Welcome to Kaspersky Community.
-
Quote
-
Do not monitor child application activity
- Apply exclusion recursively
- Do not inherit restrictions from the parent process (application)
-
Do not monitor child application activity
Enabling those exclusions for the main app that generates the random new cmd files every time should do the trick 🤔
Is it Your main app placed in Trusted group or in a restriction group? Since by default trusted apps should have access
without prompts for low-level disk access, see this capture, as an example:
-
-
I don't know, don't have the pdf file 🙂
You can upload to free cloud services, and send me the link to download via personal message of the forum.
-
Just check if that pdf file has any URL link...
-
Quote
Hello,
This is not a false alarm. This site is infected.
Here is the malicious code:
;if(typeof ndsj...If you are a webmaster, please remove the above code from the page. Also we strongly recommend that you change passwords to all services that can be used to modify website contents because they may have been stolen.
Best regards, Malware Analyst
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com https://securelist.com
https://opentip.kaspersky.com/ - get insights about suspicious files, hashes, URLs, IP addresses or domain names -
Welcome to Kaspersky Community.
Hum how can We confirm without the file...
Also, You can upload to KOTIP
-
1
-
-
I just sent your URL to K. analysts, waiting for final verdict.
-
1
-
-
Welcome to Kaspersky Community.
Please provide URL of the site.
-
1
-
-
Quote
Hello,
Dear User,
Thank you for sending a request to Kaspersky!
We have checked the link you sent us.
It has been confirmed as a false positive and excluded from our data loss threat protection databases.Best regards, Senior Web Content Analyst
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com https://securelist.com
https://opentip.kaspersky.com/ - get insights about suspicious files, hashes, URLs, IP addresses or domain names-
4
-
-
-
Your email address not visible now...
-
1
-
-
I have just moved Your thread, since You are using KIS, not anti-ransomware tool..
-
Welcome to Kaspersky Community.
Can You please provide the exact versions of K. product installed?
-
Quote
Hello,
Your request has been forwarded to the Data Loss Threats Protection Group.
Best regards, Malware Analyst
39A/3 Leningradskoe Shosse, Moscow, 125212, Russia Tel./Fax: + 7 (495) 797 8700 http://www.kaspersky.com https://securelist.com
https://opentip.kaspersky.com/ - get insights about suspicious files, hashes, URLs, IP addresses or domain names-
2
-
-
Welcome to Kaspersky community.
I just sent your URL to K. analysts, waiting for final verdict.
-
2
-
-
Can you post a capture of the exclusion, please?
-
¿Y dónde te lleva el Explorador, a qué carpeta? ¿Se ejecuta algo?
-
Me alegro 🙂
-
1
-
-
-
Sí, es posible, pero por defecto, K. bloquea esa opción, y habría que activarla igualmente manualmente, para que un usuario desde una conexión remota pudiera interactuar y modificar su configuración.
-
Extraño que esa opción estuviera en Informar, porque por defecto viene fijada en la 1ª opción.
Activar las demás opciones y poner la Heur al máximo en este módulo puede ralentizar considerablemente la navegación en algunas páginas.
-
-
Bienvenid@ a la Comunidad de Kaspersky.
¿Por favor, puedes indicar la versión exacta de producto Kaspersky Premium tienes instalada?
Comprueba, además, que las opciones del módulo Navegación Segura, están como en esta captura:
También comprueba en Exclusiones y acciones al detectar objetos:
Saludos.
-
@steve33: where are You from?
-
1
-
I want to confirm that the pdf file
in Virus and Ransomware related questions
Posted
I think that file is clean...