Jump to content

Xeno

Members
  • Posts

    43
  • Joined

  • Last visited

Posts posted by Xeno

  1. 8 hours ago, harlan4096 said:

    Welcome to Kaspersky Community.

     

    Why in the hell did You double-clicked on that unknown archive not being inside a virtual machine? 🤦‍♂️🤦‍♂️🤦‍♂️🤦‍♂️🙄

    🤷‍♂️

    Aren't you ever going to learn?

     

    If You have default deny setup (I know You know my default deny settings guide), probably no file was executed if it is unknown to KSN and / or it is not digitally signed, it was a compressed file or?

     

    Can You send me the file via personal message of the community?

    Hello, the file was a .rar that I double clicked. I wasnt trying to execute it, I was trying to see whats inside of the archive.

    I've handled this issue on my own though. I've checked the hash of the executable (its unknown to Kaspersky or VT), meaning it would be placed in a restricted group. This archive was also password protected, and I never entered a password for it 🤦‍♂️. If you somehow can execute a password protected file without the password, let me know :D.

    Harlan, don't worry, I wont be messing with malware again. I've realized most of the times I do it, I ask for people's help to ensure i'm not infected and its not worth the time for them or for me.

    • Like 1
  2. Hello! I'm using Kaspersky Premium with a default deny intrusion prevention setup. I was looking at a obviously fake adobe file for malware analysis (just uploading to sandboxes) when I had the file on my PC and double clicked the archive to see what was inside. When I double clicked, it didnt show the inside of the archive (I tried this twice, still nothing), and I am a bit concerned that the file might have actually ran.

    I have checked Intrusion Prevention, no file called "setup.exe" (which is what the file is) is there. I have also scanned with: Kaspersky, Sophos, Malwarebytes, ESET, and Emsisoft, they have found nothing.

    Should I be concerned about a infection? I dont think intrusion prevention would just stop working suddenly, but I am a bit concerned since the file has zero virus total detections and wasnt picked up by Kaspersky via static detection.

    https:// tria . ge/231230-azz71aagaj/behavioral2 incase you need the file, here it is.

  3. 7 hours ago, Yury Parshin said:

    It is impossible to block generically all vulnerable drivers in advance because we are working on the same access level. But is is possible to block known drivers, rules for blocking are updated regularly

    Couldnt it be possible though to stop unknown drivers - take the safe rather than sorry approach. In theory really, you shouldnt have unknown applications try to terminate Kaspersky.

  4. I was looking around on this forum: https://malwaretips.com/threads/suspicious-game.124193/

    There is a suspicious game getting past Opentip, Kaspersky's Scanner, and Behavioral detection. People have analyzed it and said that is a discord stealer that steals your discord token however it pops up a error which may mean its not doing its thing.

    I dont know where to submit things - I submitted on Opentip, but every time I've done that no one has ever responded back to me. 

×
×
  • Create New...