Jump to content

Kaspersky detected two threats, but it is unclear if it is doing anything about it.


Recommended Posts

happyhappy
Posted

Is Kaspersky just telling me it found two threats or did it got rid of it? If not, how can I make it get rid of it?

Those are the notificiations I received:

Threat One:

Evento: Detectado link perigoso aberto anteriormente
Usuário: LAPTOP-BF7Q1A76\alici
Tipo de usuário: Iniciador
Nome do aplicativo: msedge.exe
Caminho do aplicativo: C:\Program Files (x86)\Microsoft\Edge\Application
Componente: Navegação Segura
Descrição do resultado: Não processado
Tipo: Link malicioso
Precisão: Exatamente
Nível de ameaça: Alto
Tipo de objeto: Página da Web
Nome do objeto: 4be1a5d1-14ab-44ae-bea7-d55de09afac0
Caminho do objeto: https: // myincoffer . online /go
Motivo: Proteção na Nuvem

In "Threat one" kaspersky is saying that the result it "not processed". I have no idea what that is.

Threat Two:

Evento: Objeto malicioso detectado
Usuário: LAPTOP-BF7Q1A76\alici
Tipo de usuário: Iniciador
Nome do aplicativo: msedge.exe
Caminho do aplicativo: C:\Program Files (x86)\Microsoft\Edge\Application
Componente: Navegação Segura
Descrição do resultado: Detectado
Tipo: Cavalo de Troia
Nome: HEUR:Trojan.Script.Generic
Precisão: Análise Heurística
Nível de ameaça: Alto
Tipo de objeto: Arquivo
Nome do objeto: loadfisticling.html
Caminho do objeto: https:// waitplz-pag1 . b-cdn . net
MD5 de um objeto: FE1886387B66E61519C4C1D28A3E62E1
Motivo: Análise especializada
Data da versão dos bancos de dados: Hoje, 29/10/2024 03:43:00

However, on threat two, it seems that it is implying that something was downloaded. But there is nothing in regards of any "result".

harlan4096
Posted

Welcome to Kaspersky Community.

 

The 2 detections come from the module "Navegação Segura" (Web Anti-Virus), and K. by default just block and denies the access to those sites, so nothing else to do.

  • Like 1
happyhappy
Posted

There are times in which things appear as "Blocked" under the section "Results"

But this time they were labeled as "Not Processed" and the second one as "Detected"

The description of the second one is "Event: Malicious Object Detected" and the "type of the object" is labeled as "Archive".

Doesnt it mean that it bypassed the block?

  • Like 1
harlan4096
Posted

Check Your \Downloads folder, if anything suspicious.

 

I guess if already was blocked, no need to be processed, unless it finally was downloaded.

happyhappy
Posted

If kaspersky is telling me a malicious object was detected, shouldnt the second report tell what it is and what to do?

This is what I am asking. What does the second threat report means and how should I proceed about it?

  • Like 1
harlan4096
Posted

The object is this one: Nome do objeto: loadfisticling.html

happyhappy
Posted

And what should be done about it?

harlan4096
Posted

Nothing? That file is in server side, You can't remove it (just block it), unless it was downloaded, check Downloads log in Your browser and folder \Downloads.

happyhappy
Posted

It doesnt really appear as anything that is visible to me. 

When Kaspersky Safe Browsing labels the result as "malicious object detected" instead of the usual "Blocked", doesnt it mean that something was downloaded? 

 

  • Like 1
harlan4096
Posted

Probably not, as already told, the default action in this case is Block the access, in fact, You probably got the warning of the access to that site.

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...