Jump to content

Recommended Posts

MisslinkQn
Posted

I got a notification around 2.55pm today (20 Nov 2024) from Kaspersky saying malicious object detected: HEUR:Trojan.Multi.Misslink.a

I clicked on it too clickly and was not able to check what the detection item actually was, to diagnose where it came from.

Here are the 3 logs for disinfection:

Quote

    Event: Malicious object detected
    User: DESKTOP-733BC02\TRN
    User type: Active user
    Component: Virus Scan
    Result: Detected
    Result description: Detected
    Type: Trojan
    Name: HEUR:Trojan.Multi.Misslink.a
    Precision: Exactly
    Threat level: High
    Object type: File
    Object name: Run:Steam
    Object path: reg:\HKU\S-1-5-21-2532791771-2465090974-211415688-1000\Software\Microsoft\Windows\CurrentVersion
    Reason: Expert analysis
    Databases release date: Today, 20/11/2024 1:03:00 pm

Quote

    Event: Object disinfected
    User: DESKTOP-733BC02\TRN
    User type: Active user
    Component: Virus Scan
    Result: Disinfected
    Result description: Disinfected
    Type: Trojan
    Name: HEUR:Trojan.Multi.Misslink.a
    Precision: Exactly
    Threat level: High
    Object type: File
    Object name: Run:Steam
    Object path: reg:\HKU\S-1-5-21-2532791771-2465090974-211415688-1000\Software\Microsoft\Windows\CurrentVersion

Quote

    Event: Task completed
    Application name: avp.exe
    Application path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.19
    User: DESKTOP-733BC02\TRN
    User type: Active user
    Component: Virus Scan
    Result: Task completed

How or what can I check or use to determine the source of this registry key that was so threatening? I want to know what malicious launch activity it was doing while disguising itself with Run:Steam.

Posted

@MisslinkQn Welcome

Quote

 Object path: reg:\HKU\S-1-5-21-2532791771-2465090974-211415688-1000\Software\Microsoft\Windows\CurrentVersion

Hard to tell 🤔 , i found ↓ this ↓ which is related to [SearchForm.ComboBoxKey]

Spoiler

HEUR_Trojan_Multi_Misslink_a.thumb.jpg.e93849359b958e47dede21463d508c30.jpg


 

  • Like 1
MisslinkQn
Posted (edited)
On 11/20/2024 at 6:03 PM, Berny said:

@MisslinkQn Welcome

Hard to tell 🤔 , i found ↓ this ↓ which is related to [SearchForm.ComboBoxKey]

  Hide contents

HEUR_Trojan_Multi_Misslink_a.thumb.jpg.e93849359b958e47dede21463d508c30.jpg


 

Apologies but I'm not really familiar with registry specifics so I'm not sure what this means?

How would I use this to dig deeper/further

Edited by MisslinkQn
Posted

@MisslinkQn

During the install applications are creating registry keys. In your case, locating the malicious object related to a Reg Key  after a Kaspersky detection and disinfection is not possible

Spoiler

k_kaspersky_register.thumb.jpg.a5e9abf6aa0daa8a453ef48276147769.jpg

 

  • Like 1
MisslinkQn
Posted
On 11/22/2024 at 6:10 PM, Berny said:

@MisslinkQn

During the install applications are creating registry keys. In your case, locating the malicious object related to a Reg Key  after a Kaspersky detection and disinfection is not possible

  Hide contents

k_kaspersky_register.thumb.jpg.a5e9abf6aa0daa8a453ef48276147769.jpg

 

I am just trying to figure out if it was a false positive, or if something that I had recently installed had genuinely created a malicious entry.

Kaspersky has been known to false flag many of my code caved client/exe in the past, I am trying to determine if I experienced a genuine intrustion or not

MisslinkQn
Posted
On 11/24/2024 at 1:33 AM, Berny said:

@MisslinkQn

You have to submit one of your codes in the past  ?

Sorry, what do you mean?

Posted

@MisslinkQn  Hi

No 'sorry' of course ... ↓ i was referring to  ↓

On 11/23/2024 at 2:00 PM, MisslinkQn said:

Kaspersky has been known to false flag many of my code caved client/exe in the past

If the detection from the 'registry object path' is related to  your code  ,
then you could eventually submit a potential related exe object from the past 🤔 ?

MisslinkQn
Posted (edited)
On 11/27/2024 at 11:43 PM, Berny said:

@MisslinkQn  Hi

No 'sorry' of course ... ↓ i was referring to  ↓

If the detection from the 'registry object path' is related to  your code  ,
then you could eventually submit a potential related exe object from the past 🤔 ?

That's a separate issue, please stop conflating them.
A past false detection is not a confirmation that the incident this topic concerns is also a false detection. I need to identify the cause for this false detection

Edited by MisslinkQn
MisslinkQn
Posted (edited)

Oh my god I think I'm going insane, I didn't mean to say "I need to identify the cause for this false detection"

I wanted to say "I need to identify the cause for the detection I posted in the OP"

I'm sorry I'm really tired

Edited by MisslinkQn

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...