Jump to content

Recommended Posts

V.i.k.t.o.r
Posted

I have a problem with the Rhadamanthys PSW trojan. Kaspersky finds it in the path: pmem:\C:\Windows\SysWOW64.I also tried cleaning in Safe Mode and there is no change. I checked the detected "infected" svchost.exe file from the SysWOW64 directory online, and nothing unusual is reported. After cleaning without restarting, Kaspersky reports infection of e.g. Firefox tabs, Twitch... programs that are currently active. Ignoring and adding to exceptions does not work. To open the infected file from the antivirus I need a special program to read from pmem:.

harlan4096
Posted

Welcome to Kaspersky Community.

 

Please provide version of operating system and K. product installed.

 

Also, attach a capture with the K. details of the detection.

V.i.k.t.o.r
Posted

I have Windows 11 Pro and Kaspersky Standard.

Why does Kaspersky AV ask me to put kaspersky.com in the exceptions as unsafe?

Screen-2025-10-07_09-50-15.jpg

  • Like 1
harlan4096
Posted

Kaspersky Standard 21.22a or b?

 

V.i.k.t.o.r
Posted

21.22.7.466(b)

  • Like 1
harlan4096
Posted

Could You change temporally Your K product into English with key combination SHIFT + F12, as You can guess I can understand Russian language in Your captures 😊

V.i.k.t.o.r
Posted

Screen-2025-10-07_09-50-15.thumb.jpg.0da997378220138ca984f7291715c790.jpg

This is the best it can do. It's Serbian Cyrillic. In the interface settings I only have options for Serbian Cyrillic and Latin. I assume the order of the columns with information is the same in the English version...

Откривено - Discovered

Није могућа дезинфекција - Disinfection is not possible.

није обрађено - Not processed

Тројанац - Trojan

Тачно - Accurate

Веома - High

Датотека - File

  • Like 1
Posted

↓ EN translation attempt ↓🤔

translate_EN.thumb.jpg.cb9c26e760e570a968808b1837c2bb4f.jpg

  • Thanks 1
Posted
1 час назад, V.i.k.t.o.r сказал:

I checked the detected "infected" svchost.exe file from the SysWOW64 directory online, and nothing unusual is reported. After cleaning without restarting, Kaspersky reports infection of e.g. Firefox tabs, Twitch... programs that are currently active. Ignoring and adding to exceptions does not work.

Svchost.exe is not being detected. This is a file that tried to access malicious code in the System Memory, after which it was scanned and detected. Try to perform an Advanced Disinfection (disinfection with a restart), if it's still offered. Ignoring and adding to exceptions is a bad idea.

  • Like 1
Posted
6 минут назад, V.i.k.t.o.r сказал:

Done many times so far.

And what information do you want to get here on the forum?

More possible solutions. Perform KRD scan (download, instructions). Contact support team. Create a topic on the KL club's forum (in Russian), the rules are here.

  • Like 1
V.i.k.t.o.r
Posted
10 minutes ago, AlexeyK said:

And what information do you want to get here on the forum?

I want to know what else I can try. If a trojan is TRYING to run and Kaspersky keeps notifying me about it but can't block/clean it, it would at least help if I didn't get popups (that can't be hidden) every time notifying me of something trying to do something.

Posted

With KRD you can boot the system, and remove manually that file.

 

Would be interesting to get that file and send it to K. analysts, or maybe is it a false positive? 🤔

The quality of captures is very low, but... WAIT A MOMENT!!!

 

image.thumb.png.eef02146d130254836bfbec2954585d0.png

 

IS THAT AN "O" AND NOT A C??????????????? 

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...