Jump to content

Recommended Posts

Wandering33
Posted

Hello!

As the title suggests I was downloading a program, Unity game engine from their Unity Hub program. Which I had done a scan on before installing and everything was fine. I started the download of the game engine using Unity's hub program, and left for work. When I came home hours later Kaspersky had a pop up in the bottom right corner of my screen saying it detected a Trojan. To restart the computer. The download did not complete and the computer was disconnected from the internet when I got home. I restarted the computer and followed trough the prompts Kaspersky took me down. Once I restarted the computer I did a full scan. I turned the PC off did another full scan. I also checked with Malwarebytes and nothing came up with any threats. So I am wondering did Kaspersky stop the Trojan from getting downloaded onto my computer? Or could this have been a false positive as I downloaded it right from the developers website then used their program to download the engine.

 

I am using version 21.17.7.539

Kaspersky Premium (I believe total security)

Windows 10

harlan4096
Posted

Welcome to Kaspersky Community.

 

Default action of K. would usually be blocking the access to a downloading malware, check Quarantine, also check Reports logs.

  • Like 1
Wandering33
Posted

I’ve checked quarantine and the report logs from what I can see there is nothing about Unity other than it trusting Unity Hub. There is nothing about a Trojan either. I am unable to find anything in the program. 

harlan4096
Posted

So, any detection in Reports Web Anti-Virus or File Anti-Virus modules? 🤔

  • Like 1
Wandering33
Posted

This is all I was able to find. I'm not seeing Web Anit- Virus on there.

Screenshot 2024-06-05 201452.jpg

Screenshot 2024-06-05 201247.jpg

Screenshot 2024-06-05 201059.jpg

  • Thanks 1
Flood and Flood's wife
Posted (edited)
1 hour ago, Wandering33 said:
  1. I'm not seeing Web Anit- Virus on there.

 

Hello @Wandering33

Thank you for the information!

  1. In 21.16.* onwards - Web Anti-Virus has been renamed to Safe Browsing. 

     2. 3 & 4 - Also, the screen-prints: in the horizontal column (you) can rightclick & filter out columns to hide things like User & or blank columns, then - in the top-right-corner to expand the Report window - select the maximise icon, go back to the actual report & select the relevant event so the event detail shows in the lower-half of the expanded window - then screen-print - as in the example below: 

image.thumb.png.e699c8729f263f78f293c587ac790c35.png

Thank you🙏
Flood🐳+🐋

Edited by Flood and Flood's wife
grammar & numbering
  • Like 1
Wandering33
Posted

Thank you. I tried that I don't have a lot in the safe browsing. I also have nothing in quarantine as well. I'm not able to find anything about it stopping the download at all.

Screenshot 2024-06-05 215634.jpg

Screenshot 2024-06-05 215611.jpg

Screenshot 2024-06-05 215508.jpg

  • Thanks 1
Flood and Flood's wife
Posted (edited)
38 minutes ago, Wandering33 said:

I tried that I don't have a lot in the safe browsing. I also have nothing in quarantine as well. I'm not able to find anything about it stopping the download at all.

Screenshot 2024-06-05 215508.jpg

Hello @Wandering33

Thank you for the information!

In File Anti-virus, in the Detail section, scroll down, to show the lower-section of the event, does it give a reason for the 'Not processed' event - see image below as an example:

image.thumb.png.f05588e8b6e7f29d7f17cce2f7566456.png

Thank you🙏
Flood🐳+🐋

Edited by Flood and Flood's wife
Added image
  • Like 1
harlan4096
Posted

Web Anti-Virus module now it is called -> Safe Browsing 😉

  • Like 1
Wandering33
Posted

It shows the reason as size

Screenshot 2024-06-06 075319.jpg

  • Thanks 1
harlan4096
Posted

It seems the detection it was in a specific file .dll file... check that temporal folder:

 

image.thumb.png.dfeb0f9d3a74a0248d14afe96ed3a406.png

  • Like 2
Wandering33
Posted

I tried but I couldn’t find the AppData folder under my user. 

harlan4096
Posted

It is a system folder, You have to un hide via Windows folder Options, the hidden files and folders.

Wandering33
Posted

Thank you. It's not there I got as far as temp but the nss7939.tmp wasn't there. Maybe when I did a disk cleanup it was removed?

  • Like 1
harlan4096
Posted

Yes, probably, since they were temporal files...

Wandering33
Posted

So do you think my computer is safe then? Since they are gone. 

harlan4096
Posted

If did not get again any detection, I would probably say that yes.

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...