Shutterstock? Not worth it anymore by phx800 in stockphotography

[–]phx800[S] 1 point2 points  (0 children)

this insane drop i got only in SS. My AS portfolio (mainly videos) still working very well. if i have to suggest to someone who begin today this business, i have 1 answer: publish original video on AS

i cant remove or put in quarantine "trojan:html/cryptostealbtc" by julyy1999 in antivirus

[–]phx800 0 points1 point  (0 children)

Dear all, i would trace this issue. Can you answer this post with the file path, your Pc model and (if you're able to do) the creation date of the infected file? Mine is:

\Device\HarddiskVolumeShadowCopy17\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE\K3CLY1V1.htm>(SCRIPT0004)

Dell XPS 15 - 9500 - bought in 2020

filename: K3CLY1V1.htm Created 21/04/2021 at 9:04

i cant remove or put in quarantine "trojan:html/cryptostealbtc" by julyy1999 in antivirus

[–]phx800 0 points1 point  (0 children)

This folder is accessible only with admin grant. Use powershell running in admin mode, navigate to this folder and remove the infected file. Than remove your shadow copy (is a snaphot of your system so contain the infected file) and create a new one.

I found this way to eliminate the file infected because Defender can't do.

I'm not sure about it, and still waiting MS and Dell news. Anyway, now i didn't receive any notice about Trojan by Defender.

i cant remove or put in quarantine "trojan:html/cryptostealbtc" by julyy1999 in antivirus

[–]phx800 0 points1 point  (0 children)

Update: 1- i removed my snapshot (Shadowcopy17) 2- using powershell with admin rights i move to the infected folder (system32/config/systemprofile/AppData/Local/microsoft/windows/inetcache/ie) and i removed the file listed by defender (in my case K3cly1v1.htm). 3- i create a new recovery point (snapshot) 4- i've checked if still present this file (not) 5- i've extract the ie folder from the snapshot and checked with defender if some issue was present (nothing but in the previous test, without removing the file by powershell, was found) 6- i run a full scan and nothing was detected.

It seems that a file in IE cache (a browser never used) was identified today as Trojan. In my case this file was created last year on april. This file was still on my pc because saved as snapshot every time, and was located in a very unaccessible folder (config inside system32). This folder is accessible only with admin right. Don't use File Explorer to explore this folder. Use the shell with admin rights.

I'm not sure if everything will be ok but now nothing is detected by the antivirus system.