<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Threat Found in Opera Cache?]]></title><description><![CDATA[<p dir="auto">So I was browsing the internet using Opera and I get a notification from Windows Defender:</p>
<p dir="auto"><img src="/assets/uploads/files/1592360848860-8f4c4b67-17f2-4561-9a5a-c0dedccd6df5-image.png" alt="8f4c4b67-17f2-4561-9a5a-c0dedccd6df5-image.png" class=" img-responsive img-markdown" /></p>
<p dir="auto">The weird thing is, I went to go investigate this cache file "f_0022005", I could not find it in the Cache Folder. After I couldn't find it I clicked on "Actions" and removed the threat. Does anyone know what this is or how I got it? Also why was the file "f_002205" not located in the cache folder?</p>
<p dir="auto">From what I remember I didn't go on any sites suspicous. I believe the site I was currently on when I got this notificaion was a <a href="http://drop.com" target="_blank" rel="noopener noreferrer nofollow ugc">drop.com</a> url that was posted in a discord channel (I checked the url and it is a legit url).</p>
]]></description><link>https://forums.opera.com/topic/41519/threat-found-in-opera-cache</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Jul 2026 07:41:55 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/41519.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 17 Jun 2020 02:31:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 20:47:23 GMT]]></title><description><![CDATA[<p dir="auto">@hion said in <a href="/post/214832">Threat Found in Opera Cache?</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://forums.opera.com/uid/1579">@blackbird71</a> hmm. I've ran a full scan and everything seems fine. I still find it extremely odd that this happened.</p>
</blockquote>
<p dir="auto">I agree it seems odd, but on the other hand, if you visited an infected site or one carrying an infected ad server, I can see how Defender may have trapped the exploit as the browser was loading it into a cache folder and so it may have blocked any manual or other form of access to that file and folder until you took remedial action thru Defender... that is what an AV program is supposed to do.</p>
<p dir="auto">With a clean full scan under your belt, the implication would be that the nasty was successfully trapped before it could do or install anything else. Whether it could have unilaterally done damage from a cache folder even if not blocked, I don't really know... but in any case, it seems as if you're good to go now.</p>
]]></description><link>https://forums.opera.com/post/214843</link><guid isPermaLink="true">https://forums.opera.com/post/214843</guid><dc:creator><![CDATA[blackbird71]]></dc:creator><pubDate>Wed, 17 Jun 2020 20:47:23 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 19:19:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://forums.opera.com/uid/1579">@blackbird71</a> hmm. I've ran a full scan and everything seems fine. I still find it extremely odd that this happened.</p>
]]></description><link>https://forums.opera.com/post/214832</link><guid isPermaLink="true">https://forums.opera.com/post/214832</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Wed, 17 Jun 2020 19:19:25 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 16:20:33 GMT]]></title><description><![CDATA[<p dir="auto">@hion There's some insight regarding the threat identified by Defender over at: <a href="https://stackoverflow.com/questions/43637629/backdoorphp-webshell-malware" target="_blank" rel="noopener noreferrer nofollow ugc">https://stackoverflow.com/questions/43637629/backdoorphp-webshell-malware</a> . In that case, the comments indicate a hacked site was involved. It may be possible that a hacked ad-server linked by a legitimate site could also cause running such malicious scripting, but I'm not sure about the technicalities.</p>
<p dir="auto">There is a Microsoft writeup about the virus here: <a href="https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Backdoor%3APHP%2FWebShell.A&amp;threatid=2147651339&amp;enterprise=0" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Backdoor%3APHP%2FWebShell.A&amp;threatid=2147651339&amp;enterprise=0</a></p>
<p dir="auto">Both prudence and Microsoft suggest running a full system scan just in case something leaked through.</p>
]]></description><link>https://forums.opera.com/post/214807</link><guid isPermaLink="true">https://forums.opera.com/post/214807</guid><dc:creator><![CDATA[blackbird71]]></dc:creator><pubDate>Wed, 17 Jun 2020 16:20:33 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 15:46:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://forums.opera.com/uid/1579">@blackbird71</a> The history of the removal is still there. To be honest I'm not entirely sure if I accidentally clicked quarantined then remoe, but here is the history of the removal:<br />
<img src="/assets/uploads/files/1592408779359-f87c7e64-4120-436b-80d2-7e7421df8df9-image.png" alt="f87c7e64-4120-436b-80d2-7e7421df8df9-image.png" class=" img-responsive img-markdown" /></p>
]]></description><link>https://forums.opera.com/post/214802</link><guid isPermaLink="true">https://forums.opera.com/post/214802</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Wed, 17 Jun 2020 15:46:31 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 15:43:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://forums.opera.com/uid/73">@leocg</a> Possibly. However, if you look at the image its Status was "Active", but maybe it was put into quarantine. I don't remember, I believe "Action" button had 3 options when pressed (Allow, remove and quarantine).</p>
]]></description><link>https://forums.opera.com/post/214800</link><guid isPermaLink="true">https://forums.opera.com/post/214800</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Wed, 17 Jun 2020 15:43:29 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 15:28:56 GMT]]></title><description><![CDATA[<p dir="auto">@hion said in <a href="/post/214750">Threat Found in Opera Cache?</a>:</p>
<blockquote>
<p dir="auto">... Why didnt the file that was infected (f_0022005) not found when I went to go search for it (Note: this is before I took any action to remove it).</p>
</blockquote>
<p dir="auto">Under Windows Security &gt; Virus &amp; threat protection &gt; Current threats &gt; Protection history, is there a listing for the incident? I'm not sure how enduring that history's memory is, so it may have already scrolled off, but perhaps not... in which case you might find some additional info. When Defender blocks some 'severe' threats, it immediately prevents them from proceeding further within the computer once it has 'trapped' them and causes their action to be suspended until you give direction. In this case, it may be possible that it also blocked or suspended manual access to the f_0022005 cache folder so that Explorer, etc. couldn't pull it up and allow infection via that route. Once you clicked in Defender to remove the threat, it would have permanently removed the folder.</p>
]]></description><link>https://forums.opera.com/post/214799</link><guid isPermaLink="true">https://forums.opera.com/post/214799</guid><dc:creator><![CDATA[blackbird71]]></dc:creator><pubDate>Wed, 17 Jun 2020 15:28:56 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 12:35:01 GMT]]></title><description><![CDATA[<p dir="auto">@hion Maybe it was already removed from the cache, since things there are temporary.<br />
Also some anti-virus put the problematic files in some kind of quarentine.</p>
]]></description><link>https://forums.opera.com/post/214779</link><guid isPermaLink="true">https://forums.opera.com/post/214779</guid><dc:creator><![CDATA[leocg]]></dc:creator><pubDate>Wed, 17 Jun 2020 12:35:01 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 03:32:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://forums.opera.com/uid/73">@leocg</a> Hmm, that probably is the case. Even though I don't remembering visisting any sketchy sites, lets assume I did. Why didnt the file that was infected (f_0022005) not found when I went to go search for it (Note: this is before I took any action to remove it).</p>
]]></description><link>https://forums.opera.com/post/214750</link><guid isPermaLink="true">https://forums.opera.com/post/214750</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Wed, 17 Jun 2020 03:32:44 GMT</pubDate></item><item><title><![CDATA[Reply to Threat Found in Opera Cache? on Wed, 17 Jun 2020 03:06:37 GMT]]></title><description><![CDATA[<p dir="auto">@hion You got it from a site you've visited. It can also be a false positive.</p>
]]></description><link>https://forums.opera.com/post/214748</link><guid isPermaLink="true">https://forums.opera.com/post/214748</guid><dc:creator><![CDATA[leocg]]></dc:creator><pubDate>Wed, 17 Jun 2020 03:06:37 GMT</pubDate></item></channel></rss>