kaelri / enigma

A featured "suite" for the Windows system monitoring application, Rainmeter.
https://www.kaelri.com/project/enigma/
275 stars 94 forks source link

Double-clicking on the "Search1" extra installs trojan virus: Php/Shell-G - caught by my antivirus. #18

Closed asfsgfdsfaber closed 12 years ago

asfsgfdsfaber commented 12 years ago

I don't have any other things installed, no extras, just Enigma. Directly clicking on the blank "Search" icon (the one from Enigma > Taskbar > Search > Search1) opened Google and attempted to automatically install the trojan virus called Php/Shell-G which attempted to compromise my system.

Please fix it immediately for other users. Fortunately my antivirus caught the virus before it was able to harm my computer.

kaelri commented 12 years ago

There is absolutely no way that this is possible if you are using legitimate, unmodified versions of Rainmeter and Enigma. Can you tell me where you downloaded both the program and the package?

asfsgfdsfaber commented 12 years ago

Update: it wasn't the Template one. It was the Search icon I had right next to it, under Enigma > Taskbar > Search > Search1

I just updated the issue to show the correct one. Maybe someone working with you guys added a trojan, or somehow it accidentally slipped in there. Maybe someone working with you had a virus on their computer that put this in there.

It definitely came from that one though (Search taskbar widget in Enigma)

Also, just to be clear, I am using Version 4 Update 1 directly from this site. It is completely unmodified.

kaelri commented 12 years ago

Again, I am absolutely certain that this is not related to Rainmeter or Enigma. The search skin does nothing except take whatever text you type into the input box and execute a Google search URL. For example, if you type enigma in the search box, it will send:

https://www.google.com/search?q=enigma

This address is opened using whatever you have set as your default browser in Windows - same as if you copy and paste the same address into the Windows "Run" dialog. You can see this for yourself in the skin code.

I would recommend scanning for malware on your system, and disabling any browser extensions that you don't trust.