Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos central endpoint getting this malware

one of my sophos endpoint is getting this malware regarding windows/system32/regsvr32.exe 

"Running malware locally cleared: HPmal/WMIJS-B at C:windows\system32\regsvr32.exe"

using sophos removal tool also cannot clear it.

 

 



This thread was automatically locked due to age.
Parents Reply Children
  • Hello yeowkm,

    SOI isn't a magic wand.
    It can help to find out what writes a certain file or into a certain location. Did you get another alert during these almost 3 hours SOI ran, if so - could you tell the time?  A cursory glance showed nothing outright suspicious. There are surprisingly few records - what switches/parameters did you use (apparently -p), did you run it as admin? Wonder why the Trace has these OpenProcess failed errors (normally disk space shouldn't be a concern and I use, at least initially, maximum logging, i.e. -ll 1)..

    As it's likely not regsvr32.exe that is compromised it'd be necessary first to find out with what parameters it is called, Process Monitor should help. 

    Christian

  • Hello Yeowkm,

    If you are still seeing the detection and Sophos cleaning it automatically then make sure all of your endpoints on the network are protected by Sophos and they are up to date.

    Please monitor and try to find out which computer is triggering it using SOI tool. If you could not find anything please contact Sophos support at the earliest for remote assistance.

    SAJ
    Community Support Engineer | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.
  • Hello  

    Other than what  and  have suggested, you can also download and run MS Autoruns. There may be a script that is needing regsvr32.exe to run, and is causing the detection. If it is a scheduled task, autoruns is sure to find it.

    Please refer to this related thread for additional information.