Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos central endpoint getting this malware

one of my sophos endpoint is getting this malware regarding windows/system32/regsvr32.exe 

"Running malware locally cleared: HPmal/WMIJS-B at C:windows\system32\regsvr32.exe"

using sophos removal tool also cannot clear it.

 

 



This thread was automatically locked due to age.
Parents Reply
  • Hello yeowkm,

    SOI isn't a magic wand.
    It can help to find out what writes a certain file or into a certain location. Did you get another alert during these almost 3 hours SOI ran, if so - could you tell the time?  A cursory glance showed nothing outright suspicious. There are surprisingly few records - what switches/parameters did you use (apparently -p), did you run it as admin? Wonder why the Trace has these OpenProcess failed errors (normally disk space shouldn't be a concern and I use, at least initially, maximum logging, i.e. -ll 1)..

    As it's likely not regsvr32.exe that is compromised it'd be necessary first to find out with what parameters it is called, Process Monitor should help. 

    Christian

Children