Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos central endpoint getting this malware

one of my sophos endpoint is getting this malware regarding windows/system32/regsvr32.exe 

"Running malware locally cleared: HPmal/WMIJS-B at C:windows\system32\regsvr32.exe"

using sophos removal tool also cannot clear it.

 

 



This thread was automatically locked due to age.
Parents Reply
  • Hello Yeowkm,

    If you are still seeing the detection and Sophos cleaning it automatically then make sure all of your endpoints on the network are protected by Sophos and they are up to date.

    Please monitor and try to find out which computer is triggering it using SOI tool. If you could not find anything please contact Sophos support at the earliest for remote assistance.

Children