Thats happend serveral times to our clients since tomorrow even though the file direction (C:\Windows\System32\userinit.exe) is included to Anti-Malware and Anti-Ransomware Exclusion List
Any help?
Thanks in advance
Malwarebytes Management Server Notification
--------------------------------------------
Alert Time: 12.02.2020 16:01:30
Server Hostname:
Server Domain/Workgroup:
Description:
Ransomware threat detected, see details below:
Time HostName IPAddress ThreatName Operation Clean Result ObjectScanned
12.02.2020 16:01:23 Malware.Ransom.Agent.Generic QUARANTINE SUCCESSFUL HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit
12.02.2020 16:00:49 Malware.Ransom.Agent.Generic QUARANTINE WHITELISTED userinit.exe
Total count: 3.
-------------------------------------------
Comment: This email was generated by Malwarebytes Management Server. Please do not reply to this message.
logs.zip