Jump to content

lehieu1603

Members
  • Posts

    9
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Hi, Great! Thank so much! I will check email from your sales team. Thank you again. Everything is seem to be normal.
  2. Hi, Thanks very much for your quickly support. It seem to be ok. Can I ask if you have free or trial malwarebyte for window server?
  3. Hi, After I run quarantine on computer CE and computer ENG, it seem to be ok. DNS wasn't change during the day. But there are also others computer get the same problem, however, malwarebyte couldn''t detect. I removed task by manual. Please see the virus file with the code to change dns as attached file. hynFcf.txt
  4. Hi, Thanks for your information. Here is log for our computers. Thank you very much! Your fixlist.txt is seem to be working well. ComputerCE_Addition.txt ComputerCE_AdwCleaner[C00].txt ComputerCE_FRST.txt ComputerCE_malwarebytes.txt ComputerENG_Addition.txt ComputerENG_AdwCleaner[C00].txt ComputerENG_FRST.txt ComputerENG_malwarebytes.txt
  5. Hi, The computer which I run fixlist.txt is seem to be fine until now. But I need to monitor it more time. Beside that, there are more 2 computer get the same issue, at that time, I do check step 1, 2 as your request and I noted that we got trojan Lemonduck.powershell. Please see the attachment of logs file for this computer. Addition.txt AdwCleaner[C00].txt AdwCleaner[S00].txt FRST.txt log_malware.txt
  6. Hi, I am monitoring from this morning and I will feedback soon. Please see the attach file, I also send you host file when the dns changed. There are also some another computer get a same issue so how can I fix it? 02.04.2020_16.37.10.zip hosts.zip
  7. Hi AdvancedSetup, We are using Sophos Enterprise Console but it didn''t detect this powershell. I removed Sophos temporarily and enable window defender. This is work computer in our domain. There are 4 - 5 computer get this problem and user can''t work. Please see the Fixlog.txt as attach file. Fixlog.txt
  8. Hi, Thanks for quickly reply. Please see the attach file. When the powershell in execution, I found out that hosts file was modified to IP 66.42.43.37 jp Sometimes, the computer is working well, but after several hours, dns will be changed, powershell.exe run and CPU come to 100% We are using sophos but it didn't detect anything Addition.txt AdwCleaner[C00].txt AdwCleaner[S00].txt FRST.txt Log.txt
  9. Hi all, I got an issue that dns keep auto change 8.8.8.8 and 9.9.9.9, when I open task manager, it show a lot of powershell so CPU become 100%. This affect to our job because dns domain was changed. Please help me with many thanks!
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.