Malwarebytes full system scans are coming up clean for workstations and servers on this network, but when a user logs in the RTP is popping up a Trojan block referencing "wermreport.exe" and "wermgpd.exe". When we browse to C:\Windows\System32\wermgpd.exe or wermreport.exe don't exist. I have attached FRST, Addition and RTP logs.
-Log Details-
Protection Event Date: 8/4/20
Protection Event Time: 1:32 PM
Log File: 6774a778-d678-11ea-a844-509a4c1b0b20.json
-Software Information-
Version: 4.1.2.73
Components Version: 1.0.990
Update Package Version: 1.0.27939
-System Information-
OS: Windows 10 (Build 15063.1418)
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Windows\System32\wermreport.exe, Blocked, -1, -1, 0.0.0
-Website Data-
Category: Trojan
Domain:
IP Address: 88.119.175.96
Port: 443
Type: Outbound
File: C:\Windows\System32\wermreport.exe
-Log Details-
Protection Event Date: 8/4/20
Protection Event Time: 10:55 AM
Log File: 8700f2a6-d662-11ea-8255-000c29d22054.json
-Software Information-
Version: 4.1.2.73
Components Version: 1.0.990
Update Package Version: 1.0.27937
-System Information-
OS: Windows Server 2012 R2
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Windows\System32\wermgpd.exe, Blocked, -1, -1, 0.0.0
-Website Data-
Category: Trojan
Domain:
IP Address: 88.119.175.96
Port: 443
Type: Outbound
File: C:\Windows\System32\wermgpd.exe
Any insight on removal is greatly appreciated.
Addition.txt
FRST.txt
Malwarebytes-Workstation.txt
MalwarebytesLog-Server.txt