Jump to content

Alcam

Members
  • Posts

    5
  • Joined

  • Last visited

Posts posted by Alcam

  1. Hello,

    A WMI based coin miner virus is active on our computer. Malwarebytes is able to remove it but it comes back on the restart. We believe it comes back from MSSQL server agent jobs.

    I am attaching the reports so that you can a virus that you are not able to remove.

    Note that we suffer blue screen (caused by mwac.sys) on each restart of the Windows, but it works on the every second attempt. 

    Secondly, when the virus tries to connect to the internet, malwarebytes blocks it but it actually blocks the whole internet connection, not for just the virus. Moreoever, it even blocks the local network connections. I solve it by closing malwarebytes. Is this normal? Isnt it supposed to just block the virus's connection or the suspicious connection?

    It would be great if you can help.

    Please let me know if you need more information. 

     

    mbst-grab-results.zip

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.