WinstonSmith
-
Posts
5 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by WinstonSmith
-
-
Not getting the persistent request to the IP, but still have two detections related to WR64.sys.
-
-
Thanks for the reply. Here are those logs.
-
I have the same issue as the above poster. Every minute MWB is detecting cmd.exe being used to connect to 172.111.239.90.
I've read other threads on this topic and so I've got my log file from the support tool attached, as well as the FRST log and addition txt.
Malware cmd.exe sending request to 172.111.239.90
in Resolved Malware Removal Logs
Posted
Thank you very much. Everything seems to be working well now.