Jump to content
Ambarish

Trojan.BitCoinMiner

Recommended Posts

A lot of end points in our network is reporting that Trojan.BitCoinMiner is detected from C:\WINDOWS\SYSTEM32\AUTOCHK.EXE and is being repeatedly marked as quarantined.
I have a ticket opened # 00057413 for this and was told to post the details here
 
Is this a malware or just false positive?

autochk.zip

Edited by Ambarish
Added ticket details

Share this post


Link to post
Share on other sites
14 minutes ago, shadowwar said:

This is confirmed. We are publishing now to fix. Should be about 20 mins till released.

Thanks shadowwar we we're receiving the same false positive. 

Share this post


Link to post
Share on other sites
24 minutes ago, shadowwar said:

This is confirmed. We are publishing now to fix. Should be about 20 mins till released.

shadowwar,

Will MWB automatically restore the autochk.exe file with the new update if it was quarantined? 

Share this post


Link to post
Share on other sites

No though if running business client i am not 100% sure. Windows file protection should actually put it back possibly.

 

Share this post


Link to post
Share on other sites
2 minutes ago, shadowwar said:

This is resolved in

 

MBAM2 Version: v2018.04.11.07

MBAM3 Version: 1.0.4698

Thank you ShadowWar, was about to ask for this information. 

Share this post


Link to post
Share on other sites
15 hours ago, shadowwar said:

This is confirmed. We are publishing now to fix. Should be about 20 mins till released.

Thank you. 

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.