Jump to content

Malwarebytes found an exploit now what?


saila99

Recommended Posts

Hello, recently I noticed that my Malwarebytes EDR found on one of my endpoints and exploit... Here are the details:

C:\Windows\sysnative\cmd.exe C:\Windows\sysnative\cmd.exe \c

C:\Windows\System32\REG QUERY HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography \v MachineGuid

The automatic action taken by MB was blocked. I have some questions:

  1. Is this a real exploit or an error? 
  2. Since this exploit it is already bloqued, should I click on remediate or not?
  3. How can I trace to see how or where we got infected?

Thanks,

 

Link to post
Share on other sites

  • Root Admin

Hello @saila99

Can you please open a Support ticket and attach the logs from this for Support. Once you have a ticket number please let me know the number so I can see if I can get it escalated.

https://support.malwarebytes.com/hc/en-us/requests/new

Thank you

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.