Jump to content

PowerShell/Agent.FU malware?


cignus

Recommended Posts

  • Administrators

Please provide:
- logs collected with ESET Log Collector
- a Procmon boot log (stop logging after the threat has been detected after the system restart)

You may need to upload the archive(s) to a safe location and provide me with a download link. Especially the Procmon boot log can be quite big, depending on how long it takes for the threat to execute after a reboot.

Link to comment
Share on other sites

  • Administrators

Please compress the content of the c:\users\moreno\appdata\roaming\njiuearzu folder and send me the generated archive via a personal message.

 

Link to comment
Share on other sites

  • Administrators

Please check now. The threat should be detected as PowerShell/Agent.XD trojan and cleaned. If it has not been detected yet, try rebooting the machine so that a startup scan is run.

Link to comment
Share on other sites

Mi ritrovo anche io con lo stesso identico problema.. ogni 10 minuti viene rilevata la minaccia powershell/Agent.FU ma non viene eliminata, semplicemente bloccata. Qual è la risoluzione del problema? Grazie in anticipo

Link to comment
Share on other sites

  • Administrators
31 minutes ago, EKZero said:

Mi ritrovo anche io con lo stesso identico problema.. ogni 10 minuti viene rilevata la minaccia powershell/Agent.FU ma non viene eliminata, semplicemente bloccata. Qual è la risoluzione del problema? Grazie in anticipo

Since this is an English forum please post in English.

Please provide:
- logs collected with ESET Log Collector
- a Procmon boot log (stop logging after the threat has been detected after the system restart)

You may need to upload the archive(s) to a safe location and provide me with a download link. Especially the Procmon boot log can be quite big, depending on how long it takes for the threat to execute after a reboot.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...