Jump to content

Recommended Posts

Posted

Just to let eveyone know that we have just been hit with conhost.exe and sophos didn't detect it.

 

It basically installs into a machine and then anyone who logs into the infected machine, their profile gets hit.

Posted
In the end we had to use ccleaner and Malwarebytes. We discovered it by uses not been able to use the internet as it sets the proxy address of the machine to 127.0.0.1 and a random port. Fortunately we had about 10 members of staff affected and about 6 machines... not too bad, could have been a lot worse but had to re-create profiles. Also, conhost was starting up at machine startup so had to disable it here too.
Posted

Have you submitted it to sophos, MSE and clamav (who submit to others)?

I have submitted 3 bits of crud in recent days to all 3 so if you want details I can pass them on.

  • 2 weeks later...
Posted
Have you submitted it to sophos, MSE and clamav (who submit to others)?

I have submitted 3 bits of crud in recent days to all 3 so if you want details I can pass them on.

Zerohour, if you could please.

Im surprised it didnt detect it

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...