Hi all,
I have an endpoint OS windows 7 ENS 10.5.4 ( platform + Threat protection)with many detections and cancellations of Ransom-WannaCry!2F178E2FCAFF ( Threat Source Process Name: C:\Windows\System32\lsass.exeThreat Target File Path: C:\Windows\mssecsvc.exe).
The OS is currently patched ( by WSUS) ,EPO ONdemand scan ( deep ,with GTI high) don't find nothing, STINGER ( with computer offline) don't find nothing.
Any troubleshooting idea ?
Solved! Go to Solution.
This may provide some assistance:
WannaCry / WanaCrypt0r 2.0 / WCry Ransomware
https://community.mcafee.com/t5/VirusScan-Enterprise-VSE/WannaCry-WanaCrypt0r-2-0-WCry-Ransomware/td...
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
@gri16 The system you're seeing the detections on may be patched, but you need to also confirm the rest of the systems in your environment are also patched.
For giggles - pull the hash values for lsass.exe & mssecsvc.exe - cut/paste/search: https://www.virustotal.com/#/home/search see if anything comes up.
It has been some time since I've used this method but you may also consider running mcafee's command line scanner - here's an old post on how to create a bootable usb with the command line scanner - review @rmetzger post
To me if nothing else is found is because everything has been detected and remediated.
If it happen on one machine only, perhaps that particular user only infected the machine (opened and attachment without being sure of origin)
This may provide some assistance:
WannaCry / WanaCrypt0r 2.0 / WCry Ransomware
https://community.mcafee.com/t5/VirusScan-Enterprise-VSE/WannaCry-WanaCrypt0r-2-0-WCry-Ransomware/td...
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
@gri16 The system you're seeing the detections on may be patched, but you need to also confirm the rest of the systems in your environment are also patched.
Yes the system is patched , the enviroment is mixed OS ( 4500 endpoints) from Windows 7 until W10 1809, but the question is : why only that computer detect (and delete) Wannacry ? What kind of troubleshooting I can do ? I tried with other security vendor standalone tool but the result is the same..nothing found..
For giggles - pull the hash values for lsass.exe & mssecsvc.exe - cut/paste/search: https://www.virustotal.com/#/home/search see if anything comes up.
It has been some time since I've used this method but you may also consider running mcafee's command line scanner - here's an old post on how to create a bootable usb with the command line scanner - review @rmetzger post
To me if nothing else is found is because everything has been detected and remediated.
If it happen on one machine only, perhaps that particular user only infected the machine (opened and attachment without being sure of origin)
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA