cancel
Showing results for 
Search instead for 
Did you mean: 
gri16
Level 7
Report Inappropriate Content
Message 1 of 6

Ransom-WannaCry!2F178E2FCAFF

Jump to solution

Hi all,

I have an endpoint  OS windows 7 ENS 10.5.4  ( platform + Threat protection)with many detections and cancellations of Ransom-WannaCry!2F178E2FCAFF ( Threat Source Process Name: C:\Windows\System32\lsass.exeThreat Target File Path: C:\Windows\mssecsvc.exe).

The OS is currently patched ( by WSUS) ,EPO ONdemand scan ( deep ,with GTI high) don't find nothing, STINGER ( with computer offline) don't find nothing.

Any troubleshooting idea ?

3 Solutions

Accepted Solutions
Reliable Contributor tao
Reliable Contributor
Report Inappropriate Content
Message 2 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

This may provide some assistance:

WannaCry / WanaCrypt0r 2.0 / WCry Ransomware
https://community.mcafee.com/t5/VirusScan-Enterprise-VSE/WannaCry-WanaCrypt0r-2-0-WCry-Ransomware/td...

 

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
McAfee Employee jess_arman
McAfee Employee
Report Inappropriate Content
Message 3 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

@gri16 The system you're seeing the detections on may be patched, but you need to also confirm the rest of the systems in your environment are also patched.

JoseRR
Level 9
Report Inappropriate Content
Message 6 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

To me if nothing else is found is because everything has been detected and remediated.

If it happen on one machine only, perhaps that particular user only infected the machine (opened and attachment without being sure of origin)

 

5 Replies
Reliable Contributor tao
Reliable Contributor
Report Inappropriate Content
Message 2 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

This may provide some assistance:

WannaCry / WanaCrypt0r 2.0 / WCry Ransomware
https://community.mcafee.com/t5/VirusScan-Enterprise-VSE/WannaCry-WanaCrypt0r-2-0-WCry-Ransomware/td...

 

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
McAfee Employee jess_arman
McAfee Employee
Report Inappropriate Content
Message 3 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

@gri16 The system you're seeing the detections on may be patched, but you need to also confirm the rest of the systems in your environment are also patched.

gri16
Level 7
Report Inappropriate Content
Message 4 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

Yes the system is patched , the enviroment is mixed OS ( 4500 endpoints) from Windows 7 until W10 1809, but the question is : why only that computer detect (and delete) Wannacry ? What kind of troubleshooting I can do ? I tried with other security vendor standalone tool but the result is the same..nothing found..

Reliable Contributor tao
Reliable Contributor
Report Inappropriate Content
Message 5 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

For giggles - pull the hash values for lsass.exe & mssecsvc.exe - cut/paste/search: https://www.virustotal.com/#/home/search see if anything comes up.

It has been some time since I've used this method but you may also consider running mcafee's command line scanner - here's an old post on how to create a bootable usb with the command line scanner - review @rmetzger post

https://community.mcafee.com/t5/VirusScan-Enterprise-VSE/How-can-I-build-a-Bootable-CD-of-McAfee-Vir...

If this information was helpful or has answered your question, please select Accept as Solution. This will assist other memebers
JoseRR
Level 9
Report Inappropriate Content
Message 6 of 6

Re: Ransom-WannaCry!2F178E2FCAFF

Jump to solution

To me if nothing else is found is because everything has been detected and remediated.

If it happen on one machine only, perhaps that particular user only infected the machine (opened and attachment without being sure of origin)

 

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator