B
B
Brew2019-11-17 14:18:06
System administration
Brew, 2019-11-17 14:18:06

How to remove mssecsvr.exe?

Good day to all. There are more than 170 virtual machines in the organization, they connect to them using zero clients. Someone grabbed the mssecsvr.exe virus and it spread to all machines. VipNet IDS is simply torn from the number of incoming notifications. How to remove this virus? From what I tried:
1) Dr.Web CureIt - does not delete.
2) An update is not installed that fixes this problem.

Answer the question

In order to leave comments, you need to log in

2 answer(s)
A
Alexey Kharchenko, 2019-11-17
@Brew

The method is universal - we isolate the infected machine from the network (by any means), we treat it with an antivirus, if it does not detect it, we send a sample file to the support of the antivirus manufacturer, let it be added to the signatures. And so it is with all cars. And be sure to find a way how it got on the car, and how it spreads - and fix the problems, otherwise everything will happen again. Updates, policy rules, firewall settings, etc.
In the meantime, it is not detected by the antivirus - we take uVS, and it will definitely find where it starts, and where it lies, and what processes it is being introduced into, and all this can be deleted. The main thing is to read the documentation! Otherwise, you can ruin the system, worse than a virus.
If the name of the executable file is the same, it is easier at the initial stage to set up a policy for limited launch of programs - i.e. either determine the name/hash of the file prohibited from launching by domain policy, or simply distribute and apply the reg file with settings. Run attempts will continue, but this file will not run, regardless of user rights. Of course, if this process launches another malicious process, and it controls the launch, then it is necessary to block it.

D
Dimonchik, 2019-11-17
@dimonchik2013

make it like a virus - remove it on one, and spread the method to all machines

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question