If you experience any of the listed unusual system behavior, follow the corresponding recommendations.
- When encountering encrypted files
- Collect a sample of the encrypted file and upload to ID Ransomware.
- Once the malware has been identified, you may use Threat Encyclopedia to search for more information about the ransomware and the solution to completely remove it from your system.
- If you are not convinced that the malware has been completely removed, run ATTK on affected machines and submit the output to Trend Micro Support.
- Use this guide on how to file a case with the logs collected.
- When suspicious files / PowerShell scripts running in environment
- Suspicious files:
- Open the Task Manager.
- Go to Details Tab.
- Search for the file’s suspicious process and click Open File Location.
- End the suspicious process. Collect the file, and compress it with password: virus.
- Use ATTK on the affected machine.
- Submit the ATTK log and suspicious file to Trend Micro Support.
- Suspicious PS Scripts:
For more information about PowerShell-based malware and how to mitigate them, visit this article.
Visit this article on how to file a case with the logs collected.
- Suspicious files:
- When machine(s) connect to unknown IP addresses
- Use Global Site Safety to check the reputation of the IP address.
- Create an Apex One / OfficeScan Firewall policy to block the connection if IPs are still untested in Global Site Safety.
- Use ATTK to collect for suspicious files in the machine and submit to Trend Micro Support.
- For detailed steps on how to stop this attack, view this KB article.
- Visit this article on how to file a case with the logs collected.
- When being redirected to unknown/malicious sites
- You can check the site's safety using Global Site Safety.
- Do not input any information on the redirected site if it is untested or dangerous.
- Try connecting to the original site using other machines.
- If the same issue persists, the web site may have been compromised. If only few machines are experiencing the issue, check the "hosts" file located in C:\Windows\System32\Drivers\etc for any URL redirection. Remove all suspicious or unknown URL/IP.
- Clear the DNS cache via the Command prompt by executing this command:
C:\>ipconfig /flushdns
- If the issue persists, export detection logs in Apex One and OfficeScan and file a case to Trend Micro support.
- Visit this article on how to file a case with the logs collected.
- When pop-up messages are being displayed
- For Persistent Apex One / OfficeScan detection, refer to this KB article.
- For web page pop-ups like the image below:
- Uninstall any suspicious/unknown programs installed from Control Panel > Add/ Remove Programs.
- Remove unknown add-ons from browsers like Google Chrome, Internet Explorer and Mozilla Firefox.
- Use ATTK to resolve the issue. If it reoccurs, submit the ATTK logs to Trend Micro Support.
- Visit this article on ATTK log collection.
- Visit this article on how to file a case with the logs collected.