03-24-2021 11:38 AM
After a running running a full scan we still received email from Cisco AMP the computer is infected.... how i can remove it...
03-25-2021 09:38 PM
Hi,
For the detected SHA-256 value, I don't see any detection on AMP.
Please check for the event details on the AMP console and share the screenshot so that I can suggest accordingly.
Also, please make sure that the email is a genuine email received from AMP.
Note: You can open a TAC case as well to investigate further.
Cheers,
Pratham
07-13-2021 08:24 AM
08-11-2021 05:40 AM
Imagine you were downloading something from the web, but arbitrarily decided to check the file's integrity only halfway through the download using the .tmp file for the download. A useless and pointless exercise some might say, but every single time I see these (which is what lead me to searching the community) this is what looks to be happening. It guarantees the 'detection' hash is always unique and always useless, and of course the file will never exist at that location after the event - this is the nature of a temp file.
These don't usually appear to be user-initiated downloads in my experience, but rather a user visits some website that uses GZip compressed .JS files and AMP generates a meaningless false positive detection as a result. Curious what others may have done to remedy this as it seems the only solution would be to either exclude the threat category or use a path-based exclusion for 'C:\Users\*\AppData\Local\Temp\*.tmp'.
08-12-2021 12:58 AM
This is a temp file and it is harmless to delete out from the disk. Do not create any exclusion for the temp file, just keep your Internet browsing safe. I personally think the infection will no longer pops up if the temp directory is cleaned \\?\C:\Users\astewart\AppData\Local\Temp\e7c6af52-44c5-4edf-b2e8-06b400978330.tmp
08-12-2021 08:02 AM
Hey David,
Unfortunately, we've already tried that and it just kept coming up (different file & SHA of course). We removed everything in Temp, rebooted, and disabled all browser plugins. One user we even re-imaged his machine and it came back. Most likely sounds like what user 'TruthNotTruth' had to say about website drive-by. Can you provide what AMP/Secure EndPoint is flagging on these types of events?
Thanks,
Cheo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide