Jump to content

Warning event occurred in workspace


Recommended Posts

Event description:

Result description: Blocked

Type: Trojan

Name: PDM:Trojan.Win32.GenAutorunMsSqlServerCommandRun.a

User: NT SERVICE\MSSQLSERVER (Active user)

Object: C:\Program Files\Microsoft SQL Server\MSSQL14.MSSQLSERVER\MSSQL\Binn\sqlservr.exe

Reason: Dangerous action

Database release date: 6/15/2023 3:01:00 PM

Link to comment
Share on other sites

Hello Simon,

the event will be generated for a device where it happen and informs you about a threat which might harm the system.

The potential threat was blocked by our software.

You should do a full scan on your devices and open a ticket with support here:

https://CompanyAccount.kaspersky.com

Speed up the analysis by creating a GSI Report from the affected device: 
https://support.kaspersky.com/3632
(Please run as Administrator and include Event Logs)

In addition it might be helpful to get some version information depending on problem description and environment:
(please do not provide the below information in the forum)

- Cloud Endpoint Version installed on the device
- Network Agent Version
- Workspace ID
- Emailaddress you are logging into to Cloud
- Server address of Cloud
 

Thank you in advance

Best Regards

 

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...