Ransomware: Windows Host Process, MsMpEng.exe

Parrots Wayne 1 Reputation point
2021-05-25T07:18:59.02+00:00

Dear All,

Recently, my TrendMicro said that there was a ransomware on Windows Host Process, the program location is "C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2104.14-0\MsMpEng.exe", the target location is "c:\windows\system32\svchost.exe".

I have ran the virus scanning, however, still do not know which file is a malware.

Do you have same problem? I don't know how could I clean it or stop it.

99309-01.png

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Carl Fan 6,881 Reputation points
    2021-05-26T09:49:56.953+00:00

    Hi,
    The Antimalware Service Executable process (also known as MsMpEng.exe) plays an integral role in Windows Defender service. The process is responsible for allowing Windows Defender to monitor potential threats. I wonder if there is a conflict between Windows Defender and your security software. Update the Windows Defender to latest version or disable Windows Defender real-time feature.
    Hope this helps and please help to accept as Answer if the response is useful.
    Best Regards,
    Carl

    0 comments No comments

  2. Parrots Wayne 1 Reputation point
    2021-05-27T02:02:18.763+00:00

    Thanks Carl.

    The server is running Windows Server 2016. There is about 20 servers are using Windows Server 2016, however, only 1 server get this issue, therefore, I am wonder it is a true ransom or not. However, I am lack of information about it...

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.