Hi Folks,
Got a setup of multiple computers, office 2016 (32 bit) a custom written database and a newly introduced intercept X.
This only occurs on a single PC, all PC's are setup identically. It did go away for a short time but when opening the database it seemed to trigger it off - once it's triggered none of the office apps seem to work (word, excel etc.) and all trigger these.
Anyone have any clue where to start with it? I've used sophos SDU and about to open a case with support, thought i'd ask here too.
Cheers
Ian
What: |
Exploit LoadLib
no business files were involved
|
Where: | On xxx that belongs to xxx |
When: |
Detected on Mar 9, 2017 3:42 PM
|
How: |
winword.exe
|
Mitigation LoadLib
Platform 10.0.14393/x64 v583 06_5e
PID 7876
Application C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE
Description Microsoft Word 16
\\xxx\database\User Files\xxx\MouseHook.dll
Process Trace
1 C:\Program Files (x86)\Microsoft Office\Office16\WINWORD.EXE [7876]
2 C:\Windows\explorer.exe [4748]
3 C:\Windows\System32\userinit.exe [4680]
4 C:\Windows\System32\winlogon.exe [720]
winlogon.exe
Thumbprint
d275bc554957fe38a120aff3ff618c037adc47c5ef62d14de1c07425df37acd0
This thread was automatically locked due to age.