Good Morning
Trying to give as much data as I can !
Thank You all for reaching out as I work crazy hours up early and back early
Yes I do
Windows 11 Pro
HP Pavillion ( Brand new machine)
Windows 11 Pro
TPM enabled
Bitlocker just enabled this weekend
Running Task manager I see the process : hx tsr running at around zero %
The same PID 2780 is running from
Process explorer searching on HxOutlook :
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.resources.dll
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.exe
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.viewmodel.dll
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.view.dll
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.dll
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook_app.dll
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.model.dll
C:\ProgramFiles\\windowsapps\microsoft.windowscommunicationsapp_1605.14326.20970_x64_8wekyb\\HxOutlook.resources.dll
Numerousd threads on the same PID
I have seen numerous IP Addresses id'ed as nasty and have blocked them on my firewall for now but it seems they are getting around it
I use rdp to other machines and I believe that one of my other pc's actually was infected
So this may have come in from a windows 11 Pro Lenovo machine as this is another brand new machine but we do NOT run mail on that one
My Windows credentials have def been changed adding in other accounts on my pc not in windows tho
I am unable to post process explorer or tcp view here as norton will not allow it
My user ( Admin/system) credentials seem to have been compromsed as I removed them twice and they seem to have new accoutns re appearing ( Stripped down my admin account to 2 but I go back in and see 5 )
Tried removing them from the registry but each time it gets more difficult to remove
Thank You ALL !
Regards
Rich