Good morning,
we have malware that has attacked the entire domain network through the RDP protocol, all clients are trying to connect with the server and from the server links to compromised sites are being sent through open HTTP ports.
For the time being we have blocked all RDP connections and closed the ports.
The virus has certainly reproduced itself on all PCs connected to the network.
We are unable to identify suspicious files.
We are currently using Avast, which allowed us to see that there was an attack in progress, but it does not identify the virus.
Could you give me a suggestion?
Thank you very much!
Have you tried to run a scan with malwarebytes?
They will also assist you with removal. https://forums.malwarebytes.com/forum/7-windows-malware-removal-help-support/
I have tried them all: Combo Cleaner, SpyHunter, malwarebytes, etc. but have not solved the problem
Then start a topic in malwarebytes forum and ask for help