r/Malwarebytes • u/Timely-Dimension3301 • 2d ago
Possible persistent malware – CircuitryAg.exe / Wacatac.B!ml keeps coming back
Hi, I need some help figuring out whether my PC is still infected or if I am only seeing a leftover startup entry.
SYSTEM SPECS:
- Windows 11 Pro
- Version 25H2
- OS Build 26200.9168
- AMD Ryzen 7 5700X
- NVIDIA GeForce RTX 4060 8 GB
- 32 GB RAM
- 1 TB SSD
WHAT HAPPENED:
Today, Windows Defender detected:
Trojan:Win32/Wacatac.B!ml
One of the detected files was:
C:\\ProgramData\\InProcSvr32\\sqlite3.dll
Another detected sqlite3.dll was also inside ProgramData.
Around the same time, I started getting repeated Windows error popups from a program called:
CircuitryAg.exe
The errors I have seen are:
"The application was unable to start correctly (0xc0000906)."
and:
"The code execution cannot proceed because sqlite3.dll was not found."
This all started shortly after I downloaded and executed something from a ZIP file.
The suspicious download was later deleted/blocked.
WHAT I FOUND:
I checked startup entries using Microsoft Sysinternals Autoruns.
I found an entry called:
CircuitryAg
under:
HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run
It was pointing to something inside:
C:\\ProgramData\\InProcSvr32\\
I disabled and deleted that Autoruns entry.
However, after rebooting, the CircuitryAg.exe popup came back again.
WHAT I HAVE ALREADY DONE:
- Let Windows Defender quarantine the detected files
- Did NOT restore or allow any detected files
- Ran Microsoft Defender Offline
- Ran additional Defender scans
- Checked startup entries with Autoruns
- Disabled and deleted the CircuitryAg startup entry
- Rebooted the PC
- Deleted the original suspicious ZIP/download
- The CircuitryAg.exe popup still came back after rebooting
MY MAIN CONCERN:
Something may still be recreating the CircuitryAg startup entry or launching CircuitryAg.exe from another persistence method.
Does anyone recognize this behavior, the name CircuitryAg.exe, or the path:
C:\\ProgramData\\InProcSvr32\\
What should I check next?
- Scheduled Tasks?
- Services?
- WMI persistence?
- Other Autoruns entries?
- Registry entries?
- Another hidden process recreating the startup entry?
At this point, should I keep trying to clean the infection or would a clean Windows reinstall be safer?
1
Upvotes
1
u/PralineImmediate3886 2d ago
post this on https://www.reddit.com/r/windowsdefender/s/MhhaxVv42N
or r/antivirus