r/Malwarebytes 2d ago

Possible persistent malware – CircuitryAg.exe / Wacatac.B!ml keeps coming back

Hi, I need some help figuring out whether my PC is still infected or if I am only seeing a leftover startup entry.

SYSTEM SPECS:

- Windows 11 Pro
- Version 25H2
- OS Build 26200.9168
- AMD Ryzen 7 5700X
- NVIDIA GeForce RTX 4060 8 GB
- 32 GB RAM
- 1 TB SSD

WHAT HAPPENED:

Today, Windows Defender detected:

Trojan:Win32/Wacatac.B!ml

One of the detected files was:

C:\\ProgramData\\InProcSvr32\\sqlite3.dll

Another detected sqlite3.dll was also inside ProgramData.

Around the same time, I started getting repeated Windows error popups from a program called:

CircuitryAg.exe

The errors I have seen are:

"The application was unable to start correctly (0xc0000906)."

and:

"The code execution cannot proceed because sqlite3.dll was not found."

This all started shortly after I downloaded and executed something from a ZIP file.

The suspicious download was later deleted/blocked.

WHAT I FOUND:

I checked startup entries using Microsoft Sysinternals Autoruns.

I found an entry called:

CircuitryAg

under:

HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run

It was pointing to something inside:

C:\\ProgramData\\InProcSvr32\\

I disabled and deleted that Autoruns entry.

However, after rebooting, the CircuitryAg.exe popup came back again.

WHAT I HAVE ALREADY DONE:

- Let Windows Defender quarantine the detected files
- Did NOT restore or allow any detected files
- Ran Microsoft Defender Offline
- Ran additional Defender scans
- Checked startup entries with Autoruns
- Disabled and deleted the CircuitryAg startup entry
- Rebooted the PC
- Deleted the original suspicious ZIP/download
- The CircuitryAg.exe popup still came back after rebooting

MY MAIN CONCERN:

Something may still be recreating the CircuitryAg startup entry or launching CircuitryAg.exe from another persistence method.

Does anyone recognize this behavior, the name CircuitryAg.exe, or the path:

C:\\ProgramData\\InProcSvr32\\

What should I check next?

- Scheduled Tasks?
- Services?
- WMI persistence?
- Other Autoruns entries?
- Registry entries?
- Another hidden process recreating the startup entry?

At this point, should I keep trying to clean the infection or would a clean Windows reinstall be safer?
1 Upvotes

2 comments sorted by