- Joined
- Feb 6, 2018
- Messages
- 11,194
- Reaction score
- 7,002
If you are using RMM or whatever, this will work as well.MsiExec.exe /X {EFC8D3F7-8A56-430E-93D3-C7AF626123CB} should do the job
If the GUID is incorrect, you can find it on a sample machine by looking in the registry - this should point you in the right direction -
https://www.advancedinstaller.com/msi-retrieve-productcode.html
I should say it was the AI that got it. So if you don;t have that turned on, you wouldn't have caught it.I only have one user with the client installed and it appears to have been dormant (or he was using the web client version) till this afternoon at 13:52GMT which is when it all went a little crazy. Thankfully no other users have the client installed so it's had a low impact for us.
Agreed, I just called them about that and they said that they don't have enough evidice about what is actually happening to make an announcement. But they said they have their security expert actively working on this and will post something once they know what's going on.3CX should probably make a public (or at least a forum) posting about this soon, at least to allay some fears from the community.
Same here. Busy undoing all the exclusions we put in place at the moment.S1 ai module actually picked this up a few days ago. We thought it was a false positive.
Hi Nick, Thanks for the update. One of the infected versions it seems was the Jabra SDK version. Do you know if the updates will provide a clean version with the Jabra SDK? Thanks : )Unfortunately the rumors are true. Please uninstall the client. And we will have a new one in the next few hours via updates.
The updating probably wont work because Windows Defender will flag it.
Unfortunately this happened because of an upstream library we use became infected.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.