Author Topic: virus C:\mswvc.exe everyday  (Read 6836 times)

0 Members and 1 Guest are viewing this topic.

Offline chad82

  • Newbie
  • *
  • Posts: 10
virus C:\mswvc.exe everyday
« on: December 03, 2018, 08:19:35 PM »
Hello,
Im on avast business pro and we got a virus alert in C:\mswvc.exe that is being alerted on one of the machines almost EVERYDAY (also gets quarantined or deleted). Is there a way to see how this virus is being constantly created?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: virus C:\mswvc.exe everyday
« Reply #1 on: December 03, 2018, 08:24:33 PM »
attach requested logs  >>  https://forum.avast.com/index.php?topic=194892.0



also upload   C:\mswvc.exe  and scan it here  www.virustotal.com
post link to scan result here


« Last Edit: December 03, 2018, 08:36:08 PM by Pondus »

Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #2 on: December 03, 2018, 08:38:55 PM »
it is a windows 2003 server. Mbytes is not compatible is there any alternative?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: virus C:\mswvc.exe everyday
« Reply #3 on: December 03, 2018, 08:40:38 PM »
it is a windows 2003 server. Mbytes is not compatible is there any alternative?
and step #2 FRST ?   those two diagnostic logs are the important ones



Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #4 on: December 03, 2018, 08:50:51 PM »
here are the 2 logs from the FRST.
Is the mbytes log mandatory? Would a legacy version of mbytes be enough?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: virus C:\mswvc.exe everyday
« Reply #5 on: December 03, 2018, 08:56:52 PM »
I will notify the malware expert @Sass Drake and he will give further instructions

It may take hours before he is online


Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #6 on: December 03, 2018, 08:58:30 PM »
thank you for your prompt reply, i will be waiting :)

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: virus C:\mswvc.exe everyday
« Reply #7 on: December 03, 2018, 09:35:55 PM »
  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
Task: C:\WINDOWS\Tasks\sysnetsf.job => C:\Documents and Settings\Default User\Application Data\WINYS\mtwvc.exe
HKLM\...\batfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <==== ATTENTION
HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <==== ATTENTION
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.



Bear in mind that Microsoft doesn't support no longer Windows Server 2003 and it didn't received  any security update during last 4 years.

Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #8 on: December 03, 2018, 10:04:38 PM »
thanks for the reply, here is the attached log

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: virus C:\mswvc.exe everyday
« Reply #9 on: December 03, 2018, 11:15:41 PM »
What is system status now?

Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #10 on: December 03, 2018, 11:30:23 PM »
sorry i should have been more descriptive. the machine shuts off on its own. After running a full avast scan, i'm not able to find any viruses but the next day i will see that virus was detected and deleted. I will also see the "unexpected shutdown window" servers see when they shutdown. When it is on, it acts normally but when it shuts off  unexpectedly it causes issues for others.

Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #11 on: December 03, 2018, 11:38:14 PM »
since i've been seeing the same virus everyday wanted to see if avast is able to trace where the file is being created and delete the program or report the application that is calling that process. I have multiple computers that are seeing this mswvc.exe almost everyday.

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 820
Re: virus C:\mswvc.exe everyday
« Reply #12 on: December 04, 2018, 02:22:33 AM »
Report tomorrow what happened with Avast.

Offline chad82

  • Newbie
  • *
  • Posts: 10
Re: virus C:\mswvc.exe everyday
« Reply #13 on: December 04, 2018, 02:30:38 AM »
will do thank you

REDACTED

  • Guest
Re: virus C:\mswvc.exe everyday
« Reply #14 on: December 05, 2018, 10:09:56 PM »
I have been having the same problem for about a month.  I have about 5 users who are having the same symptoms shutdowns that seem to happen at about the same time.   There is nothing in task scheduler. Avast detects it and remove it and it starts up again Sophos does the same.