Author Topic: Win64:Malware-gen C:\windows\winexesvc.exe  (Read 6406 times)

0 Members and 1 Guest are viewing this topic.

Offline BudG

  • Newbie
  • *
  • Posts: 13
Win64:Malware-gen C:\windows\winexesvc.exe
« on: March 18, 2019, 05:44:02 PM »
We received a virus alert for the 1st time called Win64:Malware-gen C:\windows\winexesvc.exe and am wondering if this is a false positive?  Or did a new definition make this file now be considered Malware? What does the Win64:Malware-gen designation mean? Does that mean it is a PUP?  Looks the file has been on our systems for nearly 2 years and never classified as Malware.  Malwarebytes does not see it as Malware either.  Odd.  I understand that the file can be used to push software installs from Linux boxes such as by AlienVault OSSEC agents, which we do use AlienVault.  So, is Avast just saying this file could have potential risks? Or does this mean that file has been itself infected with something else?

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #1 on: March 18, 2019, 08:53:59 PM »
Can you please upload this file into virustotal and send us a link? Or send us this file directly?

Offline BudG

  • Newbie
  • *
  • Posts: 13
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #2 on: March 19, 2019, 03:15:13 PM »
Can you please upload this file into virustotal and send us a link? Or send us this file directly?

It is currently quarantined.  Can I send it from the virus chest using "submit file to virus lab"?

Not sure how to send in VirusTotal.  I know how to upload to it and have a file checked, but dont know how to send a file using VirusTotal.

Or should I un-quarantine it and send it another way?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #3 on: March 19, 2019, 03:31:36 PM »
Quote
It is currently quarantined.  Can I send it from the virus chest using "submit file to virus lab"?
yes


Offline BudG

  • Newbie
  • *
  • Posts: 13
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #4 on: March 19, 2019, 03:39:28 PM »
Quote
It is currently quarantined.  Can I send it from the virus chest using "submit file to virus lab"?
yes

I just sent it from the quarantine using "submit file to virus lab" from in the virus chest.  I put my email address in so you should be able to find it.  Will someone email me back and let me know the findings?
If I need to send it another way I can send it another way if it needs to get to the right person to be able to get information about the file.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #5 on: March 19, 2019, 03:46:22 PM »
Quote
Will someone email me back and let me know the findings?
Maybe

there used to be a feature i chest where you right cliked on file to rescan and see if it was still detected, if not detected you may restore it
Dont use avast so dont know if this is still possible




Offline BudG

  • Newbie
  • *
  • Posts: 13
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #6 on: March 19, 2019, 03:51:39 PM »
Quote
Will someone email me back and let me know the findings?
Maybe

there used to be a feature i chest where you right cliked on file to rescan it and see if it was still detected, if not detected you may restore it
Dont use avast so dont know if this is still possible

Hi,
I am trying to find out if the file has been infected with something or if the file itself is just considered malicious due to its power.  The file on Windows is winexesvc.exe and can be used on windows to receive files pushed from a Linux server to a windows server. We do use AlienVault on Linux that does push and install its OSSEC agent to windows servers. If the file itself is just considered possible malicious I do not mind restoring the file.  However, if the file has been infected with some other Malware then I want to keep in quarantined.  That is why I need to hear from someone as to which it is.
Thanks,
Bud

Offline BudG

  • Newbie
  • *
  • Posts: 13
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #7 on: March 19, 2019, 04:16:07 PM »
Can you please upload this file into virustotal and send us a link? Or send us this file directly?

I just sent it from the quarantine using "submit file to virus lab" from in the virus chest.  I put my email address in so you should be able to find it.  Will someone email me back and let me know the findings?
If I need to send it another way I can send it another way if it needs to get to the right person to be able to get information about the file.

I am trying to find out if the file has been infected with something or if the file itself is just considered malicious due to its power.  The file on Windows is winexesvc.exe and can be used on windows to receive files pushed from a Linux server to a windows server. We do use AlienVault on Linux that does push and install its OSSEC agent to windows servers. If the file itself is just considered possible malicious I do not mind restoring the file.  However, if the file has been infected with some other Malware then I want to keep in quarantined.  That is why I need to hear from someone as to which it is.

Offline BudG

  • Newbie
  • *
  • Posts: 13
Re: Win64:Malware-gen C:\windows\winexesvc.exe
« Reply #8 on: March 20, 2019, 09:34:31 PM »
Can you please upload this file into virustotal and send us a link? Or send us this file directly?

I just sent it from the quarantine using "submit file to virus lab" from in the virus chest.  I put my email address in so you should be able to find it.  Will someone email me back and let me know the findings?
If I need to send it another way I can send it another way if it needs to get to the right person to be able to get information about the file.

I am trying to find out if the file has been infected with something or if the file itself is just considered malicious due to its power.  The file on Windows is winexesvc.exe and can be used on windows to receive files pushed from a Linux server to a windows server. We do use AlienVault on Linux that does push and install its OSSEC agent to windows servers. If the file itself is just considered possible malicious I do not mind restoring the file.  However, if the file has been infected with some other Malware then I want to keep in quarantined.  That is why I need to hear from someone as to which it is.

Pinging thread due to no more responses or answers to solve problem of how to get file to Avast so someone can look at it and let me know the results of what they find...