What is mscorsvw.exe?
mscorsvw.exe is a legitimate file from Microsoft Corporation that is used for running .NET programs. It precompiles .NET assemblies in the background. It is commonly located in c:\windows\microsoft.NET\framework. Malware authors write virus programs and name it after mscorsvw.exe to spread malwares on the internet.
Affected Platform: Windows OS
How to check if your computer is infected with mscorsvw.exe malware?
If your PC is infected with mscorsvw.exe, it will take up almost 100% of your CPU usage. It laso slows down your internet connection.
Take the following steps to diagnose your PC for possible mscorsvw.exe malware:
Step 1: Simultaneously press CTRL+ALT+DEL keys to open Task Manager.
Step 2: If you notice the file located outside the file path c:\windows\microsoft.NET\framework, then you should run an antivirus scan to get ride of the malware.
How to remove mscorsvw.exe malware from system using Comodo Antivirus?
Step 1: Download our award-winning Comodo Free Antivirus.
Step 2: Installation configuration frames will be displayed. Select the configuration you would like to apply.
Step 3: Select Customize Configuration option and arrange installers, configuration, and file location.
Step 4: Restart your PC.
Step 5: It will take some time for the Comodo Internet Security to update the antivirus.
Step 6: Proceed with a quick scan that automatically begins after the update.
Step 7: If threats are found during the scanning, you will be prompted with an alert screen.
Step 8: Comodo Antivirus will remove mscorsvw.exe malware from your computer including all other malwares!
First Seen: 06 November 2011 at 10:46 am
No. | Company | File Type | SHA1 | MD5 | Malware Name |
Digitally Signed |
File Version |
Product Version |
Submitted From |
Malware Behavior |
---|---|---|---|---|---|---|---|---|---|---|
1 | Microsoft Corporation | Executable | 99806dfe0eed4bdf e352aec767b66e36 deb429af |
6b67792c6229747b c407ee4a0291a6d8 |
Virus.Win32. Expiro.naf |
No | 2.0.50727. 5483 (Win7SP1GD R.050727-5 400) |
2.0.50727. 5483 |
![]() |
N/A |
2 | N/A | Executable | f07444a061ac12ca 97e96b36c4c97c35 68edc27b |
d124b1ad1b0b80d8 a33e907bf6467be3 |
Backdoor.Win 32.Poison.bk |
No | N/A | N/A | ![]() |
N/A |
3 | Microsoft Corporation | Executable | e44019ce10381f1f 08d5be8a06db7ca3 3ec85900 |
f94c7072387c3f55 a7c375f764d8af88 |
Virus.Win32. Expiro.nw |
No | 2.0.50727. 3053 (netfxsp.0 50727-3000 ) |
2.0.50727. 3053 |
![]() |
N/A |
4 | N/A | Executable | 71636fc8bb355827 c45dee3a9f0343e7 fdf8df40 |
d1cc81e982107511 a50a788c378ab6ca |
Backdoor.Win 32.Poison.bk |
No | N/A | N/A | ![]() |
N/A |
First Seen: 16 August 2008 at 7:17 pm
No. | Company | File Type | SHA1 | MD5 | Digitally Signed |
File Version |
Product Version |
Submitted From |
---|---|---|---|---|---|---|---|---|
1 | Microsoft Corporation | Executable | 17500a57dc8c7ebe 750c0128d3b235ca 0adb2f0b |
ae2ae096bcb98474 4c8de7a3026f8a85 |
Yes | 4.0.30319. 1 (RTMRel.03 0319-0100) |
4.0.30319. 1 |
![]() |
2 | Microsoft Corporation | Executable | da08c1d6a201639e 13d00d58b3872c00 8778a4df |
c152cf53e13f3654 7bcb4e775fd7c20f |
Yes | 4.8.3761.0 built by: NET48REL1 |
4.8.3761.0 | ![]() |
3 | Microsoft Corporation | Executable | 406a4f79d471c21a 483650bcb42fb6b7 ed98ff98 |
bd2ae15efb47e521 5b4d0c59ea00c91a |
Yes | 4.6.1590.0 built by: NETFXREL2 |
4.6.1590.0 | ![]() |
4 | Microsoft Corporation | Executable | 6beacda3c977838a 88b4795bfa42b7ad 8fc9a5a2 |
d87acaed61e417bb a546ced5e7e36d9c |
Yes | 2.0.50727. 3053 (netfxsp.0 50727-3000 ) |
2.0.50727. 3053 |
![]() |