Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi, I'm confounded about the process mswincom32.exe. It is causing serious shutdowns, making my computer unable to open any application.
-Open Firefox and it is closed within seconds
-Open Control Panel and it freezes
-Open AVG, Zone Alarm, etc...it quits before they're opened!In the processes list, I am unable to stop mswincom32.exe, the file taking all resources. Searches on the internet show nothing...can anyone help?
Thanks!

If possible, please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.
Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

MsWincom32.exe is malware - I spent 16 hours at a client cleaning their systems of it - it installs itself as a service then downloads LOADS of other malware and installs them. If your machine doesn't have a firewall, you are especially vulnerable.
Dr. Web antivirus and Sophos antivirus will detect it. If you can (using another computer) make yourself an Ultimate Boot CD for Windows (UBCD4WIN) - you'll need an XP SP1 or XP SP2 integrated CD and to download the program that creates the UBCD4WIN and you can download the program from here: http://www.ubcd4win.com/
Boot to that CD and run the Dr. Web Antivirus application it has, doing a complete scan. It will detect it and allow you to rename or delete the MSWINCOM32.exe file.
MSWINCOM32.EXE actually installs itself as a service and brings along other services which is why it cannot be terminated from Task Manager. I don't recall ALL the services it creates, but there are 4, I believe - MSCOMMAND that claims to be a helper service for DOS, Network Monitor and two others that I cannot recall.
The MSWINCOM32.exe file is actually hidden and can be found in c:\winnt\system32\dllcache (or C:\windows\... depending on what version of Windows).
To prevent it (as I have found it can be VERY difficult to prevent it without a firewall. One tactic that might work (not sure) is to create a file called MSWINCOM32.exe and save it in the dllcache folder mentioned above. Just create a text file with a little text in it and name it that.
Also, disabling the services SEEMS to be enough as when they are disabled, MSWINCOM32.exe does not run and seemingly does not reinfect.
Unfortunately, the consequences of the infection can be severe as there are, as I said, MANY other malware applications that it installs.

![]() |
ActiveMovie Window error
|
Feel so STUPID!
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |