Views:

Background:
Trend Micro received some customer reports that they that there have been multiple detections for TSVIPSrv.dll which is a WinSxS file. The detection name is Trojan.MSIL.STEALTHMUTANT.A.enc.

TSVIPSrv.dll can generally be found in the following directory:
C:\Windows\WinSxS\x86_microsoft-windows-t..-tsappsrv-component_31bf3856ad364e35


Temporary Workaround (if pattern update does not work):
As a workaround, customers can temporarily exclude the directory of the location of the detected file on their Trend Micro product scan exclusions:

C:\Windows\WinSxS

You may check this KB article (Recommended scan exclusion list for Trend Micro Endpoint productsfor steps to configure Scan Exclusions.

Additional Information:
Vision One customers also reported seeing a workbench entry in their console:

Virus/Malware Log Details: Trojan.MSIL.STEALTHMUTANT.A.enc
Date/Time: 2/15/2023 12:22:12
Platform: Windows Server 2016 10.0.14393
Virus/Malware: Trojan.MSIL.STEALTHMUTANT.A.enc
Infection source: Infection channel: Local or network drive
Infected file/object: TSVIPSrv.dll File path: C:\Windows\WinSxS\x86_microsoft-windows-t..-tsappsrv-component_31bf3856ad364e35_10.0.14393.4169_none_8877eb5e94b19683\
Scan type: Scheduled
Scan Result: Cleaned
Detection Name: Trojan.MSIL.STEALTHMUTANT.A.enc


This has been confirmed to be a false positive and no additional actions are necessary.

Customers who are continuing to have issues are advised to contact their authorized Trend Micro representative for further assistance.