SVCHOST.EXE AVG resident shield alert

mugambodeva

New Member
Hello all,

two days ago i downloaded a program(Single file abt 100 kb) and executed it. After execution the program's icon simply disappeared from my desktop!!

After that I have been getting resident shield pop-ups which tell me about a new file being created in TEMP directory

eg: FILE NAME: C:\windows\temp\cvnp.tmp\svchost.exe
THREAT NAME: Trojan Horse Clicker.AEIO
Detect on open.

PROCESS NAME: C:\windows\system32\svchost.exe


-----------
My OS is Vista Home Basic
RAM 2 Gb
AVG 8.5
-----------
I've scanned my system again and again using AVG but it came out clean. Somehow it detects the infection when it executes but when I scan the system nothing happens.
I've run Spyware Doctor, Spybot, registry cleaners etc. It didnt help at all. No software detected any infection


Please help!!!!
 

My Computer

Hello Mugambodeva, It seems strange that none of your scanners are picking it up but your resident protection is
Unless it is your heuristics scan (in other words it is not a known definition, but displaying the behaviour one.)

To be on the safe side i would download Malwarebytes free scanner, update it & run a scan. Malwarebytes has a high detection rate of Polymorphic malware & will play nicely with the security apps you already have.

If it does detect anything can you please post back your results. (For my own curiositys sake as well as it may help others)

Best wishes :D


http://www.malwarebytes.org/
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Hewlett Packard, compaq presario CQ60-305AU
    CPU
    AMD Athlon QI-46 2.1 Ghz
    Motherboard
    Wistron 303C
    Memory
    2048 Mb DDR2 SD Ram
    Graphics card(s)
    NVidea GE Go Force 8200M G / 256Mb dedicated grapics memory
    Sound Card
    MCP78S NVidea High definition
    Monitor(s) Displays
    15.6" High Definition Brightview Widescreen
    Screen Resolution
    1336x768
    Hard Drives
    Toshiba MK2555GSX ATA
    Mouse
    Synaptics PS2/Touchpad

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Q6600
    Memory
    4GB
    Monitor(s) Displays
    HP w2207h
    Hard Drives
    2x250GB HDDs 1x60GB OCZ SSD 6 external disks 60 to 640GBs
    Other Info
    Also 1xHP desktop, 1xHP laptop, 1xGateway laptop
I did a full Scan with Malwarebyte. It didnt detect anything. :(

Here is the log



Malwarebytes' Anti-Malware 1.43
Database version: 3458
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18865
1/7/2010 4:49:33 PM
mbam-log-2010-01-07 (16-49-28).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 359260
Time elapsed: 3 hour(s), 21 minute(s), 30 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
 

My Computer

Hello M, The fact that none of the on demand scanners have detected anything really makes me think it could be a false positive.

You could do a bit of google on; "FILE NAME: C:\windows\temp\cvnp.tmp\svchost.exe
THREAT NAME: Trojan Horse Clicker.AEIO
Detect on open."
and see what others say about it.

Also you could disable AVG & run an online scan, this one is often recommended by our members;

Free ESET Online Antivirus Scanner
 

My Computer

System One

  • Manufacturer/Model
    Hewlett Packard, compaq presario CQ60-305AU
    CPU
    AMD Athlon QI-46 2.1 Ghz
    Motherboard
    Wistron 303C
    Memory
    2048 Mb DDR2 SD Ram
    Graphics card(s)
    NVidea GE Go Force 8200M G / 256Mb dedicated grapics memory
    Sound Card
    MCP78S NVidea High definition
    Monitor(s) Displays
    15.6" High Definition Brightview Widescreen
    Screen Resolution
    1336x768
    Hard Drives
    Toshiba MK2555GSX ATA
    Mouse
    Synaptics PS2/Touchpad

My Computer

System One

  • Manufacturer/Model
    Gateway
    CPU
    intel core 2 Extreme QX6700
    Motherboard
    intel
    Memory
    3 gigs
    Graphics card(s)
    NVIDA
    Sound Card
    Creative SB X-FI
    Monitor(s) Displays
    Gateway 24 HD Monitor
    Screen Resolution
    1920 by 1200 pixels
    Hard Drives
    2-500 gigabyte hard drive Western digtal
You can always try a scan with Malwarebytes in safe mode.
Also superantispware has an online scan too SUPERAntiSpyware.com - Online Scanner


I ran the SUPERAntispyware.com online scan... Guess what! It deleted a system file and now my laptop doesn't even boot.

The missing file is igdkmdnt.sys . No information is available on the internet.
PLZ HELP!!!!
 

My Computer

Now you are going to have to use your vista disc to do a repair.
http://www.vistax64.com/tutorials/88236-repair-install-vista.html?ltr=R
If you have a vista disc.
If you do not then you are going to have to use your restore partion by hitting f11
during start up. This will WIPE YOU DRIVE AND RESTORE THE COMPUTER TO FACTORY
DEFAULTS. I wrote it big because I wanted you to know there is no going back once you do it. You will lose everything.

Jimmy
 

My Computer

System One

  • Manufacturer/Model
    Gateway
    CPU
    intel core 2 Extreme QX6700
    Motherboard
    intel
    Memory
    3 gigs
    Graphics card(s)
    NVIDA
    Sound Card
    Creative SB X-FI
    Monitor(s) Displays
    Gateway 24 HD Monitor
    Screen Resolution
    1920 by 1200 pixels
    Hard Drives
    2-500 gigabyte hard drive Western digtal
I have NEVER formatted my system. And I will try my best that I resolve the issue without a format.

And this time too I did it successfully. I asked a friend to mail me the missing file from her system and then used the command prompt and a USB drive to copy it in the 'drivers' folder.

My system is up and running, but the resident shield alert still is ON.

Any other suggestions on how to removing this Trojan???
 

My Computer

My Computer

System One

  • Manufacturer/Model
    Gateway
    CPU
    intel core 2 Extreme QX6700
    Motherboard
    intel
    Memory
    3 gigs
    Graphics card(s)
    NVIDA
    Sound Card
    Creative SB X-FI
    Monitor(s) Displays
    Gateway 24 HD Monitor
    Screen Resolution
    1920 by 1200 pixels
    Hard Drives
    2-500 gigabyte hard drive Western digtal
Another information... AVG Resident Shield also shows the PID of the process which has executed the program. I traced it in the Task Manager and there are 2 process with that PID: DcomLaunch and PlugPlay

Any suggestions now?
 

My Computer

My Computer

System One

  • Manufacturer/Model
    Gateway
    CPU
    intel core 2 Extreme QX6700
    Motherboard
    intel
    Memory
    3 gigs
    Graphics card(s)
    NVIDA
    Sound Card
    Creative SB X-FI
    Monitor(s) Displays
    Gateway 24 HD Monitor
    Screen Resolution
    1920 by 1200 pixels
    Hard Drives
    2-500 gigabyte hard drive Western digtal
Sorry I will not download that file. It sounds like a scam to me.
 

My Computer

System One

  • Manufacturer/Model
    Gateway
    CPU
    intel core 2 Extreme QX6700
    Motherboard
    intel
    Memory
    3 gigs
    Graphics card(s)
    NVIDA
    Sound Card
    Creative SB X-FI
    Monitor(s) Displays
    Gateway 24 HD Monitor
    Screen Resolution
    1920 by 1200 pixels
    Hard Drives
    2-500 gigabyte hard drive Western digtal
mugambodeva,

i've the same problem, and after a few days of trying everything but reinstall the SO, finally found the solution...

take a look at this post

Fake svchost.exe trojan created in windows temp folder

and follow the instructions of "homersimpson"

in my case, when I ran hijackthis it found a few more entries that make no sense to me, so i've fixed them too.

follow those steps and let me know if you have success.good luck!
 

My Computer

Back
Top