Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.


Go Back   Vista Forums > Vista Forums > System Security

RB

Vista - SVCHOST.EXE AVG resident shield alert

Reply
 
01-06-2010   #1


Vista Home basic 32bit
 
 

SVCHOST.EXE AVG resident shield alert

Hello all,

two days ago i downloaded a program(Single file abt 100 kb) and executed it. After execution the program's icon simply disappeared from my desktop!!

After that I have been getting resident shield pop-ups which tell me about a new file being created in TEMP directory

eg: FILE NAME: C:\windows\temp\cvnp.tmp\svchost.exe
THREAT NAME: Trojan Horse Clicker.AEIO
Detect on open.

PROCESS NAME: C:\windows\system32\svchost.exe


-----------
My OS is Vista Home Basic
RAM 2 Gb
AVG 8.5
-----------
I've scanned my system again and again using AVG but it came out clean. Somehow it detects the infection when it executes but when I scan the system nothing happens.
I've run Spyware Doctor, Spybot, registry cleaners etc. It didnt help at all. No software detected any infection


Please help!!!!

My System SpecsSystem Spec
01-06-2010   #2


Windows Vista Home Premium x32 SP2
 
 

Re: SVCHOST.EXE AVG resident shield alert

Hello Mugambodeva, It seems strange that none of your scanners are picking it up but your resident protection is
Unless it is your heuristics scan (in other words it is not a known definition, but displaying the behaviour one.)

To be on the safe side i would download Malwarebytes free scanner, update it & run a scan. Malwarebytes has a high detection rate of Polymorphic malware & will play nicely with the security apps you already have.

If it does detect anything can you please post back your results. (For my own curiositys sake as well as it may help others)

Best wishes


http://www.malwarebytes.org/

Last edited by mitchell; 01-06-2010 at 06:08 PM.. Reason: Link for Malwarebytes download
My System SpecsSystem Spec
01-06-2010   #3


Vista home premium 32bit
 
 

Re: SVCHOST.EXE AVG resident shield alert

Have a look at this too: WikiAnswers - What is Trojan horse clicker LMJ and how do you remove it

The svchost.exe file is located in the folder C:\Windows\System32. In other cases, svchost.exe is a virus, spyware, trojan or worm!
My System SpecsSystem Spec
01-07-2010   #4


Vista Home basic 32bit
 
 

Re: SVCHOST.EXE AVG resident shield alert

I did a full Scan with Malwarebyte. It didnt detect anything.

Here is the log



Malwarebytes' Anti-Malware 1.43
Database version: 3458
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18865
1/7/2010 4:49:33 PM
mbam-log-2010-01-07 (16-49-28).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 359260
Time elapsed: 3 hour(s), 21 minute(s), 30 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
My System SpecsSystem Spec
01-07-2010   #5


Windows Vista Home Premium x32 SP2
 
 

Re: SVCHOST.EXE AVG resident shield alert

Hello M, The fact that none of the on demand scanners have detected anything really makes me think it could be a false positive.

You could do a bit of google on; "FILE NAME: C:\windows\temp\cvnp.tmp\svchost.exe
THREAT NAME: Trojan Horse Clicker.AEIO
Detect on open."
and see what others say about it.

Also you could disable AVG & run an online scan, this one is often recommended by our members;

Free ESET Online Antivirus Scanner
My System SpecsSystem Spec
01-07-2010   #6


Vista Ultimate 32bit
 
 

Re: SVCHOST.EXE AVG resident shield alert

You can always try a scan with Malwarebytes in safe mode.
Also superantispware has an online scan too SUPERAntiSpyware.com - Online Scanner
Also you can read this What is svchost.exe And Why Is It Running? - the How-To Geek
My System SpecsSystem Spec
01-08-2010   #7


Vista Home basic 32bit
 
 

Re: SVCHOST.EXE AVG resident shield alert

This certainly is not a fake alert because this never happened earlier. It started precisely after i ran that program.
My System SpecsSystem Spec
01-08-2010   #8


Vista - XP - Seven
 
 

Re: SVCHOST.EXE AVG resident shield alert

Hello mugambodeva,

I've the same problem since lastnight. Have you solved? How?

Regards,
Damian.
My System SpecsSystem Spec
01-08-2010   #9


Vista Home basic 32bit
 
 

Re: SVCHOST.EXE AVG resident shield alert

You can always try a scan with Malwarebytes in safe mode.
Also superantispware has an online scan too SUPERAntiSpyware.com - Online Scanner


I ran the SUPERAntispyware.com online scan... Guess what! It deleted a system file and now my laptop doesn't even boot.

The missing file is igdkmdnt.sys . No information is available on the internet.
PLZ HELP!!!!
My System SpecsSystem Spec
01-08-2010   #10


Vista Ultimate 32bit
 
 

Re: SVCHOST.EXE AVG resident shield alert

Now you are going to have to use your vista disc to do a repair.
Repair Install For Vista
If you have a vista disc.
If you do not then you are going to have to use your restore partion by hitting f11
during start up. This will WIPE YOU DRIVE AND RESTORE THE COMPUTER TO FACTORY
DEFAULTS. I wrote it big because I wanted you to know there is no going back once you do it. You will lose everything.

Jimmy
My System SpecsSystem Spec
Reply

RB


Thread Tools


Similar Threads for: SVCHOST.EXE AVG resident shield alert
Thread Forum
resident evil 5 benchmark Gaming
Memory Resident Programs Vista General
Avast -- resident protection Vista security
CyberLink PowerCinema Resident Program Vista General
AVG resident shield Vista security


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd