PDA

View Full Version : Trojan horse FakeAV unable to be deleted by AVG 2011 Free Edition



Holsten87
2014-06-26, 19:13
Hello
I have run an ERUNT registry back up. I'm on Vista (pretty old laptop) and have turned off user account control as per instructions on ERUNT site.
AVG found two infected files on my last scan:
1. Object name: C:\Windows\System32\svchost.exe (888)
Detection Name: Trojan horse FakeAV.TMH.dropper
Object Type: process
SDK Type: Core
Result: DELETED
2. Object Name: c:\Windows\System32\svchost.exe (888):\memory_05a00000
Detection Name: Trojan horse FakeAV.TMH.dropper
Object Type: file
SDK Type: core
Result: INFECTED
Going through my scan logs, it appears that there has been an infection which AVG has been unable to resolve an issue that has been there since 06/06/14, which is worrying, as I didn't notice this until now (usually AVG would advise me if it is unable to heal infected files). I'm pretty sure I've run a routine Malware Bytes scan since the 06/06/14. I have not done so this time as wanted some advice before proceeding.
Lots of thanks in advance for any help.
Holly.

tashi
2014-06-26, 19:40
Hello Holsten87, :greeting:

In order for someone to advise please see the forum sticky which includes guidelines and instructions in post #2 on how to provide the preliminary DDS and aswMBR logs used for analysis.

http://forums.spybot.info/showthread.php?t=288

Then start a new topic providing the logs so a volunteer analyst may advise when available. :)

Best regards.