Unrecognized/Suspicious Item in Startup

Good morning,

 

I recently noticed a suspicious file in the startup tab

 

Startup Item = rtwzhB45pjozhrdf (the italicized Red B is actually a symbol that I am unable to replicate... but it looks like a "B"..sorta"

Manufacturer = aergh9u9qagzheard

Command = C:\Program Files (x86)\Windows NT\svchost.exe

Location = HKCU\SOFTWARE\Microsoft\CurrentVersion\Run

I've run a full system scan using Norton 360 and Spybot Search and Destroy... Norton did not recognize it as a threat but It appeared that Spybot did find it and deleted it... until I rebooted and it was there again.

I deleted the file it is pointing to, well I renamed it first but it simply created a new svchost.exe file on my next startup. I also deleted the registry key but it also recreated on the next restart.

Any help you could provide would be GREATLY appreciated.

/Dan

Hi,

this must be some kind of a virus/malware. Svchost.exe can be located only in c:\windows\system32.

You should boot up in safe mode (by the start press F8 until you see a list, and select there safe mode), and run the virus scans again.

 

Let us know the scsan results.

 

ps: update all virus definitions before restart to safe mode

ps2: we usually recommend to scan the system with Malwerbyte's AntiMalware too, if you have time, please do it as well

Thank you, I appreciate the rapid and helpful response!

 

I did as you suggested and started up in Safe Mode, I ran Norton 360 first but it did not recognize any threats, I then repeated the process using Spybot which did identify and delete the offending program.

 

I've dl'd AnitMalware and having it do a scan just to see what it might find.

 

Thanks again for your help

 

/D