Author Topic: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe  (Read 7953 times)

0 Members and 1 Guest are viewing this topic.

sleepless

  • Guest
I keep getting a virus alert when I press CTRL+ALT+DEL to access the Windows task manager. Avast moves taskmgr.exe to the vault.

It says taskmgr.exe is infected with Win32:Evo-gen [susp]. It also mentions process winlogon.exe.


Yesterday I thought I'd solved the problem, and Avast didn't seem to detect anything when analysing winlogon.exe and taskmgr.exe, or when performing a full system scan.

But now it's back. I press CTRL+ALT+DEL and the alert pops up, sending taskmgr.exe to the vault again.


I also ran a scan with Malwarebytes, but nothing showed up.


I've googled a lot, and I found people with winlogon and evo-gen [susp] problems, but nothing related with taskmgr. And Avast says winlogon.exe is clean.

I'm clueless.



(I'm on Win XP SP3)


Screenshot (in spanish)
« Last Edit: March 15, 2013, 05:09:56 PM by sleepless »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #1 on: March 15, 2013, 02:05:06 PM »
right click the file in chest and upload to avast lab as false detection
you may give a link to this topic in case they reply here

sleepless

  • Guest
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #2 on: March 15, 2013, 03:59:06 PM »
Ok.

I sent it to avast lab with a link to this topic.


Here's a screenshot of the alert message (in spanish):


Cdick001

  • Guest
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #3 on: March 16, 2013, 08:12:14 PM »
I have the same problem,
What should I do now?

It has deleted my taskmgr.exe!
Now I cannot use it.
What should I do now?
« Last Edit: March 16, 2013, 08:51:42 PM by Cdick001 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #4 on: March 16, 2013, 08:52:46 PM »
I have the same problem,
What should I do now?

It has deleted my taskmgr.exe!
Now I cannot use it.
What should I do now?
same as i told the one above to do....upload to avast lab


Cdick001

  • Guest
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #5 on: March 16, 2013, 09:19:22 PM »
I have the same problem,
What should I do now?

It has deleted my taskmgr.exe!
Now I cannot use it.
What should I do now?
same as i told the one above to do....upload to avast lab



Dear sir,
I have go through the chest, it is not in the chest already.
And I have read the log, avast has already deleted my taskmgr.exe
I cannot upload anything to you, and now I have no taskmgr.exe to use with my Win XP.


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #6 on: March 16, 2013, 10:30:55 PM »
Quote
I have go through the chest, it is not in the chest already.
And I have read the log, avast has already deleted my taskmgr.exe
I dont think avast would delete a file detected as suspicious..... have you changed any of the default settings?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #7 on: March 16, 2013, 10:57:50 PM »
I have just flashed up my XP and used task manager with no ill effects... Maybe your one was actually infected
I have placed a copy of my task manager in my dropbox here https://dl.dropbox.com/u/73555776/taskmgr.exe

Offline davexnet

  • Poster
  • *
  • Posts: 540
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #8 on: March 16, 2013, 10:58:27 PM »
I'm on XP sp3 and my task manager opens fine.  Has anybody sent the suspect file to virustotal?
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

Cdick001

  • Guest
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #9 on: March 17, 2013, 04:31:05 AM »
I'm on XP sp3 and my task manager opens fine.  Has anybody sent the suspect file to virustotal?

I did full a scan afterwards, it did not show any threats.
Let me get back a taskmgr.exe, and scan again.


I have just flashed up my XP and used task manager with no ill effects... Maybe your one was actually infected
I have placed a copy of my task manager in my dropbox here https://dl.dropbox.com/u/73555776/taskmgr.exe

Thanks!
« Last Edit: March 17, 2013, 04:33:20 AM by Cdick001 »

sleepless

  • Guest
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #10 on: March 17, 2013, 01:23:59 PM »
I replaced my taskmgr.exe (I have another PC with XP SP3) and now the warnings are gone.

Everything is clean, or so it seems.

Offline davexnet

  • Poster
  • *
  • Posts: 540
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #11 on: March 17, 2013, 10:57:38 PM »
I checked my XP SP3, there is a second copy of the file in \windows\system32\dllcache.
Would malware typically attack both copies?
AMD FX-4300 4GB DDR3
avast free 2279 (Windows XP), MBAM free

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Problem with Win32:Evo-gen [susp] taskmgr.exe and winlogon.exe
« Reply #12 on: March 17, 2013, 11:00:16 PM »
Normally the dll cache copy should be safe