1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Need Help With Trojan Horse [cisvc.exe]

Discussion in 'Malware and Virus Removal Archive' started by James Martin, 2005/08/21.

  1. 2005/08/21
    James Martin

    James Martin Geek Member Thread Starter

    Joined:
    2003/05/15
    Messages:
    2,655
    Likes Received:
    79
    Hi All,

    AVG has identified a TH on my pc....

    F:\Dell XP With SP1a\I386\CISVC.EX_:\cisvc.exe
    Trojan horse Dropper.Agent.8.B Infected, Embedded object

    Selected object is located inside the archive and cannot be healed.


    I cannot find anything here on the subject, and AVG's virus encyclopedia has not been much help either.

    But there was something on Google about this TH, and it talked like it was an error on AVG's part.

    There were 2 other TH's, but I deleted them. Now I'm wondering if I did the wrong thing. :confused:

    Any help is appreciated.
     
  2. 2005/08/22
    James Martin

    James Martin Geek Member Thread Starter

    Joined:
    2003/05/15
    Messages:
    2,655
    Likes Received:
    79
    Bump :D
     

  3. to hide this advert.

  4. 2005/08/22
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  5. 2005/08/23
    James Martin

    James Martin Geek Member Thread Starter

    Joined:
    2003/05/15
    Messages:
    2,655
    Likes Received:
    79
    Sorry Pete! :eek:

    There were a few other threads above mine that had quite a few looks (compared to mine), and I was worried that there was no fix for me.

    I read the thread a time or two, but so far I honestly can't seem to grasp what they're talking about......Maybe just bits and pieces of it.

    I'm not even sure if it is a true trojan horse that they're talking about. They were talking about replacing system files--Can't that be done with the sfc/ command instead?

    Sorry for the confusion! :)
     
  6. 2005/08/23
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I suspect this is a false positive - cisvc.exe is related to File Indexing in XP. As AVG does not pick this up on your system I guess you do not have the Indexing Service running (wise move :))..

    The location you posted F:\Dell XP With SP1a\I386\CISVC.EX_:\cisvc.exe is the install cab for XP (I386) - the folder a mirror of the installed system as delivered (?).

    If you remain concerned download the trial of Ewido and run it and see what it comes up with.

    In the meantime I have edited your thread title in the hope that someone better versed in these matters drops in.
     
  7. 2005/08/23
    James Martin

    James Martin Geek Member Thread Starter

    Joined:
    2003/05/15
    Messages:
    2,655
    Likes Received:
    79
    Indexing Service is not running the last time I checked.

    FWIW, the TH was detected on the 8-9-05, but all subsequent scans have come up clean.

    Also, last night I did an online scan with Panda, and the scan was clean (Except for this.... Adware:adware/cws
    No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\FAVORITES\Health
    )

    Ad-Aware, Spybot, and MS Anti-Spyware all failed to see it.

    But I guess that's for another thread.


    I had copied the Dell XP disc (Home version) to the F drive a while back......I don't suppose it would be a bad idea to delete it would it (or maybe shred the 1386 folder first), and then recopy the disc?


    Thanks, I'll give the program a try (First I suppose), and thanks for correcting my thread title too.
     
  8. 2005/08/23
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I rather doubt that is necessary - cisvc.exe is in the I386 folder legitimately. Quite possible that recent AVG updates have solved this 'false positive' - which it is IMO.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.