• Software
  • svchost.exe and clr.exe MALWARE!

I got a notification from Kaspersky IS about a clr.exe infected file residing in the path "C:\Users[i]username[/i]\AppData\Local\Temp", there was also a running process associated with it, I have no idea how that happened and got passed KIS, anyways the annoying part was that KIS was not able to disinfect (delete) even with a reboot. While I was doing that manually, the files CLR.exe, CLR.bat, and CLR.txt kept being created on reboot, so I used sysinternals procmon.exe to check the process activity. While I was at it I displayed the process tree and noticed :

The interesting part here is that this svchost.exe residing in "c:\Users[i]username[/i]\AppData\Roaming\Microsoft" is not detected by Kaspersky and it is the parent process that creates the CLR.exe file and runs it on reboot, even scanning the file manually does not raise any flags. I finally did the removal manually, now going to change passwords since I am not sure what was uploaded by this trojan.
Anyone has any idea about this or has experienced a similar situation, please share...
I had weird stuff happening on my PC... I was able to get rid of most but some stuck like in your situation. But then after a while the number of updates from Microsoft must have at sometime replaced the faulty file and that problem was gone :)

PS: if it's related to windows explorer you can use Shexview (I think) which will let you disable windows explorer extensions.
rolf wroteI had weird stuff happening on my PC... I was able to get rid of most but some stuck like in your situation. But then after a while the number of updates from Microsoft must have at sometime replaced the faulty file and that problem was gone :)

PS: if it's related to windows explorer you can use Shexview (I think) which will let you disable windows explorer extensions.
svchost.exe was not a windows process, it was a fake and was not even a good fake since it was x86 (*32 showed beside it in Task Manager).
Maybe this is also caused by the same trojan? Please monitor your bandwidth consumption, if you see 20MB - 26MB being downloaded by Host Process For Windows Services, then we both have the same problem. And by the way, I have Kaspersky Internet Security as well.