Trojan horse scgeneric2.aoeh

Yesterday afternoon 6/23/2017  AVG after an update found Trojan Horse SCGeneric2.AOEH  C:\windows\assembly\nativeImages_v2.0.50727_32\xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

I found one mention of it yesterday about the same time.
Is this a false positive?

Thanks,

Bob Caldwell

Hello Robert,
Please share the screenshot of the AVG threat detection window, we will check the screenshot and let you know if it's a Trojan or not.
To create a screenshot, please follow this article http://avgread.me/1aZxsAV .
Thank you.

I received the AOEH false positive, but I also received the same one frank did. It says AOES, not AOEH. Is this also a false positive? 

Trojan Horse SCGeneric2.AOES
C:\Windows\twain_32.dll

I have AVG Internet Security. Only used on home computers.

@ Kim Schwaninger
Kim, Also have a look @ these 2 links…
[1] (https://support.avg.com/partners_contact_form?l=en&retUrl=partners)
[2] (https://support.avg.com/business_contact_form?l=en_US)
Please be informed that this Community forum basically deals with 'home' version of AVG products.
AVG Guru

Hello Kim,
May I know if it is a business edition or home edition of AVG you are using? If it is a home edition of AVG, please confirm if it is a free version or a paid version. I'd be grateful if you could share a screenshot ( http://avgclick.me/getscreenshot ) of the threat detection pop up. Click on 'Answer' & then click on the 'Image' [mountain symbol] & follow the instructions.

We are having very similar issues with our Business Internet Security product.  Our computers are reporting the rundll32.exe as infected.  I assumed it was a false positive, but still was very nervous.  I entered a case with support yesterday and still have not received an answer.  I have got more information from this post than with their support.  This is the hair that broke the camel's back if you know what I mean.

Not sure why my version is business, I don't own a business, this is strictly personal home PC.  I'll just have to take it in tomorrow for someone to help.  Thanks.

I received the AOEH false positive, but I also received the same one frank did. It says AOES, not AOEH. Is this also a false positive? 

Trojan Horse SCGeneric2.AOES
C:\Windows\twain_32.dll

I have AVG Internet Security. Only used on home computers.

Hello Brian,

If you contact our Business support, you will be able to get the details about the fix.
Thank you.

Received this this morning…

Thank you for contacting AVG.
I do apologize for the inconvenience. This issue has been addressed and it is a false positive. The fix will be released it the next virus definition update (14607). 

Hello Robert,

This seems to be a false positive as well. Please run AVG repair and check if that fix this issue and let us know the version of AVG installed in your computer.

Hello Mike,
I request you to contact our Business support team (https://support.avg.com/internet_security_business?l=en), they will be in best position to help you. If you already submitted a request, then I request you to wait for them to reply you. I'm sorry but we do not have scope to help you with AVG Business Internet Security program. Your patience is much appreciated in this matter.
Best regards,
Alok.

Hi, I've got this issue on a server too also with multiple events in the same path \TEMP folder with resident shield (Note Object inaccessible after attempted removal)

"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP60B5.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:20:50";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPBD65.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:54";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPAFBF.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:50";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA228.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:47";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP93E5.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:43";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8584.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:39";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7741.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:36";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"
"Trojan horse SCGeneric2.AOEH";"c:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP68EF.tmp\System.Data.dll";"Object is inaccessible.";"25/06/2017, 10:00:32";"file";"C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe"

Hello Kim,
May I know if it is a business edition or home edition of AVG you are using? If it is a home edition of AVG, please confirm if it is a free version or a paid version. I'd be grateful if you could share a screenshot ( http://avgclick.me/getscreenshot ) of the threat detection pop up. Click on 'Answer' & then click on the 'Image' [mountain symbol] & follow the instructions.

This showed up over the past 2-3 days on nearly every client computer running AVG.  This is many dozens of computers, including my own.  All running CloudCare, all updated to the latest, no other errors or detections.
Screenshot of error

@ Simon Sparkes
Simon, Also have a look @ this AVG webpage (https://support.avg.com/business_contact_form?l=en_US). Please be informed that this Community forum basically deals with 'home' version of AVG products.
AVG Guru

Also got the same issue this morning from Business edition
Trojan horse detection

@ Del Dayton
Del, 'AVG CloudCare' support… Have a look @ this AVG webpage (https://support.avg.com/partners_contact_form?l=en&retUrl=partners). Please be informed that this Community forum basically deals with 'home' version of AVG products.
AVG Guru

I've recieved a similar alert to Bobs, except that the threat was called ' Trojanhorse SC Generic2.AOES'. (Not 'AOEH')

The Object Name was: C:\Windows\twain_32.dll

I didn't think of getting a screenshot, just noted the particulars.

When the AVG Detection alert popped up, I clicked on "Protect Me".

I'm uncertain if it is a connected problem, but I can no longer access my Canon MX700 Copier/Scanner/Faxer.

Hello Simon,

I am sorry to hear that. You can contact our AVG Business support from this link http://www.avg.com/us-en/customer-support-business and they will assist you further.