Перейти к содержимому


Фото
- - - - -

New Unknown Virus


  • Please log in to reply
2 ответов в этой теме

#1 rukicc@apollo.lv

rukicc@apollo.lv

    Newbie

  • Members
  • 1 Сообщений:

Отправлено 10 Февраль 2010 - 20:52

Hi,

Situation:
After reboot PC is extremly slow, no icons no start menu after 15 - 25 min icons displayed but pc is slow.
if manualy kill SVCHOST exe whitch use more than 18MB memory. then user interface is ok and working until restart.

in registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\ under netsvc value delete Shell hardware detection then after restart computer works aceptable, but...

Broken installer service. un able to repair.
problems in dcomcnfg when try to access component services -> Computers - dcomcnfg exit without any message.

Symantec antivirus system - clean
Kaspersky - clean
Cureit - clean
avira - clean

No high cpu, ram or network usage


in event viewer i see strange messages similar to:

The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80080005 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Drive d - CD


Application image dump failed.
Server Application ID: {01885945-612C-4A53-A479-E97507453926}
Server Application Instance ID:
{3419D9D9-3A5A-4439-80B6-1276E95534A1}
Server Application Name: COM+ Explorer
Error Code = 0x80004005 : Unspecified error
COM+ Services Internals Information:
File: f:\xpsp3\com\com1x\src\shared\util\svcerr.cpp, Line: 1259
Comsvcs.dll file version: ENU 2001.12.4414.702 shp




any ideas how to identify this virus

#2 mrbelyash

mrbelyash

    Беляш

  • Members
  • 25 897 Сообщений:

Отправлено 10 Февраль 2010 - 21:04

re-direct https://support.drweb.com/new/tech/?lng=en
wiki https://drw.sh/endjcv | Утилиты https://drw.sh/dgweku | Лечить удаленно https://drw.sh/wmzdcl | Скрытые процессы https://drw.sh/tmulje | Логи https://drw.sh/ruy | Песочница https://drw.sh/exhbro

#3 fedf

fedf

    Newbie

  • Posters
  • 7 Сообщений:

Отправлено 11 Февраль 2010 - 08:47

I suggest You run WMIDiag - http://www.microsoft.com/downloads/details...;displaylang=en

See LOG-file, register "missed" dll's like ole32.dll, oleaut.dll - "regsvr32 %SystemRoot%\System32\ole32.dll", "regsvr32 %SystemRoot%\System32\oleaut32.dll" and so on, according log's "WMIDIAG-V2.0.....LOG" and "WMIDIAG-V2.0.....TXT" in %USERPROFILE%\Local Settings\TEMP

Windows Installer 4.5 Redistributable is here - http://www.microsoft.com/downloads/details...;displaylang=en