Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer in use & locked, plus other error messages.


  • Please log in to reply
3 replies to this topic

#1 GeraldUK

GeraldUK

  • Members
  • 88 posts
  • OFFLINE
  •  
  • Local time:01:28 PM

Posted 17 May 2011 - 04:50 AM

I am using a desktop running Windows XP SP3 with 2GB RAM.

Very recently I was infected by a trojan(s) and that got cleared up via a thread in “Am I Infected.”

Oddly when coming to my computer in the morning I have found a notice that the computer (which I leave on overnight) is in use and had been locked. I just reboot and off we go.

This morning I had the same message but in addition a few error messages: “Unable to relaunch restart.exe.”

Another ERF which said that my Avira antivirus “ccwkrlib.dll cannot be found or has been modified or destroyed.” The Avira system tray icon was missing.

Could not read from file Qualcomm\Eudora\Out.mbx (Eudora is my email program).

I did a hard reboot, which was fine and I looked at Event Viewer - which showed 2 system errors at about 4.00 am UK time.

One was “Unable to start DCOM Server”(Event10000) and it said there was insuffienct resource when carrying out C:\Windows\system32\wbem\wmiprvse.exe - Embedding.”

Later 4 or 5 “SidebySide” error (Event 59): “Resolve Partial Assembly failed for Micosoft VC90.CRT. Reason, again, insufficient resources.

These insuffient resources are a real mystery as I always leave my computer with just Windows Explorer open plus minor stuff like firewalls.

Anyway, I just did a (short) Malwarebytes scan, plus a Spybot scan - both showing clear. I see that on 14th May I had done a full Avira scan - which was also clear.

The only other bit of information, which I do not understand is an Application Event about 3 days ago from WinMgmt event 63 saying “a provider, OffProv11, has been registered in the WMI namespace. Root \MSAPS11 to use the local system account.” and it may cause security violations....

I am not sure where to go from here. The coming to my computer to find a message that it has been locked is not new - has been happening about once a week for a month.

Be grateful for any advice from the more computer literate!

BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 55,757 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:07:28 AM

Posted 17 May 2011 - 09:45 AM

Please...it helps if you post the exact, entire wording...of any onscreen messages indicating a problem.

If a file path is indicated on such, please include.

Filenames are often not reliable references when troubleshooting, since various malware items will either duplicate or slightly change legitimate filenames. Looking at the path indicated helps.

Louis

#3 GeraldUK

GeraldUK
  • Topic Starter

  • Members
  • 88 posts
  • OFFLINE
  •  
  • Local time:01:28 PM

Posted 17 May 2011 - 10:23 AM

I would have posted more detail, particularly the Event errors, but do not know how to do so. In a way, the short system factual errors did not contain too much detail except the path of where the Avira file was.

Funnily enough I have just completed a full Avira scan which was clean except for I hidden object:

"Start of the scan: 17 May 2011 11:44

Starting search for hidden objects.
HKEY_LOCAL_MACHINE\System\ControlSet011\Services\NtmsSvc\Config\Standalone\drivelist
[NOTE] The registry entry is invisible.

The scan of running processes will be started......"

I can do copy and paste of the relevant bits - when the system allows me! Event view seems not to allow it.

Using regedit the key does end at folder Standalone - there is no drivelist shown.

From what I have posted, are you able to hazard any guesses as to what might be causing these problems? Of course, I can always wait until the next time.

Regards

#4 hamluis

hamluis

    Moderator


  • Moderator
  • 55,757 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:07:28 AM

Posted 17 May 2011 - 12:52 PM

I was referring to onscreen error messages...not Event Viewer errors.

If you wznt to investigate EV errors, you can use a combination of:

www.eventid.net, insert the Event ID and stated Source for a given error...you will be taken to user feedback on their interpretations of the error and how to overcome it.

If you cannot find a given error at that website...I suggest just using Google to find an interpretation that is more definitive.

And...of course...double-clicking on any line item reveals the detail. If a link to MS is included, please click on it and see what info they have.

Louis




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users