Hi,
as of yesterday my computer has been performing sluggish. I've identified the problem to a service running under svchost.exe. When i suspend that particular process the computer goes back to running normally again.
I've installed and ran Svchost Viewer, and i'm able to indentify themalfunctioning svchost.exe with it's PID. But the service information tree underneath it is empty (unlike all the other services running). The PID is also different everytime i reboot the system.
I've performed all kinds of virus scans on the cumputer, but no virus or trojan or anything is detected. However, Norton Auto protect tries blocking two different viruses (the dialogue keeps poping up every five minutes or so). This continues even after the unknown process described above is suspended.
The two found viruses are named Hacktool.Rootkit and Trojan.Gen.2, and here's a dump:
Full Path: c:\windows\installer\{802c7347-9c23-6c3c-462b-e65e6cccccc8}\u\80000000.@
Threat: Hacktool.Rootkit
____________________________
____________________________
On computers as of 2012-05-27 at 15:54:25
Last Used 2012-05-27 at 15:54:25
Startup Item No
Launched No
____________________________
____________________________
Unknown
Number of users in the Norton Community that have used this file: Unknown
____________________________
Unknown
This file release is currently not known.
____________________________
High
This file risk is high.
____________________________
Threat Details
Threat type: Virus. Programs that infect other programs, files, or areas of a computer by inserting themselves or attaching themselves to that medium.
____________________________
____________________________
File Actions
File: c:\windows\installer\{802c7347-9c23-6c3c-462b-e65e6cccccc8}\u\80000000.@
Blocked
____________________________
File Thumbprint - SHA:
d9dc59c3f6e026874ea58888c54b597a8c080e446062c9c80be833649df04f29
____________________________
File Thumbprint - MD5:
3ba69999f27f85670cfa627204427584
____________________________
I can also add that i've been trying to roll back windows to an earlier date, but this operation fails.
I've been searching your forums for a solution, and it seems that other people have had similar problems, but still i haven't found a solution. The same goes for other forums i've been searching.
So if you could please help me with this i would appreciate it a lot! Thank you so much in advance.
Henrik