
I am looking for advice and words of support. I have been using Windows 7 for a relatively long time. I don’t want to be the cause of holivars in any way, but I like the “seven”. More than XP and even more so than Vista. I love * nix systems, I love MacOS, but it turned out that the problem that has arisen is taking place on Microsoft products.
It started a couple of months ago, and
today a reason has been found .
In the “Start” menu (I use the English 32-bit system, the Russian scared me with my translation) in the area for fixing the shortcuts for quick launch, the icons and correct links to executable files were lost. Unpin and pin to ... did not help. The same attack happened with the taskbar. The Quick Launch folder was empty. All “turn off and turn on” (IT-crowd) manipulations didn’t give any results either. Additionally, I noted for myself that the search in the same menu “Start” stopped working and often responded with an error window. At that time there was a beta. Bilda, unfortunately, I do not remember, and it does not matter. Some programs stopped running. Those that are still running, stopped saving settings. Google Chrome has stopped going to Google Mail. And you have to work. Demolished everything, put XP. On a clean system set Kaspersky, - silence. On the same day, all the symptoms seen on the “seven” were repeated. Virus? Maybe. CureIt and AVZ found nothing. Moreover, the shortcuts from the Quick Launch folder are erased right before your eyes, and not during a reboot (a problem known in the vast web). Dumped all info on a portable disk. Formatted completely screw, demolished MBR. On the "virgin" computer put Windows 7 RC. Protected by antivirus. Two days later, the problems returned. The first time helped roll back to Restore Point, but less than a day. Everything. Again, I sit at the broken trough. Newly installed software on the machine immediately begins to fail.
')
The letter describing the symptoms for more than a month has been ignored by Kaspersky Lab despite the fact that I have a licensed version of KIS2009.
If it were not for the specific software and equipment, I would have been sitting under Linux long ago. And I don’t even know what to do. No one met? Any ideas?
UPD:Summary of comments and responses to them:
- I remembered that one time I cleaned mdm with my hands, which I hadn’t seen Casper. Therefore, there are suspicions of Trojan downgraders.
- The screw is already lying, it remains to raise the system on it.
- The memory has not been tested yet, but there are plans. And BIOS reflash.
- I did not install the left software, only trusted free software in the minimum set.
- Network access through NAT. Without an Internet I can not sit a single day - work.
- Antiviruses tried: KIS, Avast, AVZ, CureIt.
- The second day running Process Monitor, but the problem does not occur.
- The mentioned XP was installed from a disk that had been in use for five years. There were no such problems before.
Well ... Who had any doubts about the viral origin of the problem? Wash everything there.
Here is the Process Monitor log: e580.ru/Logfile.CSV
If, briefly, svchost is looking for antivirus shortcuts in quanche. Or is it Windows Defender svhost looking for viruses? Completely confused ... In any case, 13 svchostov probably a bit too much?
I would like to know what kind of virus and how to protect. What to do?With the help of Process Monitor found cattle, which muddies the water. The Trojan got into a software. Thank you all for your advice and help.
The killer was a new version of the specialized software necessary for work. Its low prevalence also affected the uniqueness and rarity of the described problem.