Start a Conversation

Unsolved

This post is more than 5 years old

13626

November 1st, 2006 20:00

XPS 410 Runtime Error wmiprvse.exe

XPS 410 Runtime Error wmiprvse.exe
 
On a new 410 (received second week of Oct)... the full error is:
 
-------------------
 
Microsoft Visual C++ Runtime Library
Runtime Error!
Program: C:\WINDOWS\SYSTEM32\WBEM\wmiprvse.exe
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information
---------------------
 
It's happening several times a day, with each incident generating two of the above messages - one ontop of another.
 
Any ideas? 

November 2nd, 2006 03:00

Start >> RUN >> Regedit and look for the issues noted at this link to see if you have a virus that masquerades as this file:

http://www.sophos.com/virusinfo/analyses/w32sonebotb.html

========================

This section helps you to understand how it behaves

W32/Sonebot-B is a network worm which includes IRC bot and backdoor functionality that allows unauthorised remote access to the infected computer.

This worm copies itself to network shares with weak passwords, initiates a remote background process, connects to a remote IRC server and joins a specific channel.

W32/Sonebot-B drops a copy of itself to the Windows System32 folder with the filename WMIPRVSE.EXE and sets the following registry entries to run the copy on system restart:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Kernel_check = wmiprvse.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Kernel_check = wmiprvse.exe

W32/Sonebot-B also attempts to terminate a number of processes and delete a number of files from the infected computer.

This worm may also set the following registry entries:

HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\
AutoShareServer =
AutoShareWks =

HKLM\System\CurrentControlSet\Control\lsa\
RestrictAnonymous =
RestrictAnonymousSam =

========================

5 Posts

November 2nd, 2006 08:00

Phobos512 -
 
Thanks for the info! What I know so far...
 
"W32/Sonebot-B drops a copy of itself to the Windows System32 folder with the filename WMIPRVSE.EXE":
 
This is NOT the case on my system -- the only copy of wmiprvse.exe is in C:\WINDOWS\SYSTEM32\WBEM\ not C:\WINDOWS\SYSTEM32\
 
The system is not on a network per se -- it is sharing wifi broadband cable internet access.
 
More later.

5 Posts

April 7th, 2007 17:00

Here it is April 2007 and the error continues.
 
"runtime error...  ...wmiprvse.exe terminate it in an unusual way"
 
Any ideas?
 
 


Message Edited by walts0042 on 04-07-2007 02:15 PM
No Events found!

Top