1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Generic host process for win32 services has encountered a problem and needs

Discussion in 'Malware and Virus Removal Archive' started by SNY, 2008/06/24.

  1. 2008/06/24
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    I cant re raise this thread but this exact problem is occuring with my brand new PC! http://www.windowsbbs.com/showthread.php?t=56803

    Any help with this would be much appreciated as it didn't seem to be resloved fully in the above thread

    cheers.
     
    SNY,
    #1
  2. 2008/06/24
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    SNY - Welcome to the Board :)

    Read this and post the logs requested.
     

  3. to hide this advert.

  4. 2008/06/24
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    will do
    anyone know how this occurs? i've literally done nothing more than use internet for half hour?
     
    SNY,
    #3
  5. 2008/06/24
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    for information:
    have used spybot search and destroy and AVG free addition and found nothing wrong.
    also it wodoesn't look like it will me enough access to the internet to do download HijackThisâ„¢ or anything else
    hmmm
     
    SNY,
    #4
  6. 2008/06/24
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Please wait on guidance fron our trained malware experts - as you can imagine they are overworked - we are all volunteers here, so it may take a while.
     
  7. 2008/06/24
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    i appreciate that im in no rush as i'll be sat a desk at work for the next 5 hours
     
    SNY,
    #6
  8. 2008/06/24
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I think hours may be wishful thinking - our experts are both in the States.
     
  9. 2008/07/15
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    Still no reply? what sort of time wouldn't be considered wishful thinking?
    any reply would be appreciated as I'm in a bit of a rut...
    Thanks.
     
    SNY,
    #8
  10. 2008/07/15
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Not sure why your thread has apparently been overlooked, but I see you have not posted the logs requested as yet.
     
  11. 2008/07/15
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    I dont have internet, as mentioned, so i have no way of getting HijackThisâ„¢... I don't know how to get all the information, is there a program already installed with Windows that does this?
     
    SNY,
    #10
  12. 2008/07/15
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    You obviously have internet access so download HJT from here ....

    http://www.trendsecure.com/portal/en-US/

    Save it to a USB stick -install & run it on the affected computer - save the log file, copy it to the USB stick and post it here.
     
  13. 2008/07/15
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    I have limited internet access at work (hence my posts) but downloads aren't permitted. I can think of a long winded idea:

    1. Get HijackThisâ„¢ onto USB stick
    2. Transfer onto my PC. Copy logs into word file.
    3. Copy word file back onto USB.
    4. Email this to my PC here at work.
    5. Repeat when more info is needed.

    Will this suffice?
     
    SNY,
    #12
  14. 2008/07/15
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Sure - the log is saved by default as a .txt file to the drive on which HJT is run.

    I will draw the attention of your thread to our trained analysists.
     
  15. 2008/07/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi SNY,

    Your topic wasn't really overlooked, but thought to be dropped by you since no logs were posted, nor a response from you stating you were unable to post said logs. Apologies :eek:

    Most users with this problem still have internet access, it's just limited to the time it takes to get the error and have it drop out. Are you saying you have no access at all?

    Please give us at least a few details about this 'new' pc.
    What operating system (XP, Vista), and what version (original XP, SP1, SP2)?
    Home built (or shop built) or store bought?

    Oh, for the record, the topic you first linked to was resolved for the original user, as well as several others that appended to it ..... by installing the patch from Microsoft that was suggested in post #44. ;)
     
  16. 2008/07/25
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    Finally! This is the Notepad file that came out of HiJack results:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:37:44, on 25/07/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\TDSupportApp\cdrom_mon.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\STacSV.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\sttray.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\ZTE Mobile Connection\datacard.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe "
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C5CC5B96-B509-47A8-ADEF-E693CD6BD0E4}: NameServer = 4.2.2.3 4.2.2.4
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Autorun CDROM Monitor - Unknown owner - C:\WINDOWS\system32\TDSupportApp\cdrom_mon.exe
    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

    --
    End of file - 6071 bytes
     
    SNY,
    #15
  17. 2008/07/25
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    Noah, thanks for response btw, much appreciated I have taken time to get HiJack this using internet on my PC, i find leaving it for a while (hours, days) i get longer internet acces, enough to d/l.

    PC is custom built, person not shop:
    - Intel Core 2 Duo CPU, E8400 @ 3.00 GHz
    - Microsoft Windows XP (Service Pack 2)
    - NVidia GeForce 8800 GT
    - DirectX 9.0c
    Anything else about the spec relevant?
    Responses really appreciated, i'll be looking forward to hearing back, thanks.
     
    SNY,
    #16
  18. 2008/07/25
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    P.s Will the d'l you mentioned be of help?
     
    SNY,
    #17
  19. 2008/07/25
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    The MS patch might fix the problem. I certainly recommend you attempt to download and install it before anything else. A reboot may be required for changes to take effect.

    Let me know the outcome. :)
     
  20. 2008/07/26
    SNY

    SNY Inactive Thread Starter

    Joined:
    2008/06/24
    Messages:
    11
    Likes Received:
    0
    The patch seems to have worked I've been on the internet ages now and no problems....i'm getting a new, better internet connection soon so if any problems do arise i'll post em.

    Does the log file look like it has any problems?

    Thanks for all time and responses.
     
    SNY,
    #19
  21. 2008/07/26
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Good to hear. :)

    Log appears clean.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.