Question

Generic host for Win32 Svchost.exe error persistant -and I am stuck.

Asked by: Cosmo2b

In XP I get Generic host for Win32 error when my computer boots up to desktop if I have an internet connection.  If I close that out I quickly get a svchost.exe error.  After this my computer pretty much locks up -it does some basic functions but doesn't go online and opening other programs sometimes works and sometimes doesn't.

My System:
Dell D820 Latitude portable computer 2.0 duocore
Dual booting to XP or Vista Ultimate

What I have tried:

From XP:
Ran Spybot
Ran AdAware
Ran Avast antivirus
Ran SuperAntiSpyware

Turned off Automatic updates
Went to www.windowsupdate.com and got updates until current
Turned Automatic updates back on
>>Issue reoccurred

Turned off Automatic updates
Renamed the Software distribution folder
Downloaded Windows Installer 3.1 v2
Reboot
Turned on Automatic updates
>>On next reboot issue reoccurred

In Vista:
Ran full Licensed Trend PCcillin across both partitions XP & Vista
>didn't find anything significant -cleaned up a few cookies

Reboot into XP
>>Issue reoccurred

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-09-06 at 16:10:37ID22812298
Tags

error

Topics

HijackThis Software

,

Windows XP Operating System

,

Internet & Email Software

Participating Experts
3
Points
0
Comments
49

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. SVCHOST.EXE
    What is SVCHOST.EXE and why would their be 4 instances running concurrently on my computer?
  2. Svchost.exe
    All, I have windows server running on a dell poweredge, this server is acting as a file and print server and is joined to AD. The only programs installed are McAfee AV. The problem is that the server is really slow due to the service Svchost.exe taking up 99% CPU power. Has ...
  3. svchost.exe
    I see three svchost.exe; One of them is eating a lot of CPU time. Is there a utility that allows to track to which program is a given svchost.exe linked? Thank you, Daniel Bessis
  4. svchost.exe - Application Error
    I am desperate in trying to solve a problem I am having. Whenever I boot my computer, I get the following error message: svchost.exe - Application Error The Instruction at "0x00000000" referenced memory at "0x00000000". The memory could not be "read...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: Cosmo2bPosted on 2007-09-06 at 17:04:13ID: 19844568

Problem only occurs in XP  -no problems in Vista.

 

by: souseranPosted on 2007-09-06 at 17:34:15ID: 19844660

Can you download, install and run HijackThis from

http://www.spywareinfo.com/~merijn/programs.php#hijackthis

and post the log.

 

by: Cosmo2bPosted on 2007-09-07 at 00:18:45ID: 19845863

Hijack This Log:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 2:02:30 AM, on 9/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hitman Pro\srhelper.exe
C:\Admin_IT\Downloads\Hijack_This\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.rittercomputersolutions.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Hitman Pro SurfRight Helper] "C:\Program Files\Hitman Pro\srhelper.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 2833 bytes



This might be of use as well -Tasklist /SVC results

Tasklist /SVC produces a list all the below are the 6 different svchost entries and what is activated by each as the system starts:
svchost.exe    

1.)  DcomLaunch, TermService
2.)  RpcSs
3.)  AudioSrv, BITS, Browser, CryptSvc, Dhcp, ERSvc, EventSystem, FastUserSwitchingCompatibility, helpsvc, lanmanserver, lanmanworkstation, Netman, Nla, RasMan, Schedule, seclogon, SENS, SharedAccess, ShellHWDetection, srservice, TapiSrv, Themes, TrkWks, W32Time, winmgmt, wscsvc, wuauserv, WZCSVC
4.)  Dnscache
5.)  LmHosts, RemoteRegistry, SSDPSRV, WebClient
6.)  stisvc

 

by: souseranPosted on 2007-09-07 at 02:49:11ID: 19846382

Can you fix this:

O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

Also, when you connect, are you connecting to a wired or wireless network? If wired, can you disable your wireless and report back?

 

by: Cosmo2bPosted on 2007-09-07 at 10:55:03ID: 19849744

fixed O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)

Disabled wireless and LAN -under Network adapters  -so, no adapters to go online.
>>Next reboot -before logging in to profile I get the svchost.exe error
>>After logging in (with adapters disabled) I get the Generic Host for Win32 Services encountered a problem error.

Dunno if this is related:  In Event Viewer with second of the error I found an entry that says: The server was unable to add the virtual root '/Family Drivers' for the directory 'C:\Documents and settings\Profile I don't use anymore\Family Drivers' due to the following error: The system cannot find the file specified. The data is the error code.
A printer error for suitable Capture Fax driver not being found
A parallel error because it is disabled or no enabled devices are associated with it.  -probably normal because there are no devices attached to it

Then there are several NLA (Network Location Awareness) entries that are NOT failures but have the same timestamp.

The Main Generic...Win32 error is reported 1 second after the Windows Security Center Service started.

10:51:08AM EVENT ID 1000
4 seconds later an error says Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.  

**There are 3 more repetitions of Events of "the Windows Security Center started"  and "Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000. "

***Hmmn... the last entry adds the words svchost.exe

***Faulting application svchost.exe, version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.  

 

by: Cosmo2bPosted on 2007-09-07 at 11:14:42ID: 19849895

The Main Generic...Win32 error is reported 1 second after the Windows Security Center Service started.

I think this is the significant part but I don't know how to narrow down from here.  Maybe this and results from tasklist /SVC will give a clue.  I think I am stuck at this point though.

10:51:08AM EVENT ID 1000
4 seconds later an error says Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.  

**There are 3 more repetitions of Events of "the Windows Security Center started"  and "Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000. "

***Hmmn... the last entry adds the words svchost.exe

***Faulting application svchost.exe, version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.  

 

by: Cosmo2bPosted on 2007-09-07 at 11:45:13ID: 19850084

I kept rebooting to see if I could get anything different in Event viewer  -got one that says:

Faulting application svchost.exe, version 5.1.2600.2180, faulting module ntdll.dll, version 5.1.2600.2180, fault address ox00081fea

I got several others that look like the ones I already listed above.

 

by: souseranPosted on 2007-09-07 at 13:28:45ID: 19850757

Except for the fact that you're on XP, this Microsoft article seems as though it would apply:

http://support.microsoft.com/default.aspx?scid=kb;en-us;910666

Can you go to Start | type in:

sfc /scannow

You will need your Windows XP CD for this.

 

by: Cosmo2bPosted on 2007-09-07 at 17:27:48ID: 19851808

The link you sent has almost identical error listed in it  -the below part IS identical.
**************************
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000

Event Type: Information
Event Source: Application Error
Event Category: (100)
Event ID: 1004
Description:
Faulting application svchost.exe, version 5.2.3790.0, faulting module ntdll.dll, version 5.2.3790.0, fault address 0x0000694e.
***********************

I think the event ID Stayed 1000 in both places though  -I see it changes to 1004 here -dunno if that matters.

I did a sfc /scannow earlier but I don't remember what restore point I moved to trying to fix this -I will run it again and reboot -just in case I wiped it out.  

I will see if the fix for the 2003 has any bearing on the boot.ini on my system and if it helps.

 

by: Cosmo2bPosted on 2007-09-08 at 13:07:44ID: 19854417

As seen on the link you provided from Microsoft I have this setting in the Registry
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management

Key Name: PhysicalAddressExtension
Type: DWORD
Value: 1
I changed it to 0 but it always changes back to 1 on reboot -even though I added the /NOPAE into the boot.ini

sfc /scannow with Original XP w/SP2 media didn't provide any additional help -error still occurs.

 

by: SheharyaarSaahilPosted on 2007-09-09 at 06:23:35ID: 19856722

 

by: Cosmo2bPosted on 2007-09-10 at 15:34:42ID: 19864801

I did not have the KB921883 installed -but I brought it across on a USB stick and installed it.

System locks up and gives svchost.exe msg with either LAN or Wireless connection.

If I pull up task manager and list in order of memory usage and get rid of the largest svchost process -then I can surf.  However, if I do a IPCONFIG /RELEASE and /Renew I get an error saying that the RPC server cannot be found and I am no longer online.

Something of interest:
When I do an IPCONFIG I get a result like below -Extra IP ADRESS LINE??


IP ADDRESS:  192.168.1.104
SUBNET MASK: 255.255.255.0
IP ADDRESS: ?
DEFAULT GATEWAY 192.168.1.1

and then I get a tunnel adapter -don't have the exact msg on screen since I am using the same unit booted to Vista to try to fix the XP problem
But it's something like below:

Tunnel adapter
IP ADDRESS: ?

>>Error is still reoccurring

 

by: Cosmo2bPosted on 2007-09-10 at 15:54:25ID: 19864878

I just uninstalled IE7 in case that was an issue -I think that was installed a week or so before the problem occurred. I reinstalled by going to C:\windows\inf and right clicked on IE.inf and installed it with the XP CD in the drive.  

It didn't seem to help.

 

by: Cosmo2bPosted on 2007-09-10 at 15:55:20ID: 19864882

So, now I have IE6 Back on the unit.

 

by: Cosmo2bPosted on 2007-09-10 at 18:19:40ID: 19865367

>>I added comments just to be clear.  Not sure if I made this clear, but error is still reoccurring.
>>Error still occurs.

 

by: Cosmo2bPosted on 2007-09-10 at 18:33:55ID: 19865412

What if I deleted the svchost entries from the registry and deleted svchost.exe -then did a repair install -would that repair the things that are supposed to start with svchost ?  

Is there a way of figuring out which service(s) called by svchost is/are the problem and how to fix it/them?

 

by: SheharyaarSaahilPosted on 2007-09-10 at 22:37:46ID: 19866289

can you check out the Workaround in this MSKB?
http://support.microsoft.com/kb/910666

also is your system restore enabled?
if yes then can you try restoring it to the date when this problem was not there?

 

by: Cosmo2bPosted on 2007-09-11 at 07:55:57ID: 19869131

This was the suggestion by  [ID:19850757Author:souseranDate:09.07.2007 at 03:28PM ] listed above -->seems to match almost exactly as I mentioned on my next post after this comment -I was excited because the message matches what shows up in event viewer almost exactly -however, it didn't seem to help though.

I have tried system restore to no avail.

I don't know the services called by svchost well enough to tell which ones I could turn off but my gut says that is probably the way to fix this -however I am open to any kind of fix.  I don't have the experience many of you have -especially SheharyaarSaahil, but it seems to me that if we can end a svchost process and get things moving again that we should be able to narrow it down to a specific process called by svchost.

btw -This also seems to match up (generally) with MSKB 927385  http://support.microsoft.com/kb/927385/en-us  -->but none of that helped either.

From my first 2 posts I will reprint this for reference:

Tasklist /SVC produces a list all the below are the 6 different svchost entries and what is activated by each as the system starts -each one of the groups below is across from a svchost service in the listing.
svchost.exe    

1.)  DcomLaunch, TermService
2.)  RpcSs
3.)  AudioSrv, BITS, Browser, CryptSvc, Dhcp, ERSvc, EventSystem, FastUserSwitchingCompatibility, helpsvc, lanmanserver, lanmanworkstation, Netman, Nla, RasMan, Schedule, seclogon, SENS, SharedAccess, ShellHWDetection, srservice, TapiSrv, Themes, TrkWks, W32Time, winmgmt, wscsvc, wuauserv, WZCSVC
4.)  Dnscache
5.)  LmHosts, RemoteRegistry, SSDPSRV, WebClient
6.)  stisvc

 

by: Cosmo2bPosted on 2007-09-11 at 08:31:20ID: 19869518


From Post http://search.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/Q_22136817.html?sfQueryTermInfo=1+encount+failur+problem+servic+svchost+win32

I can see that to query a service within svchost I can do: sc qc servicename  
--> and to disable them i can do: sc config servicename start= disabled  and  sc stop servicename

As I troubleshoot what is the syntax to turn them back on?  I am guessing it is sc config servicename start= enabled and sc start servicename.

If I am going the wrong way and this can be solved a different way (I'm sure there is more than one way to go about this overall issue) please repoint me in the right direction.

The above post shows under Microsoft Operating Systems -I think I chose that as one of my three choices in posting this question -is this post in the right place for this type of question, -if not, let me know.

 

by: Cosmo2bPosted on 2007-09-11 at 08:41:24ID: 19869612

I just pulled up the Tasklist /SVC from a SIMILAR computer (that works fine) to see what it's svchost services are:
1.) DomLaunch, TermService
2.) RpcSs
3.) AudioSrv, BITS, Browser, CryptSvc, Dhcp, ERSvc, EventSystem, FastUserSwitchingCompatibility, helpsvc, lanmanserver, lanmanworkstation, Netman, Nla, RasMan, Schedule, seclogin, SENS, SharedAccess, ShellHWDection, srservice, TapiSrv, Themes, TrkWks, w32time, winmgmt, wscsvc, wuauserv
4.) Dnscache
5.) Alerter, LmHosts, RemoteRegistry, SSDPSSRV, WebClient
6.) stisvc
7.) HTTPFilter

 

by: Cosmo2bPosted on 2007-09-11 at 08:55:05ID: 19869734

Comparing the two tasklists:
"WZCSVC" is listed separately on the system that is working -and not under svchost.
There is an "Alerter" on the system that is working.
There is a "HTTPFilter" on a separate svchost on the system that is working.

Of course I don't know that there might be a corrupted or infested file within the normal names of what is listed either -but I have run some pretty heavy-duty anti-malware listed above and it's not finding anything.

 

by: Cosmo2bPosted on 2007-09-11 at 11:42:30ID: 19871101

I turned off the WZCSVC service using the commands listed above and a new service appeared called 6to4 -says that is is a helper to convert IPv6 to IPv4 or something -disabled that as well.

On next boot programs were able to open and I could bring up and IE window but not surf.  I could however ping all over the internet sucessfully.

I uninstalled the software for Intel Pro Wireless that came with this machine as one of the MSCONFIG startup items for Intel was WZCSVC  -I also uninstalled SDK for Windows.

On reboot I seem to be surfing just fine with a wired connection but I am unsure of what will happen when I reinstall the wireless adapter.

 

by: Cosmo2bPosted on 2007-09-11 at 18:44:38ID: 19873382

I was only able to surf to a couple pages before it locked up again using Local Area Connection.  But the system isn't locked up for all functions -just doesn't surf -until now the whole machine would lockup after the svchost message and I couldn't even click on anything.  

I can still ping google and others.

Kinda looks like I'm moving slowly in the right direction...  I can use any help you would like to give.

I'm not getting many hits on this question -is it too hard or did I post it in the wrong place?

Please help, I am just floundering though this -I am trying stuff because I am not getting many other ideas -I may be going in the wrong direction or I may be onto something but don't have the experience to carry it to completion/ a fix.

 

by: SheharyaarSaahilPosted on 2007-09-11 at 22:38:32ID: 19874080

im sorry for the late reply....got stuck in work yesterday.....

there is a program called Process Explorer which can tell you that which svchost process is calling which file
http://www.snapfiles.com/get/processexplorer.html

in that way, you can try finding out the one which is causing this issue, and then we can decide what to do with this particular service/file :)

 

by: Cosmo2bPosted on 2007-09-12 at 11:59:51ID: 19879001

OK -downloaded it but don't know how to use it -please give me tips

-I won't be able to try it out until the early AM -working night shift.

 

by: SheharyaarSaahilPosted on 2007-09-14 at 05:39:40ID: 19890852

check the properties of the processes and see which file(s) they are calling.....

 

by: Cosmo2bPosted on 2007-09-14 at 11:38:52ID: 19894027

it looks identical to the tasklist /svc as far as I can tell.  svchost is calling the same stuff.

 

by: Cosmo2bPosted on 2007-09-14 at 12:09:42ID: 19894316

Is there some way of printing a report or is there some things you would like me to type out to be of help? -to help you help me?  

Current status:  Machine is not locked up with no internet connection (not hard-wired right now, and wireless is uninstalled) and with the processes I turned off a few posts ago.

What should be the next few trouble-shooting steps?  -I can tell from Googling that if we fix this it will be a great find -looks like most people (that had a similar problem) gave up around here -it seems like we have enough information to do it but I don't  know exactly how.

 

by: Cosmo2bPosted on 2007-09-14 at 18:22:41ID: 19896087

Bueller...?  

 

by: rpggamergirlPosted on 2007-09-14 at 20:25:54ID: 19896348

I only quickly read the whole thread, if it isn't hardware/software/drivers issue then try others.

If you're desperate, it doesn't hurt to run malware diagnostic tools.

1.  Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
*  Instead of Windows loading as normal, a menu with options should appear;
*  Select the first option, to run Windows in Safe Mode, then press "Enter".
*  Choose your usual account.

*  Open the extracted folder and double click "RunThis.bat" to start the script.
*  Type "Y" to begin the script.
*  It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
*  Press any Key and it will restart the PC.
*  Your system will take longer that normal to restart as the fixtool will be running and removing files.
*  When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
*  Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back

 

2.  Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall



IF still no joy, scan for rootkits:
1.  Download (Download the GUI) version of BlackLight, and save it to your desktop.
https://europe.f-secure.com/blacklight/try.shtml
Doubleclick blbeta.exe, accept the agreement, click scan > next.

You'll see a list of all the items it found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (where xxxxxxx represents numbers). The application finds both bad files and legitimate ones such as "wbemtest.exe", so don't choose the rename option yet! Copy and paste the log it generated in your next reply.


2.  Rootkit Revealer:
http://www.sysinternals.com/files/rootkitrevealer.zip
Unzip it to it own folder or to your desktop.
Run RootkitRevealer.exe and scan your system. When the scan is complete click on File, Save, and save the log file. Post the log here.
In order to minimize RKR log being polluted with legit data run RootkitRevealer on an idle system.


3.  Download GMER from here:
http://www.gmer.net/gmer.zip

Unzip it and start GMER.exe
Click the rootkit-tab and click scan.

Once done, click the Copy button.
This will copy the results to clipboard.
Paste the results in your next reply.

If you're having problems with running GMER.exe, try it in safe mode.

 

by: Cosmo2bPosted on 2007-09-28 at 16:51:21ID: 19982483

Sorry, I checked several times and had no answer -I was really hoping to continue down the svchost processes path as SheharyaarSaahil had me download the process explorer thing -oh well guess he got busy or didn't want to close it.  It really felt like we were going in the right direction and we just had to zap the wrong process.

rpggamergirl, you have helped me in the past several times -I will try what you have posted tomorrow when I get home from work.  

 

by: Cosmo2bPosted on 2007-09-30 at 08:19:13ID: 19987176

Error msg for Svchost generic service no longer appears BUT SAME SYMPTOMS REMAIN
Cannot connect to internet via browser.   LOGS INCLUDED BELOW

 *sigh I can ping google.com but IE webpage won't come up.  

I still get a weird IPCONFIG result

Connection-Specific DNS suffix: hsd1.tn.comcast.net:
IP ADDRESS:  192.168.1.104
SUBNET MASK: 255.255.255.0
IP ADDRESS: ?
DEFAULT GATEWAY 192.168.1.1


Tunnel adapter
IP ADDRESS: ?

SDFix log:

***SDFix, Combofix and hijackthis logs removed by rpggamergirl, Zone Advisor***

 

by: Cosmo2bPosted on 2007-09-30 at 09:30:59ID: 19987312

Blacklight said it didn't find anything so it didn't print a log.

Rootkit Revealer seemed to get stuck after it got into the F drive (or at least after it scans the F drive it won't save to a file) which is the Vista installation -so I saved the part that will save and I will manually type in the other from what I saw on the Rootkit Revealer window.

I think that the entry that looks like HKLM\SECURITY\Policy\Secrets\SAC* looks suspect and I recall seeing this error first pop up once in late december -but I don't have experience looking at these logs so I will defer to those who know better.

HKU\.DEFAULT\Control Panel\International      9/30/2007 9:37 AM      0 bytes      Security mismatch.
HKU\.DEFAULT\Control Panel\International\Geo      9/30/2007 9:37 AM      0 bytes      Security mismatch.
HKU\S-1-5-21-842925246-861567501-839522115-1012\Control Panel\International      9/30/2007 9:37 AM      0 bytes      Security mismatch.
HKU\S-1-5-21-842925246-861567501-839522115-1012\Control Panel\International\Geo      9/30/2007 9:37 AM      0 bytes      Security mismatch.
HKU\S-1-5-18\Control Panel\International      9/30/2007 9:37 AM      0 bytes      Security mismatch.
HKU\S-1-5-18\Control Panel\International\Geo      9/30/2007 9:37 AM      0 bytes      Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC*      12/27/2006 3:20 PM      0 bytes      Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI*      12/27/2006 3:20 PM      0 bytes      Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SCM:{3D14228D-FBE1-11D0-995D-00C04FD919C1}*      1/3/2007 3:13 PM      0 bytes      Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\Installer\Products\32418F9EE1126B64A90E8365B85CFCF6\ProductName      2/2/2007 3:24 AM      58 bytes      Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\DisplayName      6/26/2007 11:49 AM      58 bytes      Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet002\Services\vax347s\Config\jdgg40      6/27/2007 11:02 PM      0 bytes      Hidden from Windows API.
******I am typing out the remainder maybe it didn't know how to represent a folder with no properties like the one below**********
No name folder (just an icon) No timestamp 0 bytes Hidden from API.
\$Repair:$Config       2/20/2007  3:52pm     8 bytes     Hidden from API.
\$Txf                          2/20/2007  3:52pm     0 bytes     Hidden from API.
\$Txflog                     2/20/2007  3:52pm     1MB          Hidden from API.
\$Txflog \$Tops:$T    2/20/2007  3:52pm      0bytes       Hidden from API.









 

by: Cosmo2bPosted on 2007-09-30 at 09:42:23ID: 19987331

gmer log:

  ***Gmer log removed by rpggamergirl, Zone Advisor***              
           
---- EOF - GMER 1.0.13 ----

 

by: rpggamergirlPosted on 2007-09-30 at 18:26:58ID: 19988505

>>I think that the entry that looks like HKLM\SECURITY\Policy\Secrets\SAC* looks suspect<<
the above key is part of the OS and is quite normal to show up in RKR log.

I had a quick looked in RKR log and don't find any suspicious or rootkits entries in the log(unless I missed something) anyone finds anything on the logfile before I remove it?


Do you recognize these files? likely came when you installed "Intel" app.
C:\WINDOWS\system32\AegisI5Installer.exe
C:\WINDOWS\system32\drivers\AegisP.sys
C:\WINDOWS\AegisP.sys


also know these?
C:\WINDOWS\SoftwareDist3
C:\WINDOWS\sdOld

 

by: Cosmo2bPosted on 2007-09-30 at 23:39:42ID: 19989082

The software distribution folder renames are my attempt to make sure updates wern't the problem with this issue.

I think you are right under the Aegis as Intel apps  -Again, I only have the problem when the Wireless is installed -though, even now, I can't surf even through the LAN connection.

 

by: Cosmo2bPosted on 2007-10-01 at 08:57:46ID: 19991585

What can we do next?

Also, any ideas on the weird ipconfig?
I still get a weird IPCONFIG result with the "?"

Ethernet adapter Wireless Network Connection 10:

Connection-Specific DNS suffix: hsd1.tn.comcast.net:
IP ADDRESS:  192.168.1.104
SUBNET MASK: 255.255.255.0
IP ADDRESS: ?
DEFAULT GATEWAY 192.168.1.1

 

by: Cosmo2bPosted on 2007-10-01 at 08:59:47ID: 19991602

I don't know if this makes any difference but when I turn on my wireless radio (from the button) I can get to one website before it starts getting "Page cannot be displayed" -I can get to any page -and it's not cached because it has current content -but the next address I try gets me nowhere.

 

by: Cosmo2bPosted on 2007-10-10 at 07:54:18ID: 20049027

What's next?

The Aegis was the intel Proset Wireless:
"Do you recognize these files? likely came when you installed "Intel" app.
C:\WINDOWS\system32\AegisI5Installer.exe
C:\WINDOWS\system32\drivers\AegisP.sys"

Just curious -Why was the GMER Log requested then removed?

 

by: Cosmo2bPosted on 2007-10-10 at 07:57:10ID: 20049059

Just posted the previous post -can an Advisor or moderator tell me if I have posted this question to the appropriate area and if there are others (I know I can choose 3) to post this to that might be better suited than the ones I chose?

 

by: Cosmo2bPosted on 2007-10-12 at 19:41:32ID: 20070045

I have followed each step and have posted logs and info requested -I am not seeing any posts -am I abandoned?

 

by: rpggamergirlPosted on 2007-11-20 at 04:58:02ID: 20319257

I am very sorry for failing to post back. I seem to have lost this one.
What's the update to your problem?

 

by: Cosmo2bPosted on 2007-12-07 at 20:18:58ID: 20432995

I deleted Zcfgsrv.exe and stopped the process I listed above WZCSVC and it works fine now.  Hope that helps someone else.  I backed everything up and thought I'd start deleting stuff because it wouldn't matter anymore.  I deleted those two first and it started working and I didn't need to dig any deeper.  

-Cosmo

 

by: Cosmo2bPosted on 2007-12-07 at 20:20:08ID: 20432998

-as per above -I fixed it -what is the method of closing this out now?  

-Hope that info helps the next unfortunate person that gets this freak lockup.

 

by: Cosmo2bPosted on 2007-12-08 at 11:02:25ID: 20434853

can we set it to 0 points or something but leave it as a reference in case someone else gets this problem?  I would like it there in case I get a similar issure or an intermediate svchost issue.  I spent sooooo much time on this.  Thanks!  

I will look over your links in the next couple days -I gotta get back to work.

 

by: rpggamergirlPosted on 2007-12-08 at 15:25:05ID: 20435490

Yes, "FAQed and refunding your points" in this case means this question will have 0 point and will be added to EE database of solutions, with your comment  {http:#20432995} as the Accepted answer.

 

by: Cosmo2bPosted on 2008-01-22 at 20:55:39ID: 20720913

I clicked on all the links in the administrative comment above so that I could learn how to make this a 0 point question that could retain my answer for anyone who needed it but all the links brough me to EE help page with billing answers..? -I hit Ctrl-F to find the words "answered my question myself" but they were not found.  -Can someone walk me through that process or give me a link that explains it?

Thanks, I would like to not leave questions open but don't know how to really close them or submit them for 0 point value answered.

 

by: rpggamergirlPosted on 2008-01-23 at 01:25:24ID: 20721923

It's okay, it's done. Next time, you just need to click on the "Delete Question" button in the lower part of the Title and it will automatically send a request for you to the Community Support, after you fill up the form and click Submit.


Question FAQed - and 500 pts refunded.


rpggamergirl
Zone Advisor

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...