Generic Host....

G

Guest

Process for Win 32 encountered a problem and needed to close.

Error signature
$zAppName:svchost.exe
$zAppVer:0.0.0.0
$zModName:unknown
$zModVer:0.0.0.0
Offset:00000000

C:\DOCUME~1\xx5952~1.xxx\LOCALS~1\Temp\WERe637.dir00\svchost.exe.mdmp
C:\DOCUNE~1\xx5952~1.xxx\LOCALS~1\Temp\WERe637.dir00\appcompat.txt

the xxx would be my initials.
Windows XP Home SP2

Can some on please tell me what this is and help me with it?
 
D

David H. Lipman

| Process for Win 32 encountered a problem and needed to close.
|
| Error signature
| $zAppName:svchost.exe
| $zAppVer:0.0.0.0
| $zModName:unknown
| $zModVer:0.0.0.0
| Offset:00000000
|
| C:\DOCUME~1\xx5952~1.xxx\LOCALS~1\Temp\WERe637.dir00\svchost.exe.mdmp
| C:\DOCUNE~1\xx5952~1.xxx\LOCALS~1\Temp\WERe637.dir00\appcompat.txt
|
| the xxx would be my initials.
| Windows XP Home SP2
|
| Can some on please tell me what this is and help me with it?



Dump the contents of the IE Temporary Internet Folder cache (TIF)

start --> settings --> control panel --> internet options --> delete files

1) Download the following four items...

McAfee Stinger
http://vil.nai.com/vil/stinger/

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp

Ad-aware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt448.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM .

2) Update Ad-aware with the latest definitions.
3) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode [F8 key during boot]
and shutdown as many applications as possible.
5) Using Trend Sysclean, Stinger and Ad-aware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using the three
utilities; Trend Sysclean, Stinger and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point


* * * Please report your results ! * * *
 
G

Guest

Hi,

You need to provide more details about the error message. When do you get
the error message ? How frequent is it ?
You can try this...boot the computer in safe mode while restarting it, by
hitting the f8 key. At the advanced options menu please select safe mode and
hit enter. When the computer boots in safe mode, then check for the error
message. If you dont get the error then follow this knowledge base article.

http://support.microsoft.com/default.aspx?scid=kb;en-us;310353
 
G

Guest

Hi Yusha,
this happened after I looged in,with desktop up and running.
(Read on next posts)Thank you.
 
G

Guest

Hi David,
well here goes. I turned off Restore Point and went into safe mode.
(Via msconfig)
All my security is updated anyway,so I started with the
Ad-Aware=OK
Spybot S&D13=OK
CWShredder=OK
AVG=nothing
Then I ran the stinger,well some where in the middle of the scan this popup
shows up with "Virus detected" and my hand was quicker then my brain,
and clicked the "heal" button. But here is what I think it was,and it is
listed under
the Stingers Viruses.."Exploit-MS04-011"
So having healed it, I ran the Stinger again and it came up clean.
Just for good measure I ran it again ,with "Bootsector" under prefs.
enabled,and it came out clean again.
So now it remains to be seen what happens at my next logons.
With any luck I found the culprit and all is well.
Thank you for all your help.

David H. Lipman said:
| Process for Win 32 encountered a problem and needed to close.
|
| Error signature
| $zAppName:svchost.exe
| $zAppVer:0.0.0.0
| $zModName:unknown
| $zModVer:0.0.0.0
| Offset:00000000
|
| C:\DOCUME~1\xx5952~1.xxx\LOCALS~1\Temp\WERe637.dir00\svchost.exe.mdmp
| C:\DOCUNE~1\xx5952~1.xxx\LOCALS~1\Temp\WERe637.dir00\appcompat.txt
|
| the xxx would be my initials.
| Windows XP Home SP2
|
| Can some on please tell me what this is and help me with it?



Dump the contents of the IE Temporary Internet Folder cache (TIF)

start --> settings --> control panel --> internet options --> delete files

1) Download the following four items...

McAfee Stinger
http://vil.nai.com/vil/stinger/

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp

Ad-aware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt448.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM .

2) Update Ad-aware with the latest definitions.
3) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode [F8 key during boot]
and shutdown as many applications as possible.
5) Using Trend Sysclean, Stinger and Ad-aware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using the three
utilities; Trend Sysclean, Stinger and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point


* * * Please report your results ! * * *
 
G

Guest

I wanted to ask you one more thing about the Restore Point.
Mine was at the max,which I brought down to your suggested
400-600mb,which is the minimum....Why then is the default so high,
when , I assume it's not needed ?
Thanks for all your help.
 
D

David H. Lipman

| I wanted to ask you one more thing about the Restore Point.
| Mine was at the max,which I brought down to your suggested
| 400-600mb,which is the minimum....Why then is the default so high,
| when , I assume it's not needed ?
| Thanks for all your help.


First I noticed that you didn't run Trend Sysclean.

Stinger only Targets ~50 infectors (mostly Internet worms) and their respective variants.
Trend Sysclean is a broad-spectrum virus, worm and Trojan removal tool. Please run it as
well.

As for the System Restore, it uses a percentage of the hard disk space so as the hard disk
gets bigger, so does the System Restore Cache. And the cache is HIGHLY desirable so do
think it it is not needed.
 
G

Guest

Downloading the trend items as I write,will run them in safe mode
and report.
As far as the System Restore space goes,I think I put it back to max,
since I have 88% free space on my disk...
Thank you David.
 
G

Guest

Yikes-yikes,you knew this didn't you.
It almost took an hour for this trendmicro to run through.
There was a bunch of files that said "access denied",
not sure how to handle that,but the rest came out clean.
My heart dropped when I saw all those files running by me,
and just about all of them had <<error 94>>> at the end.
I suppose a log is saved,if it needs to be looked at.

It does seem to log off faster then it did before.

Now if I need to update this trendmicro,I suppose I have to
look for it on their site ? Because I didn't see anywhere ,
 
D

David H. Lipman

| Yikes-yikes,you knew this didn't you.
| It almost took an hour for this trendmicro to run through.
| There was a bunch of files that said "access denied",
| not sure how to handle that,but the rest came out clean.
| My heart dropped when I saw all those files running by me,
| and just about all of them had <<error 94>>> at the end.
| I suppose a log is saved,if it needs to be looked at.
|
| It does seem to log off faster then it did before.
|
| Now if I need to update this trendmicro,I suppose I have to
| look for it on their site ? Because I didn't see anywhere ,
| on the item it self,an update button.


No it is a manual process and if you want to use it again, you have to go to Trend and
download both parts as they are both updated by Trend.

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top