Generic Host Process for win32 services

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by monita, Nov 26, 2010.

  1. monita

    monita Private E-2

    "Generic Host Process for win32 Services has encounter a problem and needs to close"
    When I close the message the computer locks.
    The computer had a virus "Thinkpoint" I ran all the programs on your list
    unfortunately I have not been able to run Combofix. When I click on Combofix, it starts running thru the procedure and gives me a message "Master boot record is infected, make sure your antivirus program is disable, I click on ok, it start running but freezes. I am also getting "Svchost.exe - application error - the instruction at "0x7c923845" referenced memory at "0x00000000" the memory could not be "read" click on OK to terminate the program. Please help me. To make things worst, I had downloaded all programs you recommend to "Documents settings" and ran the programs. When I re-read your instructions realize the mistake and uninstall Malwarebytes, CCleaner etc.by mistake and I don't have the reports to attached. I would appreciate your help.

    Thanks
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rename combofix.exe to magpie.com and and try again. If it fails you will need to boot into safe mode and try again.

    Next Run C:\MGTools.exe as per the instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    Attach the C:\Mglogs.zip
     
  3. monita

    monita Private E-2

    Thank you for your help. I tried again running combofix in safe mode but again did not work, then I tried running MGtools to no avail; the computer freezes even thought it looks like it is working; it did create the folder and I am attaching it. This is a windows XP, SP3

    Thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    MGTools did not run to completion. Did you recieve any error messages whilst running it? Try again and this time let it run through until you see "hit any key to continue" Attach the C:\MGlogs.zip.
     
  5. monita

    monita Private E-2

    after I doubleclick on MGtools, a black window showed up, (DOS) it found the OS XP then it said something else about running a scan, on the next line there was a note saying to ignore any messages regarding not finding the registry and then on the following line I got a blinking dash. The blinking dash remained there, no messages to answer, I left it on for over 3 hours and the blinking cursor (dash) remained on the screen, no action whatsoever. I restarter the computer in safe mode and tried again to run MGtools, I got the same window and same messages, left it on all night and the blinking dash still in the same position, what I did not check was if underneath that blinking dash was a message, it did not look like there was anything else after that.
    Please help.

    Thanks
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should run Malware Bytes and SUPERantispyware as per the instructions in the Read and Run Me First procedures. Attach the logs once done. Try again after running both of those to run MGTools.exe again. IF it does not work, then please do the below:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  7. monita

    monita Private E-2

    Thank you for your help and patience.
    Attached please find the 4 files. I am very hopeful now that I was able to run those programs. MGtools definitely didn't work.
    Looking forward to your instructions.
    Once again thank you
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :files
    C:\WINDOWS\tasks\At47.job
    C:\WINDOWS\tasks\At22.job
    C:\WINDOWS\tasks\At45.job
    C:\WINDOWS\tasks\At23.job
    C:\WINDOWS\tasks\At40.job
    C:\WINDOWS\tasks\At46.job
    C:\WINDOWS\System32\123.js
    C:\WINDOWS\tasks\At21.job
    C:\WINDOWS\tasks\At44.job
    C:\WINDOWS\tasks\At20.job
    C:\WINDOWS\tasks\At43.job
    C:\WINDOWS\tasks\At42.job
    C:\WINDOWS\tasks\At19.job
    C:\WINDOWS\tasks\At18.job
    C:\WINDOWS\tasks\At41.job
    C:\WINDOWS\tasks\At17.job
    C:\WINDOWS\tasks\At16.job
    C:\WINDOWS\tasks\At12.job
    C:\WINDOWS\tasks\At33.job
    C:\WINDOWS\tasks\At39.job
    C:\WINDOWS\tasks\At38.job
    C:\WINDOWS\tasks\At15.job
    C:\WINDOWS\tasks\At36.job
    C:\WINDOWS\tasks\At14.job
    C:\WINDOWS\tasks\At37.job
    C:\WINDOWS\tasks\At35.job
    C:\WINDOWS\tasks\At13.job
    C:\WINDOWS\tasks\At11.job
    C:\WINDOWS\tasks\At10.job
    C:\WINDOWS\tasks\At32.job
    C:\WINDOWS\System32\234.js
    C:\WINDOWS\tasks\At9.job
    C:\WINDOWS\tasks\At8.job
    C:\WINDOWS\tasks\At7.job
    C:\WINDOWS\tasks\At48.job
    C:\WINDOWS\tasks\At34.job
    C:\WINDOWS\tasks\At31.job
    C:\WINDOWS\tasks\At30.job
    C:\WINDOWS\tasks\At29.job
    C:\WINDOWS\tasks\At28.job
    C:\WINDOWS\tasks\At27.job
    C:\WINDOWS\tasks\At26.job
    C:\WINDOWS\tasks\At25.job
    C:\WINDOWS\tasks\At6.job
    C:\WINDOWS\tasks\At5.job
    C:\WINDOWS\tasks\At4.job
    C:\WINDOWS\tasks\At3.job
    C:\WINDOWS\tasks\At24.job
    C:\WINDOWS\tasks\At2.job
    C:\WINDOWS\tasks\At1.job
    C:\WINDOWS\System32\234.js
    C:\WINDOWS\tasks\At48.job
    C:\WINDOWS\tasks\At47.job
    C:\WINDOWS\tasks\At46.job
    C:\WINDOWS\tasks\At45.job
    C:\WINDOWS\tasks\At44.job
    C:\WINDOWS\tasks\At43.job
    C:\WINDOWS\tasks\At42.job
    C:\WINDOWS\tasks\At41.job
    C:\WINDOWS\tasks\At39.job
    C:\WINDOWS\tasks\At38.job
    C:\WINDOWS\tasks\At37.job
    C:\WINDOWS\tasks\At36.job
    C:\WINDOWS\tasks\At35.job
    C:\WINDOWS\tasks\At34.job
    C:\WINDOWS\tasks\At33.job
    C:\WINDOWS\tasks\At32.job
    C:\WINDOWS\tasks\At31.job
    C:\WINDOWS\tasks\At30.job
    C:\WINDOWS\tasks\At29.job
    C:\WINDOWS\tasks\At28.job
    C:\WINDOWS\tasks\At27.job
    C:\WINDOWS\tasks\At26.job
    C:\WINDOWS\tasks\At25.job
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run OTL again and attach its log.

    Describe to me at this point how things are running for you.
     
  9. monita

    monita Private E-2

    Dear Kestrel13,

    I apologize in advance, but I have a bit of a problem, when I try to run OTM as administrator is asking for password and frankly that most be the default because I never created an administrator account so I don't have a password. This is an IBM laptop and I check all the papers and books I have I don't find the password, can I run it any other way.

    Thanks
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm not heard of OTM requiring a password before...:confused

    Do this then instead:

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Answer my question about how thngs are running.
     
  11. monita

    monita Private E-2

    Dear Kestrel13
    things are running better, at least I am not getting "Generic host process" message today, however almost all the time, when I open internet explorer my main page changes to something else indicating "you are a winner", I always have to close that window in order to continue. Once again today I could'nt run the "MGtools/getlogs.bat, the same DOS window opens and after the NOTE regarding the registry I get the blinking dash which remains there, it doen't run and the computer freezes just like before. I tried both on regular mode and safe mode several times.
    Attached, please find Avenger.txt
    You have no idea how much I appreciate your help, you are my angel.
    Thanks for your help and patience.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Now run OTL again and attach the log.
     
  13. monita

    monita Private E-2

    Dear Kestrel13
    I just ran the TDSSkiller, please attached.
    Thank you
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now things should be running better for you! Correct?

    But you forgot to run OTL again, or forgot to attach its log. Do that now and I can have another sweep through to see if all looks good.
     
  15. monita

    monita Private E-2

    Dear Kestrel13
    I did forget to run it but I am attaching them now. I noticed that OTL.txt has today's date but the extras.txt did not change dates, I am attaching it anyway.

    Thanks a million
     

    Attached Files:

    • OTL.Txt
      File size:
      85.2 KB
      Views:
      2
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    LOgs look good. How's the PC behaving?
     
  17. monita

    monita Private E-2

    Dear Kestrel13

    The PC seems to be working fine! Is there anything else I need to do

    Thanks
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Nope, I think you're all set. :)
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. monita

    monita Private E-2

    Dear Kestrel13 and all Major Geeks Staff:

    I want to express my sincere thanks for your help and such a terrific job you are doing for the community. Your website is not just only user friendly, it is like having a close friend at your side explaining every step you are taking with precision and patience. Thank you Kestrel 13! God bless you.

    I just want to wish you all Happy Holidays.

    Thanks again,

    monita
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    On behalf of all of us you are *most* welcome! :) Happy Holidays to you too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds