Generic Host errors

Discussion in 'Malware Help (A Specialist Will Reply)' started by ShatteredFlame, Jan 9, 2011.

  1. ShatteredFlame

    ShatteredFlame Private E-2

    I have been getting that "Generic Host Process for Win32 Service, has encountered a problem and needs to close" error. Like others it has occasionally resulted in a crash in my browser but mostly it prevents any programs from using audio (ex: music/video players are silent but if I view..say a youtube video online, the sound is fine), my taskbar changes to some classic theme, and I also frequently get random popups when browsing that are usually trojan droppers.

    I use Windows XP (32bit). This problem has been going on for the whole week, I recently got rid of another virus that ran under "z.exe" (and something else I forgot), a few hours later this problem began occuring. I have tried the guide method a couple of times with no success. The problem doesn't appear on some runs but then just when I think I'm free, it comes back. My computer has been infected many times before and I have always been able to resolve the problem with the help of the guide on this site. But at one point about 2 years ago, I ran into the same problem, ignored it but then it eventually plagued my computer with an endless blue screen ensemble and the only thing I could do was system restore, deleting many important files. I really can't afford for that to happen again, please help!
     

    Attached Files:

  2. ShatteredFlame

    ShatteredFlame Private E-2

    *mglogs post*
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Note: At a minimum, you need to double the amount of memory in your PC to 1 GB. But 2 GB is highly preferred. You can no longer properly run Windows XP with 512 MB of memory.

    As stated in the READ & RUN ME, you are only supposed to run it once. You need to attach the 1st log from running SUPERAntiSpyware now.
    Code:
    "C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Jan 8 2011 16327 "SUPERAntiSpyware Scan Log - 01-08-2011 - 17-50-29.log"

    This is not saying much about your surfing habits!! And no wonder you have problems. You are not keeping your PC update nor is it protected properly. You are way behind in Windows Updates, you did not update SUPERAntiSpyware, you are extremely out of date with Malwarebytes, and you are 7 months out of date with MGtools.


    In addition you did not address the below as instructed in the READ & RUN ME.
    • You ran scans in safe mode and we need them run in normal boot mode unless that is not possible but you did not say it was not.
    • We asked you to uninstall old Sun Java versions in step 3 and then update. You have the below extremely outdated Java which is a security issue. Follow the instructions in step of the READ & RUN ME and uninstall this and update to the current version.
      Java 2 Runtime Environment, SE v1.4.2_03
    • Uninstall the below
      • Ask Toolbar <<< part of the list in step 5 of the READ ME
      • Viewpoint Media Player <<< specifically stated in step 3of the READ ME
    • Now run SUPERAntiSpyware and first Update it as requested. You should always update before scanning. Now run a new scan and attach a new log.
    • Now uninstall your very out of date version of Malwarebytes. Then download and install the version given in the READ & RUN ME form here >> Malwarebytes Anti-Malware Make sure that you UPDATE it while installing to so that you get all current database changes!!!! Then run a new scan, fix anything found, and attach a new log.
    • We will get MGtools updated later on in the below!!!
    Now try to do all of the below in normal boot mode, if you cannot run in normal boot mode then run in safe mode but make sure you explain this.


    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. ShatteredFlame

    ShatteredFlame Private E-2

    Alright, thanks for the help ;)!! I have since updated everything you told me too with the exception of increasing my ram, you have to buy more...correct? At first my PC had many booting errors trying to remove/update everything but once the SUPERAntiSpyware successfully updated, I had no problems. Not once did I get the Generic Host error, but I did get some google redirects while browsing.
     

    Attached Files:

  5. ShatteredFlame

    ShatteredFlame Private E-2

    *both SAS logs and TDSS Killer post*
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    TDSSkiller fix one issue related to this; however your MBRcheck log shows that the Master Boot Record (MBR) for two drives ( the C and G drives) on your system may be corrupted because it appears to be an Unknown MBR code. I see that the G drive is and external USB My Book drive which is almost full and may be what you use for backups. It appears to be infected too.

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.
     
  7. ShatteredFlame

    ShatteredFlame Private E-2

    No problems have been occurring since I did all that. The google redirects are gone, PC is running fine and that Generic Host error never comes up.

    I use my G drive solely for the extra HD space since the HD on my PC only has a capacity of 30GB. I don't have my stuff backed up at the moment(I'll get to it sometime) but what will I have to do to fix the problems?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have to repair the MBRs on your C drive and the G drive. Your MBR check log shows the below:
    Code:
          Size  Device Name          MBR Status
      --------------------------------------------
         37 GB  [URL="file://\\.\PhysicalDrive0"]\\.\PhysicalDrive0[/URL]   Unknown MBR code
                SHA1: E66C176942DF42CCFE7A0113EAFF39E82F8B0047
        465 GB  [URL="file://\\.\PhysicalDrive1"]\\.\PhysicalDrive1[/URL]   RE: Unknown MBR code
                SHA1: 2109F29445E77C0BCB56987F39830EB288D04575
    
    However these is always the chance that repairing the MBR can cause problems which is the reason for asking about the backup. And if you are using drive G for your backup, obviously repairing it could also make your backups of no use.

    MBR infections can open up back doors where personal information could be stolen.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds