Help- system32 error

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mocca4, Dec 3, 2006.

  1. Mocca4

    Mocca4 Private E-2

    Hi
    I have been having problems with my computer and the internet which i think is due to a virus.
    Although my motorola cable modem is all lit up and the computer says its connected i still get page cannot be displayed.

    I think its a virus because my Antivirus/spyware (panda Titanium 2006) comes up with the message
    unknown virus blocked c:/windows/SYSTEM32/SVHOST.exe

    Also on start up i get the error saying problem with service32. exe has expreinced problems and had to close

    I have run the instructed programs in safemode
    CCleaner
    CounterSpy (results attached)
    (i could not run spyBot cos i can update it and thus it would let me go on)
    Plus no internet means i havent been able to use the online scans reccommened.

    I also before hand ran Tauscan but that found nothing.
    Rang the service provider and everything it ok at their end...which i already thought as i am using the same connection on my laptop enabling me to post this.

    Also when i go to network connections and hit the repair button it says:
    cannot be fixed..problems with IP address, how ever at other times it works although still no internet
    The internet will work for a few mintues after i unplug the modem but after that i get the same page error

    Generally the computer freizes alot now too

    I ran Hijack this (attached)
    I had to uninstall panda cos it was blocking Hijack

    I have tried to follow the instructions before posting so hopefully i done them correctly, iv tried to give you as much info about the problem, and a appericate all you help
    thanks
    Mocca4
     

    Attached Files:

  2. Mocca4

    Mocca4 Private E-2

    oops I didnt put the O in in the error message
    so panda comes up with
    c:/windows/system32/SVOHOST.EXE
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    If Microsoft AntiSpyware is still installed, uninstall it. I see it in your HJT log. It is not supported anymore.

    Please attach logs from GetRunKey and ShowNew as requested. You should be able to get these on the computer the same way you got CounterSpy and HJT.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Windows Accounts Driver Extensions
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • Netsrv Work Services
      • ERSever
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste Windows Accounts Driver Extensions into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • Netsrv Work Services
      • ERSever
    • Now exit HJT and reboot when it tells you it needs to.

    After reboot attach a new HJT log.
     
  4. Mocca4

    Mocca4 Private E-2

    Hi
    Thanks for you reply
    i did everything you said- heres some info
    After disabling ERsever the computer restarted itself
    Netsrv wasnt started so i just disabled it

    In hijackthis message said couldnt find Windows accounts driver extenisions or ER server but it deleted Netsrv

    Resqusted logs attached

    Thanks again for your help
    Mocca
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall this: Viewpoint Media Player (Remove Only)

    Continue by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\SVOHOST.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SoundMam] C:\WINDOWS\system32\SVOHOST.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\service32.exe
    C:\WINDOWS\system32\SVOHOST.exe
    C:\WINDOWS\234117176113.exe
    C:\WINDOWS\23916796175.exe
    C:\WINDOWS\Down(1).exe
    C:\WINDOWS\system32\dskernel.exe
    C:\WINDOWS\system32\dvtgsd.exe
    C:\WINDOWS\system32\zt.exe
    C:\WINDOWS\spoolsv32.dll
    C:\WINDOWS\sys32exploer.dll
    C:\WINDOWS\system32\dvtgsd.dll
    C:\WINDOWS\system32\winscok.dll
    C:\WINDOWS\system32\ztdll.dll
    C:\WINDOWS\system32\QQhx.dat
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Toscano\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. Mocca4

    Mocca4 Private E-2

    Hi
    I did all steps with no troubles

    In Deleting Temp folders in C:\Documents and Settings\Toscano\Local Settings\Temp, windows wouldn't allow me to delete the folder hsperfdata_Toscano with had a file named 768 in it which was made yesterday
    also i noticed these files in C:\Documents and Settings\Toscano\Local Settings\Temp:
    vmpremov from viewpoint Media player which came up after i deleted viewpoint
    and the text document called jusched which says in it the following
    Mon Dec 04 11:42:17 2006
    :: nextSched=Thu Dec 14 08:00:00 2006
    ; sleeptime (sec=850663, hours=236), actual sleep=852172000 msecs

    Mon Dec 04 11:42:17 2006
    :: lastSchedTime= Tue Nov 14 08:00:00 2006
    ;

    i deleted them but for now kept them in recycle in case

    Other then that everything went fine
    My computer is running better and so far iv been on the net for 20 mintues with no connection errors and i dont think i got the service error on start up

    new logs attached
    Many Thanks again
    Mocca
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have no problems connecting now then it would be in your best interest to go back and run the two online scanners (BitDefender and PandaActiveScan) now to make sure there is nothing else hiding.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like Viewpoint Media Player came back. Run this: ViewpointKiller

    Also Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    J2SE Runtime Environment 5.0 Update 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment
     
  9. Mocca4

    Mocca4 Private E-2

    Hi
    I ran Panda and bitdefender, they found a few baddies
    results attached

    Viewpoint killer said it didnt find any of the files to do with viewpoint media player

    and iv installed new java

    heres the lastest hijack log
    Everythings working great though....still connected to the net and no error messages of anykind.
    Thanks
    Mocca
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And that is exactly why I said you should run them. ;)

    Run Pocket Killbox and select File, Cleanup, Delete All Backups
    Use Killbox to delete the below files

    C:\WINDOWS\system32\svchosta.exe
    C:\WINDOWS\system32\wsystem.dll
    C:\WINDOWS\system32\wsystem.exe

    Delete the below folders
    C:\WINDOWS\vip
    C:\Program Files\Microsoft AntiSpyware

    What are you storing in the C:\mocca folder?
    Do you know what Cliprexdsfree.exe is for?


    Viewpoint killer said it didnt find any of the files to do with viewpoint media player

    and iv installed new java

    heres the lastest hijack log
    Everythings working great though....still connected to the net and no error messages of anykind.
    Thanks
    Mocca[/quote]
     
  11. Mocca4

    Mocca4 Private E-2

    Hey...
    Killbot comes up with

    C:\WINDOWS\system32\svchosta.exe = file does not exist
    C:\WINDOWS\system32\wsystem.dll = could not be deleted
    C:\WINDOWS\system32\wsystem.= could not be deleted

    the other two deleted fine

    C:\Mocca folder has a lot of radom stuff in it like songs, photos and downloads
    I dont know what Cliprexdsfree.exe is for, it uses a setup icon....
    i think it would be fine to delete
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please put both C:\WINDOWS\system32\wsystem.dll and C:\WINDOWS\system32\wsystem.exe into a ZIP file and attach it to your next message. I'm wondering if these possibly belong to a program that you run.

    Look to make sure that C:\WINDOWS\system32\svchosta.exe does not exist because Panda did show it.
     
  13. Mocca4

    Mocca4 Private E-2

    Hi
    Ok done winzip

    C:\WINDOWS\system32\svchosta.exe IS still there

    Thanks
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those two files are definitely infect with the below:
    Try booting into safe mode and use Pocket Killbox to delete the below three files.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINDOWS\system32\svchosta.exe
    C:\WINDOWS\system32\wsystem.dll
    C:\WINDOWS\system32\wsystem.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    If that does not work, then while in safe mode see if you can right click on the filenames (one at a time) and select Rename. Rename them as shown below:
    C:\WINDOWS\system32\svchosta.exe ===> svchosta.xxx
    C:\WINDOWS\system32\wsystem.dll ===> wsystem.ddd
    C:\WINDOWS\system32\wsystem.exe ===> wsystem.xxx

    Let me know the results.
     
  15. Mocca4

    Mocca4 Private E-2

    Hi
    yep your instructions worked wiht the first step

    C:\WINDOWS\system32\svchosta.exe
    C:\WINDOWS\system32\wsystem.dll
    C:\WINDOWS\system32\wsystem.exe
    are all gone

    I ran another Panda scan and there were no virus'

    Iv attached latest HJ log
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now the hidden service finally shows:

    O23 - Service: Windows System (WSystem) - Unknown owner - C:\WINDOWS\system32\wsystem.exe (file missing)

    Let's fix this!

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Windows System
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteWSystem into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.
    After reboot attach a new HJT log so we can be sure the O23 service line is gone.
     
  17. Mocca4

    Mocca4 Private E-2

    ok Done
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  19. Mocca4

    Mocca4 Private E-2

    Hey
    Iv done the system restore step
    everything is working great
    Thankyou so much for all you help i really appreciate it
    Its great that theres people out there willing to help
    Thanks again
    Mocca
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds