Svchost error / no internet or task bar, etc...

Discussion in 'Malware Help (A Specialist Will Reply)' started by meganmmf, Aug 13, 2008.

  1. meganmmf

    meganmmf Private E-2

    Hi there-

    First, thank you so much for existing! You all helped me out the last time and I appreciate it so much!

    I will start by saying that I did as much as I could in the READ ME FIRST section, but many of my functions are disabled so I wasn't able to do much.
    The same goes for reading other posts related to my issue.

    So, here is my dilemma (I'm sure you have heard it all before):

    • I get the following message upon loading my computer:
      "Svchost.exe application error - The instruction at "0x008a01c0" referenced memory at "0x008a01c0". The memory could not be "written".

      Upon Clicking either OK or Cancel, it simply keeps popping back up (either the same number, or sometimes it changes the "0x00...." to a slightly different number.​
    • I have zero internet access (I usually connect with a cable modem).
    • My task bar has disappeared
    • "My computer" has disappeared from my desktop, though I can access it and other files by going through my recycle bin.
    • My "Search" function is disabled so I am unable to search files or programs on my computer
    • I have Ad-Aware 2007 (NOT SE) on my computer and it found Vx2 but was unable to remove it.
    • I also noticed that I have smanager.7.exe as a startup item.
    • I was unable to uninstall previous JAVA updates (I have several). In trying to remove them, my computer just froze and never came back.

      So, there you have it. I'm pretty stuck since so many of my functions are not working at this point. Just to let you know I do have a mac at home as well (which I am on right now) so I don't know if I can download any needed software on here, save it to disk and install onto my infected PC? Just wanted to let you know that.

      OK - I thank you in advance for any help you might be able to give me - and I understand you are all pretty swamped so I can be patient!

      Thanks-
      Megan
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to actually attempt running all steps in the READ & RUN ME. Especially the steps in the cleaning procedures for your version of Windows. Even if you have to try running things in safe boot mode. Without logs, we cannot do anything for you. At this point your problems could just as well be due to trouble with Windows. We have no way of knowing for sure without getting some logs. However smanager.7.exe is definitely malware and needs to be removed. The startup entry for it needs to be removed from the registry and the file must be deleted. I'm going to paste a typical boilerplate we give people on running the READ & RUN ME since some of the notes may be helpful to you.



     
  3. meganmmf

    meganmmf Private E-2

    OK - here goes:

    I was able to do some things, but not most. I will go down the list:

    1. I was NOT able to uninstall ANY programs. My Windows installer/unistaller in not functioning and always comes back with an error message.

    2. I Cleaned my hard drive w/ CC Cleaner (deleted files, fixed registry issues). But i was still unable to uninstall unwanted programs (I have a few outdated Javas)

    3. Removed unnecessary start-up items.

    4. I successfully used JK Defrag - which took 2.5 days to complete.

    5. I burned the XP cleaning tools onto a disk and try to install on computer.

    6. Was NOT able to install SuperAntispyware. It told me I had an older version and needed to uninstall that first. Upon attempting to do that, it gave me the usual uninstaller error. I then tried to use my older version of SuperAntiSpyware, but it never opened.

    7. Successfully installed Spybot. It found and removed:
    • Rootkit.Dayoff.Process
    • Virtumonde
    • Virtumonde.generic
    • Nonstech.UltimateFakeSecurityCenter

    8. Unable to use MalwareBytes - upon attempting to open it gave me the following error: "Run-time error '372': Failed to load control 'vbalGrid' from vbalgrid6.ocx. Your version of vbalgrid6.ocx may be outdated. Make sure you are using the version of the control that was provided with your application."

    9. ComboFix: Ran but gave me the following: "The Batch file cannot be found."

    10. MGTools: Gave me the following error (which was not listed in your post) : "Failure to ensure dir exists: /MGTools"

    SO unfortunatley, all of the programs that you needed logs from did not run.

    HOWEVER: I do have HIJACK THIS on my computer and could get you that log if that would be helpful.

    I hope I did not miss any steps - I really tried to make sure I followed everything exactly.

    Thanks for your help....

    Megan
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you have a combination of problems. Some malware and some are issues within your Windows operating system.

    Hopefully it is the correct version. Before running a scan, rename the HijackThis.exe file to analyze.exe. Then run the scan and save a log. Attach the log here. While this is not going to help us find all of your problems, perhaps it will let us get started.
     
  5. meganmmf

    meganmmf Private E-2

    Hi there-

    Well, you were right (of course) about it being a combination of problems. After trying a bunch of things, I ended up having to run a repair install of windows because my system was just not functioning. Luckily it worked! I am back online and things seem to be working fairly smoothly. I was able to run those scans and get the logs - and if you don't mind I will attach them for your review just to make sure I am as clean as can be....

    A couple strange things:
    ~I have 3 "Internet Options" icons in my control panel and I am not able to get rid of them.
    ~I seem to have lost my IE upon re-installation.

    Anyhow - I am in much better shape, but again, I will attach my logs.

    Thanks again for all your help.

    Megan
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And you still have some more problems with your OS. ;) The MGtools scans were incomplete due to these problems. You may be getting one or more of the errors mentioned on the Using MGtools download page. You should do the below to check.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.


    Post these problems in the Software Forum.


    Did you really want to disable the below BHOs? It is not recommended that you disable these?
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (disabled by BHODemon)
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll (disabled by BHODemon)
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (disabled by BHODemon)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds