Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Virus/Malware What's wrong with this error?, Generic Host Process for Win 32

views
     
TSApoKalypse
post Oct 31 2008, 11:03 PM, updated 18y ago

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



user posted image

When I got this error, I cannot reconnect internet again... why? sad.gif

This post has been edited by ApoKalypse: Nov 3 2008, 08:10 PM
TSApoKalypse
post Oct 31 2008, 11:16 PM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



here is my HJT log...

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:16:14 PM - AmZ, on 10/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Download All Links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{59B5E40F-5DEF-436A-8531-46B2EE7D5F36}: NameServer = 202.188.0.133 202.188.1.5
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 5740 bytes
TSApoKalypse
post Nov 1 2008, 09:20 AM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



QUOTE(Hattori @ Nov 1 2008, 12:10 AM)
Are you still using WinXP Service Pack 1 or 2?

Solution in post #76 by sUBs :

http://forum.lowyat.net/topic/326260/+60

Otherwise update to Service Pack 3.
*
yeah Im still using Service Pack 2, why?
TSApoKalypse
post Nov 2 2008, 08:51 AM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



QUOTE(Hattori @ Nov 1 2008, 05:06 PM)
Your PC is being attacked from the Internet causing the netapi32.dll to overload and crash.

To solved the problem install the updated netapi32.dll :

http://www.microsoft.com/downloads/details...1a-46b3eac7a305
*
what is netapi32.dll ? can u explain? is that a virus?
TSApoKalypse
post Nov 3 2008, 04:28 PM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



i have install all file from the top posted but i still have the problem. how to fix it? sad.gif
TSApoKalypse
post Nov 3 2008, 07:48 PM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



update service pack 3? hurm that mean i must format my pc rite?

when i try to open the software (wwdc) i got this notice,

user posted image

This post has been edited by ApoKalypse: Nov 4 2008, 09:39 AM
TSApoKalypse
post Nov 4 2008, 09:44 AM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



anybody can help me? sad.gif
TSApoKalypse
post Nov 4 2008, 12:44 PM

Enthusiast
*****
Senior Member
830 posts

Joined: May 2007
From: Melaka, MALAYSIA



QUOTE(francischuahcw @ Nov 4 2008, 11:21 AM)
Good day,
Lets do the below.

Look at your Event Viewer in Administrator Tool under Control Panel
In your CP, switch it to classic view then you will see Administrator Tool

Launched the Administrator Tool and you shall see it.
In Event Viewer look at both System Log and Application Log.
You can save a copy of your log and upload it here.
Use the Action toolbar and choose Save Log As
Then, save the log as .txt file and upload it here.

Next,

Look at Dr. Watson Debugger log.
Please search for the log file at the below location (if present)

C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp

In your next reply, please post:

  • Event Viewer log (System and Application)
  • Dr.Watson Debugger log
Thanks
*
here is Apps log and system log.. http://www.mediafire.com/?jnnf5uqjeao

dr watson log is around 83MB, so big to upload with my poor internet connection sad.gif

QUOTE(Hattori @ Nov 4 2008, 11:49 AM)
Alright everyone, I have some update on this problem :

This problem is similiar to the problem & solution posted by sUBs 2 years ago in post #76 of this topic :

http://forum.lowyat.net/topic/326260

The Microsoft article :

http://www.microsoft.com/technet/security/...n/MS06-040.mspx

All freshly installed WinXP with SP2 will still face this problem unless you install the updated patch.

Your PC that are connected directly to the modem & using Window's PPPOE dailer, or PCs that are behind a router but was set as the DMZ PC would be hit by this problem.


As of 23 October 2008, Microsoft has released a new update to solve this new attack that affect even fresh installed WinXP with Service Pack 3 and Vista with Service Pack 1.

http://www.microsoft.com/technet/security/...n/MS08-067.mspx
Install this update for 32-bit WinXP SP2/SP3 users :

http://www.microsoft.com/downloads/details...76-2067B73D6A03

Install this update for 32-bit Vista users :

http://www.microsoft.com/downloads/details...5C-CAC7D8713B21
For other Windows version please, select the appropriate version from

http://www.microsoft.com/technet/security/...n/MS08-067.mspx
If you are interested in the technical details of this problem:

http://blogs.technet.com/swi/archive/2008/...t-MS08-067.aspx
*
okay i'll try n post the result here...

 

Change to:
| Lo-Fi Version
0.0148sec    0.76    6 queries    GZIP Disabled
Time is now: 10th December 2025 - 04:36 PM