This thread's last reply is from April 5, 2012, 11:31 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
I have a second machine--ThinkPad T40 with XP sp3. Recently, I received the following (together with an array of problems):
"Faulting application svchost.exe, version 5.1.2600.5512, faulting module wzcsvc.dll, version 5.1.2600.5512, fault address 0x0002d3ae."
This is from event viewer following from a "Generic Host Process for Win 32 ...." closure message.
I can't be sure what caused this, as the machine, although little used, worked fine (mobile communicator--e-mails, Skype etc) when away from home. Connection to internet was via onboard wireless modem in hotel.
Now I am using it at home and connect to internet via onboard usb network adaptor via cable to an ADSL modem--two other computers work fine when using this connection.
Unless there is something else obvious to the technical dept, this 'connection platform' change is all I can think of.
Help would be appreciated.
Hi orepsam,
This could be a configuration problem or something else. ----------------------------------------------------------- Check/Alter status of Wireless Zero Configuration
Go to Start, Run and type services.msc
into the box, and hit <Enter>
Scroll down to the entry named Wireless Zero Configuration
Right click it and choose Properties
Under the General tab, if the Status is not Started, then click Start.
Under Startup Type, Automatic should be selected.
Click Apply and OK. ----------------------------------------------------------- Check Hard Disk For Errors
Press Start->Run, then type or copy/paste the following command into the box and press OK:
A blank command window will open on your desktop, then close in a few minutes. This is normal.
A file and icon named checkhd.txt should appear on your Desktop. Please post the contents of this file.
Thanks askey
I will try wireless and usb when I go home tonight.
I tried to shorten this post, here is my original. As you see already chkdisk and all OK:
"General
I'm not sure quite what started this Generic Host… message "GHP".
I'm in the process of putting some programmes on the machine from original software. Our ageing laptop (ThinkPad T40) as opposed to our desktop is destined to be our mobile communicator, when we 4 X 4 or 'swallow' between here and Europe.
The T40 is loaded with XP pro SP3 while the desktop has the home edition. I have a Toshiba Satellite (even older—and quite slow) on which I have successfully loaded the required programmes, and it performs (apart from speed) the way I expect the T40 to work. The desktop also has the programmes and everything works fine there. All systems have adequate memory and disk space for their intended use.
The T40 system used to be stable—basically used by my wife as a simple communicator—remote internet e-mail, Skype and occasionally Word for attaching to e-mail. The connection was via a wireless modem (on board) offered by our hotel.
I now 'connect' via a USB ADSL network adaptor (built in), the Mweb supplied modem "Billion?" allows for a faster cable connection (fast wire?), which has an outlet plug that is different to the normal USB one—I use this output on my desktop, as the laptops are not equipped with a compatible port.
I have done my best to recover the issue, including several attempts to restore until hard drive had no more space—+-2%. I disabled auto restore which recovered > 60% of the space; a chk disc and defrag followed, and everything looked great but still the GHP returned.
Internet sites know about the problem, but no meaningful solution is offered, even by MS.
Symptoms
1. A few, up to 15 mins after bootup I get the GHP; the event viewer indicates a problem with svchost.exe—see the screen-prints below.
2. If I choose the 'send the error report' option it goes off, but the machine then becomes inoperable (not frozen completely), but it won't respond to a Ctr/Alt/Delete, other than to show the first popup. However Task manager does not come up but if logoff is selected it responds, plays the shutdown music but does not shut down—this has to be done manually.
It reboots normally, but the onboard ADSL network adaptor becomes disabled and requires the driver to be installed—either through device manager, or the Found New Hardware Wizard.
3. If, on the other hand, I elect Debug, the machine lives on more or less normal but sound card deactivates yet device manager does not show a problem. Also, if you remove something from USB e.g. internet connection or flash drive, it won't accept it back, nor recognise a new addition. The machine slows down quite a bit.
The machine does however permit my GPS to be removed and plugged in, and the map software recognises it immediately but does not notify 'found new hardware'. Not being a typical storage device, it does not show on Explorer.
4. On normal shutdown, it reboots back to 'normal' and the problem of the ADSL mentioned in 2 & 3 does not recur until GHP arrives, which is inevitable.
5. Skype 5.1 is resident, but won't upgrade from the Help "check for later versions",
nor from a downloaded setup file—while running it gives "problems connecting to server" however there was still a connection. I had similar hiccoughs with my desktop that cleared fairly soon and 5.1.8 was eventually installed from a downloaded setup..
6. CC cleaner is regularly used—the anti-virus is Eset NOD (old version).
orepsam,
All that stuff is just garbage sentences, probably created by a computer.
Please let me have a look at the contents of checkhd.txt
By the way, you can pick up anything, including malicious properties, from other users via a hotel wireless. To use any public wireless, the wireless function in a laptop should only be turned on for the brief period of direct communication, then turned off again. Otherwise the laptop and its contents are open to others for reading or writing..
Now I want to check for a rootkit.
Please remove any GPS plug-ins first. -------------------------------------------- TDSSKiller - Rootkit Removal Tool
Please download the TDSSKiller.exe by Kaspersky... save it to your Desktop. <-Important!!!
Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
(Vista - W7 users: Right-click and select "Run As Administrator")
If TDSSKiller does not run... rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com).
If you don't see file extensions, please see: How to change the file extension.
If you try to change the filename and extension, you may get a warning message from Windows because of the change of file extension. OK the change.
Click the Start Scan button. Do not use the computer during the scan!
If the scan completes with nothing found, click Close to exit.
If malicious objects are found, they will show in the "Scan results - Select action for found objects" and offer 3 options.
Ensure Cure (default) is selected... then click Continue > Reboot now to finish the cleaning process.
If Cure is not offered as an option, choose Skip.
A log file named TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt will be created and saved to the main directory of C:
(the dd.mm.yyyy_hh.mm.ss numbers in the filename represent the time/date stamp)
Copy and paste the contents of that file in your next reply.
If, for some reason,you can't locate the text file to paste into your reply, just tell me, but DO NOT run the program a second time.
askey127
Well Askey 123!
Things 'progressed'. Before receiving your latest, I interacted with MS Answers on the same topic.
The advice was "Clean Boot" and then restore to normal boot. To cut a long story short--the GHP went away, but so did a host of other stuff; the computer is working--just--but isolated. No more "Device Manager" or "Add new hardware" , network card not found, but usb recognises wireless mouse. So really a bit of a mess for me (my last week before going on pension) to sort out.
I do appreciate your help, and will try to figure out how to get the virus programme onto the machine. I'll also run the chkdsk thingy for you in the next few days.
If the way forward is now obvious to you, please break the news gently!
Cheers
orepsam,
When you work with more than one advisor, neither of them can properly keep track of what's going on.
So you don't need to do anything I previously asked, but please don't install, uninstall, or scan with anything unless I ask, until we are done. --------------------------------------------- Download the OTL Scanner
Please download OTL.exe by OldTimer and save it to your desktop. --------------------------------------------- Run a Scan with OTL
Double click on the OTL icon to run it.
Check the boxes labeled :
Scan All Users
LOP check
Purity check
Extra Registry > Use SafeList
Make sure all other windows are closed to let it run uninterrupted.
Click on the Run Scan button at the top left hand corner. Do not change any settings unless otherwise told to do so.
When the scan starts, OTL may appear to be frozen while it runs. Please be patient.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. (desktop)
The Extras.txt file will only appear as a running Notepad document the very first time you run OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them as a reply. Use separate replies if more convenient.
Hi Askey 127
Managed to download OTL to a flash drive via desktop; pleased to find that the laptop read the drive as well.
However, the 'fun' continues--on executing OTL, I get a message to the effect "OTL experienced a problem and has to close" The error report looked like this file--not sure how to attach.
"The following information about your process will be reported:
Exception information
Code: 0x0eedfade Flags: 0x00000001
Record: 0x0000000000000000 Address: 0x000000007c812afb
System Information
Windows NT 5.1 Build: 2600
CPU Vendor Code: ....etc
CPU version: ...etc
CPU and feature code: 00E5E820
Module 1
OTL.exe
Image base ...etc
Check sum ...etc
etc etc
The following files will be included in this report.
C:Documents/Jen/Locals~1/Temp/64e_appcompat.txt"
I suppose I should have opened that last file, but didn't and I'm at work for this week during the day.
You're probably going to be mad at me once more--Askey.
Senior moment again. I forgot to mention: As part of the MSAnswers 'boot fix', I was told to run Microsoft security Essentials.
It highlighted a medium threat and claimed to have fixed it, so I thought nothing more of it.
I've done some more reading, but NO, I haven't done any more fiddling as advised by you!
I'm beginning to suspect that it didn't fix it. It is HACKTOOL:WIN32/KEYGEN/... .
My software is all legal. (Ironically the other laptop, which is working fine (but slow) does have one or two 'dodgy' programmes, but no Hacktool as of yet.)
I'm obviously concerned that the Trojan may migrate there as well.
How do I protect it, apart from isolation or quarantine?
Cheers again.
ALL the "dodgy" programs should be assumed to transmit infections.
You should post Logs from the other machine online and get it fixed, or you will end up having to Reformat and Re-Install Windows on both of them.
------------------------------------------------ Download and Run Rkill before Running OTL
You can download a few versions of these to your flash and transfer one at a time until one appears to work.
If a black DOS box briefly flashes and disappears, it indicates the tool ran successfully.
You only need to get one to run, then try OTL again.
Please download and run the tool named Rkill, which may help in allowing other programs to run.
There are different versions with different names. If one of them won't run ,then download and try to run one of the other ones.
After the download, Vista and Win7 users will need to right click the icon and choose Run as Administrator. XP Users can just double-click.
You only need to get ONE of these to run, not all of them. You may get warnings from your antivirus about any of these tools. Either ignore the warnings or shutdown your antivirus.
Please download Rkill from one of the following links (note the different names) and save to your Desktop:
iExplore.exe
Rkill.exe
eXplorer.exe
RKill.com
RKill.scr
Rkill.pif
uSeRiNiT.exe
Double-click on the iExplore, Rkill, eXplorer, or uSeRiNiT desktop icon to run the tool.(If using Vista or Windows 7 right-click on it and choose Run As Administrator).
A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
If you get a Warning Message when you try to run it, run it again while the Warning Message is still displayed.
If it doesn't run on the first try, please try to run it another two or three times.
If it still does not run, delete the desktop entry. Then download and use the one provided in the next link.
If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
Do not reboot until instructed.
If the tool does not run from any of the links provided after trying each a few times, please let me know.
Perhaps the last chapter Askey?
I ran the first one RKill and received this, after dos screen etc.:
"This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 2012/03/27 at 20:12:19.
Operating System: Microsoft Windows XP
Processes terminated by Rkill or while it was running:
Rkill completed on 2012/03/27 at 20:12:29."
I thought it may have worked, but OTL still couldn't open.
I ran all the others with the same result, just slightly different text log.
I couldn't get RKill.pif to download.
It seems as though executing 'non-MSoft' exe files doesn't work. By contrast the preloaded Word, Excel etc seem unaffected.
Thanks again
There is no question that you have a malware infection on this machine.
Please try to run TDSSKiller per the previous instructions.
Download it to a flash drive from a clean machine if necessary in order to transfer(copy) it to the desktop of this one.
When you follow instructions here, it's important to follow the details exactly.
Online assistance is difficult, and every item in the instructions is significant.
Since this is an infection, I am going to Move this topic to the Malware Removal section of the forum.
Once again many thanks.
I'll try the rootkit and let you know.
I still think the MSoft recommended 'clean boot' caused the present weak state of the machine. Before that I could have run your kit.
Any point in trying Hitmanpro, if the kit doesn't work?
HitmanPro is a conglomeration of a bunch of anti-spyware utilities, some good, some not so good.
Problem is you never know what it will do, or what it did afterward.
We have other tools if this doesn't work properly.
Please don't try to run things on your own in between replies.
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.