PDA

View Full Version : Svchost.exe - Application Error


slimdread
September 16th, 2005, 09:34 AM
hi,
i notice that once i boot my system & open a couple of internet explorer windows, an error msg appears;

svchost.exe - Application error
The instruction at '0x77fcc2c0' refrenced memory at "0x7c54144c". The memory could not be "written". Click on OK to terminate the program.

After click on "OK", i can do much anymore. I cant copy & paste, cant download, can open my media player, can open any more internet explorer windows. its just like everything STOPS, until i reboot my system. It has made life so unbearable.

my system:
P4 2.4ghz, 256MB, 60GB HD.

I connect to the internet thru my office LAN. I need soem help or suggestion on how to reslove dis problem.

Thank you.

Spider
September 17th, 2005, 06:10 AM
Go here to Panda ActiveScan (http://www.pandasoftware.com/products/activescan.htm) and after everything is loaded select Local Disks to scan.
If it finds something save the log and post it here please.

slimdread
September 19th, 2005, 11:30 AM
hi,
Scanned my local drive with Panda ActiveScan and this is wht d report looks like. Could it be d cause for d "svchost.exe -Application error" am getting. Any suggestions please...



Incident Status Location
Adware:adware/cws No disinfected D:\WINNT\Downloaded Program Files\Q330995.exe
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-084952.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-085204.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-085205.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-094200.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-094206.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-102533.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-102621.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-102651.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-102719.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.20040912-111031.backup
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts.bak
Virus:W32/Blaster.F.worm Disinfected D:\WINNT\system32\enbiei.exe
Security Risk:Application/RestartNo disinfected D:\WINNT\system32\Tools\Restart.exe

Spider
September 19th, 2005, 04:24 PM
Could it be d cause for d "svchost.exe -Application error" am getting

Adware:adware/cws No disinfected D:\WINNT\Downloaded Program Files\Q330995.exe
Virus:Trj/Qhost.gen Disinfected D:\WINNT\system32\drivers\etc\hosts
Virus:W32/Blaster.F.worm Disinfected D:\WINNT\system32\enbiei.exe
Security Risk:Application/Restart No disinfected D:\WINNT\system32\Tools\Restart.exe
Most definitely.

Go here to Ewido Spyware scan (http://www.ewido.net/en/onlinescan/) and scan all drives. Save the log file and post that here.
reboot
then go here to Trend Housecall (http://housecall60.trendmicro.com/en/start_corp.asp?id=scan) and scan drives, post log please.

You *do not* have your Windows 2000 updated and this is where some of those virus came in.
*Do not* update Windows yet, you must be clean of virii and spyware to be able to update properly.

slimdread
September 19th, 2005, 06:59 PM
hi
this is report of the scan from ewido suite, check it out...
__________________________________________________
ewido security suite online scanner
http://www.ewido.net
__________________________________________________

Name: Spyware.Cookie.Yieldmanager
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@ad.yieldmanager[2].txt
Risk: Medium

Name: Spyware.Cookie.Addynamix
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@ads.addynamix[2].txt
Risk: Medium

Name: Spyware.Cookie.Advertising
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@advertising[1].txt
Risk: Medium

Name: Spyware.Cookie.Atdmt
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@atdmt[1].txt
Risk: Medium

Name: Spyware.Cookie.Hitbox
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@ehg-communityconnect.hitbox[2].txt
Risk: Medium

Name: Spyware.Cookie.Hitbox
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@ehg-kaplan.hitbox[2].txt
Risk: Medium

Name: Spyware.Cookie.Hitbox
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@ehg-qualcomm.hitbox[1].txt
Risk: Medium

Name: Spyware.Cookie.Fastclick
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@fastclick[1].txt
Risk: Medium

Name: Spyware.Cookie.Hitbox
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@hitbox[1].txt
Risk: Medium

Name: Spyware.Cookie.Revenue
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@revenue[1].txt
Risk: Medium

Name: Spyware.Cookie.Advertising
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@servedby.advertisi ng[2].txt
Risk: Medium

Name: Spyware.Cookie.Trafficmp
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@trafficmp[2].txt
Risk: Medium

Name: Spyware.Cookie.Fastclick
Path: D:\Documents and Settings\Administrator.HRS-SERV-ADMIN.002\Cookies\administrator@fastclick[2].txt
Risk: Medium

Spider
September 19th, 2005, 08:14 PM
At ewido you want to put checkmarks on everything before you scan.