another "Generic Host Process ..." problem

Status
Not open for further replies.

Hangman

Posts: 14   +0
Hello all,
New to the forum. I've recently been receiving an error message that has caused me to do some searching for an answer and have noticed one similar here on this forum.

Hopefully, someone can help me understand the meaning of it.

The error message:
Generic Host Process for Win32 Services
The perpetrator:
AppName: winsvc32.exe AppVer: 5.1.2600.0 ModName: winsvc32.exe ModVer: 5.1.2600.0 Offset: 0000226f

As you can see, this is from the winsvc32.exe and not the svhost.exe.

I have taken the suggestions from others, I don't have a virus and I have run Adware. This error isn't causing any problems that I can find, nothing stops working, nothing closes. It's just a little annoying that it pops up randomly with an error. And I do mean randomly. I had everything closed down, the very basics to keep windows XP pro running, ... and it popped up.

I've read the tech info from microsoft but it gives basic info about the exe and doesn't explain in more detail what it's used for.

Thanks,
 
From Symantec:
When Trojan.Grepage runs, it performs the following actions:

Copies itself as %System%\Winsvc32.exe.

NOTE: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

Creates the value:

winsvc32.exe %system%\winsvc32.exe

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

so that the Trojan starts when you start Windows.

Also from Network Associates
When run, this trojan opens your web browser to a specified site, copies itself to the WINDOWS SYSTEM directory, and creates a registry run key to load itself at startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run\winsvc32.exe=C:\WINDOWS\SYSTEM\winsvc32.exe

Also might check out http://www.sysinfo.org/startuplist.php?type=&filter=&count=100&offset=4400 and http://www.windowsstartup.com/wso/browse.php?l=23&start=225&end=250 as well as http://www3.ca.com/threatinfo/virusinfo/virus.aspx?id=38649
 
Status
Not open for further replies.
Back