svchost.exe Error 0x595c16e2 and 0x595c17c2 please help me
Hey everyone! I'm helpdesk for a small company and found in this last 2 month many error in diffrent pc models with windows xp sp3 oem installation For every pc , I used the same iso built with nlite win xp pro sp2 + sp3 + ich driver + serial + some personalisations after installation I install Office 2003 complete + Mcafee Virusscan 8.5 entreprise + some other small soft (firefox + cdburnerxp + chrome + daemontool + vlc + ......) the 2 svchost.exe error apear every where but I think the most place are when outlook2003 are used , the 2 error are : QUOTE svchost.exe- Application Error The instruction at"0x595c16e2" (or ""0x595c17c2") refferenced memory at (or ""0x595c17c2"). The memory could not be "written". Click on OK to terminate the program. when I click OK or cancel , the pc freeze no possibility to open task manager no posibility to reboot or shoot down pc yesterday I make this step with one pc 1 - I scan the pc with Spybot - Search & Destroy with the last update I delete 4 cookie infected , I have not a log for this 2 - I use Malwarebytes' Anti-Malware 1.42 to do a system scan : this is the report log QUOTE Malwarebytes' Anti-Malware 1.42 Version de la base de donnes: 3358 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 14/12/2009 17:35:04 mbam-log-2009-12-14 (17-35-04).txt Type de recherche: Examen complet (C:\|D:\|) Elments examins: 205125 Temps coul: 32 minute(s), 34 second(s) Processus mmoire infect(s): 0 Module(s) mmoire infect(s): 0 Cl(s) du Registre infecte(s): 0 Valeur(s) du Registre infecte(s): 1 Elment(s) de donnes du Registre infect(s): 2 Dossier(s) infect(s): 0 Fichier(s) infect(s): 1 Processus mmoire infect(s): (Aucun lment nuisible dtect) Module(s) mmoire infect(s): (Aucun lment nuisible dtect) Cl(s) du Registre infecte(s): (Aucun lment nuisible dtect) Valeur(s) du Registre infecte(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully. Elment(s) de donnes du Registre infect(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Dossier(s) infect(s): (Aucun lment nuisible dtect) Fichier(s) infect(s): C:\RECYCLER\S-1-5-21-4040278158-4412668293-423075710-8749\hd1.exe (Worm.Autorun. -> Delete on reboot. 2 - Finaly I do a system scan with hijackthis , here is the log QUOTE Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:54:05, on 14/12/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe C:\Program Files\Symantec\pcAnywhere\awhost32.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\userinit.exe C:\WINDOWS\system32\userinit.exe C:\WINDOWS\Explorer.EXE C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\Local-Admin\Desktop\HijackThis v2.0.2.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 151.89.16.100:8080 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [bginfo] C:\WINDOWS\BgInfo\bginfo.exe /iC:\WINDOWS\BgInfo\AEN-Algerie.bgi /timer:0 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir la slection en Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la slection en un fichier PDF existant - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir les liens slectionns en fichier Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convertir les liens slectionns en un fichier PDF existant - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_15\bin\npjpi142_15.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = aen.ansaldo.it O17 - HKLM\Software\..\Telephony: DomainName = aen.ansaldo.it O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = aen.ansaldo.it O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe -- End of file - 6715 bytes Please help me I'm very blocked in my job cause of this thank you 2 people need an answerI do too
December 16th, 2009 8:20am

svchost.exe-application error, "The instruction at "0x7521b07e" referenced memory at "0x00000011". The memory could not be "written". I click OK, then PC no response. I tried to restart one of the svchost.exe in the taskmanager, it ll be awake with some of the devices are disabled.Answer for this ErrorSETP 1Download the Windows Update Agent for the version of XP installed,either 32 (x86) or 64 (x64)bit and save it.SETP 2Then download KB928791, either 32 (x86) or 64 bit (x64) and save it:http://support.microsoft.com/kb/927891/When the downloads complete install the Windows Update Agent first, theninstall KB927891, and restart the system.Did that resolve the issue ? Download and installSetp1 Linkhttp://support.microsoft.com/kb/932494Setp2 Linkhttp://support.microsoft.com/kb/927891/
Free Windows Admin Tool Kit Click here and download it now
May 24th, 2010 8:36am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics