First let me say thanks in advance for the help!
Our CFO came to me last week and said his machine has been freezing up and in turn, he will get frustrated and reboot it. On the reboot, he will receive the "Generic Host Process for Win32 Services" error and eventually he can get back into the OS.
The error signature is below:
szAppName: svchost.exe
szAppVer: 0.0.0.0
szModName: unknown
szModVer: 0.0.0.0
offset: 00000000
In this error he also receives errors pertaining to the files:
C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\WER3.tmp.dir00\svchost.exe.mdmp|
C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\WER3.tmp.dir00\appcompat.txt
Heap=C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\WER3.tmp.dir00\svchost.exe.hdmp
I've done some research and there is alot of info pointing to the blaster virus...I have confirmed that he indeed has the patch installed and any instances of this virus has been removed from the registry, so I don't think that is the case. Anyone else, I would probably just reimage the machine, but this guy will want a detailed answer as to why we have to do that...Any help is greatly appreciated.
Our CFO came to me last week and said his machine has been freezing up and in turn, he will get frustrated and reboot it. On the reboot, he will receive the "Generic Host Process for Win32 Services" error and eventually he can get back into the OS.
The error signature is below:
szAppName: svchost.exe
szAppVer: 0.0.0.0
szModName: unknown
szModVer: 0.0.0.0
offset: 00000000
In this error he also receives errors pertaining to the files:
C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\WER3.tmp.dir00\svchost.exe.mdmp|
C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\WER3.tmp.dir00\appcompat.txt
Heap=C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\WER3.tmp.dir00\svchost.exe.hdmp
I've done some research and there is alot of info pointing to the blaster virus...I have confirmed that he indeed has the patch installed and any instances of this virus has been removed from the registry, so I don't think that is the case. Anyone else, I would probably just reimage the machine, but this guy will want a detailed answer as to why we have to do that...Any help is greatly appreciated.