Windows XP error message with strange file

Quadriflax

Member
Jan 12, 2005
36
0
0
Starting a couple of days ago my laptop has been getting an error on Windows start up and I can't figure it out. The error reads:

"Error: loader couldn't initialize service!"

I can click ok and everything works fine. It doesn't seem to really do anything that I've noticed so far. I did some digging and found that if I run task manager and click "go to process" I can figure out what's causing the error. This takes me to the process "sbchost.exe"

What is this? That's not a typo, it's listed as "sbchost.exe" My guess is Windows is trying to load this file and it doesn't exist. I did a search for the file name and came up with nothing. I searched on Google and found nothing of use. I've checked my startup in registry etc, and I didn't notice anything wrong there either. What is this mystery sbchost? It's not a virus or spyware either, as far as I can tell (Adaware and NAV don't detect anything). I didn't install or change any settings, it just starting popping up one day. Any ideas?

edit: okay, so I wasn't totally correct. I just searched through the registry and found these entries:

My Computer\HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603

Name: 001
Type: REG_SZ
Data: sbchost.exe

My Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache

Name: C:\WINNT\system32\sbchost.exe
Type: REG_SZ
Data: Generic Host Process for Win32 Services

My Computer\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Name: svchosts
Type: REG_SZ
Data: sbchost.exe

My Computer\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

Name: svchosts
Type: REG_SZ
Data: sbchost.exe

I guess the questions are, what is sbchost.exe, why is it missing, and if I need it, how can I get it back? If I don't, how do I get it to stop trying to load it? I'm concerned about it being tied to svchost.exe, which I know is vital to the system operation, so I don't want to screw with it if I could potentially ah heck things up.

Thanks for any help.
 

Jeff7

Lifer
Jan 4, 2001
41,596
20
81
Spyware. The normal file is svchost.exe, not svchosts, or sbchosts. The line that says Search Assitant is a definite warning too. It might be a new variant of CoolWebSearch. If it is, just hope that it's not even more difficult to remove than some other versions of it. A few versions of CWS required some unique methods of tricking and tracking the program in order to cripple and then delete it.

My usual copy-and-paste advice for this:
Adaware
Spybot
Standalone version of CWShredder.

Download them. Update them. Run them.


svchosts.exe info
 

daniel49

Diamond Member
Jan 8, 2005
4,814
0
71
if he is right the reason you are getting the error message for the adware is because of the entry in the run folder.

Once you have determined its truly addware delete that one and the error message will disappear.
run services you could probably just disable in administration.
 

Quadriflax

Member
Jan 12, 2005
36
0
0
Thanks for your replies you guys. Like I said, the search for the actual file didn't reveal anything. That's probably why it's erroring out. It's trying to load something that isn't there. I do have AdAware installed and updated. I ran it, but it didn't detect anything. Maybe it detected it awhile ago and removed the file but not the registry entry. Though I don't recall it ever detecting anything but cookies as far back as I can remember. Plus it's weird that nothing came up when I put it into Google. Usually anything I suspect as spyware comes up on a Google search.

I'll check Spybot and the other program listed when I get home. I'll also try pandasoft, Nocturnal, and let you all know what happens.

I should also mention I downloaded a little program that lets me check/uncheck what programs load on start up. I think the first thing I'll do is uncheck the "svchost... sbchost.exe" box that's in there (probably links up to the reg entry in the "run" folder). I was just concerned that if I did this it would totally hose everything by disabling svchost entirely. But then again, I could always reload from the last good checkpoint. I digress. I'll report back this evening after I get home from work and try a few things. Thanks!