svchost and starbar trouble

Discussion in 'Malware Help (A Specialist Will Reply)' started by WilliamsEynon, Oct 17, 2007.

  1. WilliamsEynon

    WilliamsEynon Private E-2

    Hi guys,

    I've read over many many pieces of advice on this problem and to be honest I'm at the end of my tether. I'm not having any joy at all!!!!

    I'm running XP home SP2, on an average system. I regularly run Adaware, Spybot, Window washer, ccleaner, Regmechanic, defrag and Norton Antivirus 2008.

    When I start up, my system boots up fine until it reaches the user screen. I click on my user (the other being my Mom who has big text and icons coz shes a bit blind)

    I get my wallpaper image but nothing else. About five minutes later the icons on the desktop load and the start bar appears. I seem to have about a minute to click on any icons or the start bar before my pc just locks up for another five minutes. If I click anything during the lockup, it will all suddenly flash through when the five minutes is up!!!! Very frustrating.

    I have found that after logging in and getting the wallpaper and nothing else, I can start task manager. Nothing on the list seems to be drawing vast CPU apart from System Idle Processes and the odd flash of life from System.

    I have found that of the svchost.exe's that are running (Three System, one Local and two Network Service) if I end the process svchost.exe Network Serices my system flashes into life, icons appear and the start menu appears and works like old times????? I do however get the message saying my Remote Procedure Call is shutting down my PC. I kill this off by running "shutdown -a" thanks to Blackviper.

    After this my PC works fine......well apart from not being able to update Norton, use any peripherals like my printer or cut and paste from different app's (word to firefox etc) or use the clipboard. If I look at the add/remove programs list it won't populate?

    I've followed the guide that I was directed to by "Lev" from the Software forum.

    Ok, so here's what happened:

    0: Tried to uninstall anything that I don't want. Nokia PC Suite and Nokia Cable Driver wouldn't uninstall as woould'n several other useless bits of jusnk. I tried in both Safe and Normal? Also I set MSCONFIG to Normal startup!

    1: Emptied Norton 2008 Quarantine. It now says "there are no items to display" but Norton will not "normal/auto update" or "auto protect" outside Safe Mode. Also Norton Live Support "cannot detect a internet connection" to establish a session?? Even though I can connect using IEXP or Firefox. Norton is not happy after I've stopped the svchost.exe, but works fine before hand.

    I also emptied Norton Protected waste basket, ran CCleaner and Window washer.

    I have updated all my drivers using DriverAgent.com! Well not strictly speaking!! I used it to find updates for my drivers and manually found and installed them myself!! Some loaded fine but others got bumped by the install shield. I started up without killing off svchost.exe and they loaded fine!

    2: Enabled hidden files!!

    3: Having recently parted form the beast that is AOL. I have changed Virus and Firewall software from McAfee AV and Firewall, to Norton Antivirus 2008 and Windows Firewall (only temp till I can buy a decent one)

    4: Downloaded and setup GetRunKey and ShowNew fine!
    Updated, immunized, fixed the ignore products bug and ran Spybot. It found three objects. That where deleted!

    I downloaded Counterspy, but was not allowed to install it. In safe, normal or either scvhost.exe modes. A notice saying the Administrator has set rules not allowing the user to make changes appears. The install shield wizard just wouldn't work in either the Administrator or the other main user.

    I managed to download and install AVG Anti-spyware. It found three bits of spyware and fixed them! Log saved!!!

    5: Restarted in Safe Mode and ran all the above again! Clean as a whistle!

    6A: Tried to run Panda in normal but wouldn't work. So ran in Safe Mode with networking but still didn't work. "Error on page" was the message both times??
    Ran Bitefinder instead successfully. Log attached!!

    6B: Ran GetRun.bat and ShowNew.bat - Logs attached!!

    6C: I ran a few other online scans and they found nothing!!

    7: Downloaded a new version from your site of HJT. Installed it, changed its name, ran it and saved a log!

    ........................................................................................................


    I am still having the svchost.exe problem. Its locking up my PC bigtime and disabling it only means I can't use certain tools like printer.clipboard etc. My system is allowing some installs and not others. Some programs to run ok and not others????

    I'm not sure what to do???

    Thanks for your help.
     

    Attached Files:

  2. WilliamsEynon

    WilliamsEynon Private E-2

    Heres my HJT log! Thanks
     

    Attached Files:

  3. WilliamsEynon

    WilliamsEynon Private E-2

    Oh by the way, I'm about 48hrs away from either burning my Dell on a big bonfire. Or wiping my system and starting again!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    While you have a few things to fix, you major problems may not be due to malware. They may be due to the choice of installing Norton. You should consider uninstalling all of the Norton/Symantec software which is most likely the reason your PC is getting bogged down. You can replace it with free tools given here:
    How to Protect yourself from malware!

    First a couple question from what I saw in your logs. These are not malware issues so if you cannot answer questions, you may need to research answers in the Software Forum. Why were the below proceses running?
    Why does Encarta require all of the below and why does it need to load at all when your PC starts up?


    Now let's fix a few problems.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    Viewpoint Media Player
    <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log ( c:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  5. WilliamsEynon

    WilliamsEynon Private E-2

    Hi Chas,

    Firstly, thanks for the assistance, your help is hugely appreciated.

    This problems started a few weeks before I bought and installed Norton. Norton was supposed to be an attempt on my part at fixing the problem. I thought it was all being caused by a Virus??? Wrong I was!!!!

    The processes you where asking about will be investigated further. I'll post a message on the Software forum after I've written this!
    Encarta has been uninstalled, disassembled, disembowled and had the crap kicked out of it!!!! So hopefully, only remnants of it still exist that will be wiped away during washes/ccleans etc.

    My first attempt at uninstalling the Java and Viewpoint software was after I had killed off the dodgy svchost.exe and freed up my PC to work. I was met with the message:

    "The Windows Installer Service could not be accessed. This can occur if you are in safe mode, or if the windows installer is not currently installed. ontact your supprt personnel for assistance"

    I restarted and left my PC to churn through its job slowly and during one of the momentary free phases, I quickly opened the add/remove window. Once a Software window is open its fine working in it, its only when you try to open another window or the program your using opens one, then it snags up!!

    I managed to uninstall the three bits of software you asked me to. Plus a few others I had been trying to get rid of for a while. It took almost four hours to do it though???

    I rebooted and opened Firefox to install the new Java package!

    It installed fine!

    Rebooted again and then downloaded combofix.exe. I ran combofix.exe and during it (at stage 8) a prompt window opened saying:

    sed.cfexe has encountered a problem and needs to close. AN error report has....etc etc

    combofix.exe then rebooted windows and as it was starting up afresh the message:

    "Microsoft Visual c++ Runtime Library
    Runtime Error
    Program:...am Files\Norton Systemworks\Password Manager\AcctMgr.exe

    This application requested the runtime to terminate it in an unusual way. Please contact the applications support team for more information."

    The usual symptoms still persist with my startbar and svchost.exe is still bogging down processes????

    Attached are the logs you requested. Many thanks for your time once again. My deepest gratitude! Simon Williams
     

    Attached Files:

  6. WilliamsEynon

    WilliamsEynon Private E-2

    Here's the HJT log too.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But before Norton, you had McAfee which can also slow your PC down a ton. Not as bad as Norton but it is still a resource hog. Thus installing Norton, may have taken you from bad to worse.

    Does the software you installed from Norton/Symantec include a firewall? If so, you will need to uninstall Port Monster.

    Looks that way. ;)

    Not according to your logs. Did you uninstall it before or after getting the logs? The below are in your HJT log:
    Be careful with svchost.exe. There will always be several (even more sometimes) running and most of the time they are valid and required. Don't use Task Manager to look at them. Use HijackThis's process manager because it will show where they are running from. C:windows\system32\svchost.exe is valid. Anywhere else is bad. Task Manger will not tell you the path to the file and as such is not very useful.


    It still could be Norton. Try uninstalling but double check your logs to make sure it all gets uninstalled. Norton can be as troublesome as malware to get uninstalled. After uninstalling Norton. Tell me how things are running.

    Sounds like Norton may have been causing some problems for ComboFix but it appears to have run reasonably well in spite of this. Sometimes it is necessary to shutdown and even uninstall protection software (like Norton) inorder to remove malware issues. This happens becaue the protection software can view what we are trying to do as malware actions.

    I will look thru your new logs and see whatelse there is to do but I still think that you should just first try what I suggested and that is Uninstall all of the Norton software and then tell me how things are running.

    Also tell me how fast is your processor and what type? Also how much RAM do you have?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I do see signs of a possible WareOut infection that needs to be removed. Please run the below procedure.

    WareOut Removal

    Attach the requested log from FixWareOut.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    And if you are sure that Encarta is not needed anymore, also fix the below lines.
    O4 - HKCU\..\Run: [E07ZXLRD_926343] "C:\Program Files\Microsoft Encarta\Encarta Reference Library 2007 DVD\EDICT.EXE" -m
    O4 - HKCU\..\Run: [E07ZXLRD_9172718] "C:\Program Files\Microsoft Encarta\Encarta Reference Library 2007 DVD\EDICT.EXE" -m
    O4 - HKCU\..\Run: [E07ZXLRD_2323562] "C:\Program Files\Microsoft Encarta\Encarta Reference Library 2007 DVD\EDICT.EXE" -m
    O4 - HKCU\..\Run: [E07ZXLRD_11490828] "C:\Program Files\Microsoft Encarta\Encarta Reference Library 2007 DVD\EDICT.EXE" -m
    O4 - HKUS\S-1-5-21-1060284298-1708537768-682003330-1004\..\Run: [E07ZXLRD_2323562] "C:\Program Files\Microsoft Encarta\Encarta Reference Library 2007 DVD\EDICT.EXE" -m (User '?')
    O4 - HKUS\S-1-5-21-1060284298-1708537768-682003330-1004\..\Run: [E07ZXLRD_11490828] "C:\Program Files\Microsoft Encarta\Encarta Reference Library 2007 DVD\EDICT.EXE" -m (User '?')

    After clicking Fix, exit HJT.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. don't forget the log from FixWareOut


    Make sure you tell me how things are working now!
     
  9. WilliamsEynon

    WilliamsEynon Private E-2

    :eek

    OMG!!!!!! Trying to run the most basic of tasks whilst leaving the svchost.exe running is just super tedious!!!!!

    I deleted the lines you highlighted in HJT. Removed Norton and then ran the Norton Removal tool from you download area. It didn't effect performance at all even after about four reboots doing other stuff. I've even left it off my system for now! I'll use AVG for now so as not to have any conflicts!!

    When I've run McAfee or Norton in the past my system has performed perfectly, I've only had one incident of slow performance. That was when I was runing two firewalls!!!!! Dohh...

    I don't use the Norton Firewall. Portmonster is only a recent addition. I looking for a really good firewall at the moment!!

    ....Having a few problems...will finish this post off later??????
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay make sure you complete what I requested in message # 8 and then attach the requested logs.
     
  11. WilliamsEynon

    WilliamsEynon Private E-2

    Hi,

    Been away for a few days to recover form the stress!!!

    I've run through the list of tasks you posted.

    I've an Intel Pentium 4 -2.0ghz processor. 384mb Ram. 120gb Hard drive

    I've also attached a process list of the running processes on my system. This is without killing off the svchost.exe that's bogging down my system!

    I'll just post the getrun and shownew next post
     

    Attached Files:

  12. WilliamsEynon

    WilliamsEynon Private E-2

    Et voila!!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should seriously consider upgrading to 1 GB of RAM. 384 MB is way to low for Windows XP to run properly.

    Not needed. The running process list is already in your HJT log and in fact your HJT log shows the below running.

    C:\DOCUME~1\Simon\LOCALS~1\Temp\Div52.tmp\DivXInstaller.exe

    Why is this running?

    FixWareOut removed a few problems.

    Now uninstall Windows Defender and then reboot. Is your PC running any better now?
     
  14. WilliamsEynon

    WilliamsEynon Private E-2

    Hi Chas,

    I had a guy (brother of a friend) look at my PC a while back. He installed a new hard drive and operating system. When I checked my RAM today, before posting, I was really surprised to see I had only 384??? I had 586 (4x 128's) when I had my system built by Dell. I've a Dimension 8200 by the way. I now only have 2x 128's and 2x 64's. It looks like the thieving bastardos has taken out my RAM (which was Kingston) and replaced it with some crappy crap stuff????? Well hacked off about this!!!!

    Anyways, I'll be upgrading it to my motherboards max of 1gb soon. I'm just shopping around at the moment!!! Quite expensive though??? About $200+ for it here in the UK???

    I'd much rather get an XPS!!!!! LOL

    DIVX installed earlier when I was browsing some surf movie site!! The prompt says it was a newer version to one I already had on my system??? I'll kill it off??
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's 512K. ;)

    Indeed!!!!!


    Did uninstall Windows Defender help at all?
     
  16. WilliamsEynon

    WilliamsEynon Private E-2

    Hi Chas

    The other 74mb of RAM in purely Jedi force!!!:D or was.

    I'm gonna be upgrading over the next few days to 1gb of ram and installing another 80gb hard drive.

    Uninstalling Windows Defender didn't change anything! There is still something locking my startbar and desktop.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please describe exactly what your problems are but first do the below and then see if there are still problems.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Fixing Locked Desktop
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.


    Now also attach new logs from GetRunKey, ShowNew, and HJT if still having problems.
     
  18. WilliamsEynon

    WilliamsEynon Private E-2

    Nope, still the same?

    Simple tasks still stalling and then happening all at once.

    Right here's a detailed description, from startup, of my problems:

    Power on!
    I get the usual Dell and then XP screens at the usual speed. I then see my wallpaper. Nothing else appears for a good two three minutes. I then get a few basic files on my desktop appear. ie jpegs, text, zip files! I also get the start bar and button, Including the clock, but no icons of processes or programs by it.

    If I scroll the mouse over the start bar I see the egg timer. I can still move the mouse about, but anything I click doesn't react?

    During this freeze time I can ctrl+alt+del to open task manager. This operates as if there is no problem? I cannot open anything else or click on start to access my programs or "my computer" files.

    During the freeze there is no sound/life from the hard drive, floppy or the CD-Rom. In task manager "system idle process" is using 99% CPU. Also in the freeze I worked out that if I end one of the six svchost.exe processes my system suddenly springs to life and operates as if nothing is wrong! I do however get a message saying "remote procedure call is shutting down your PC" etc. giving me 60 seconds. I then run "shutdown -a" to stop this!

    I came upon the svchost.exe/shutdown -a solution by reading a page on Black Vipers website!

    If however I don't stop the svchost.exe, my system wille freeze for about 4 minutes and then unfreeze for a minute, and then repeats this over and over.

    I'll restart my system now and run shownew, getrun and HJT.

    Thanks again for your time Chas!
    Simon
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Much of what you are describing could still be related to inadequate RAM and also there is potential that the RAM that was used to replace yours does not have the required specs to properly operate in your PC. And in addition, the RAM could even be defective.

    This is normal and what you want. System Idle Process is not a real process. It is a measure of the time your processor is not doing any other tasks. Thus your processor was 99% free.

    Killing a required svchost process will always cause this to happen.
     
  20. WilliamsEynon

    WilliamsEynon Private E-2

    I've run memtest.exe for a few hours and it found nothing wrong with my RAM. I'll run it overnight tonight just to make sure.

    I only use my PC for a bit of wordprocessing (word and excel), email (outlook) and browse the net with Firefox. I occasionally use Photoshop 7 and ArchiCAD with no problems, especially as they both crank up the processor and RAM. Plus I wouldn't say I put my system under massive strain like gaming etc??

    I'll upgrade the RAM in the next few days and see what happens. I think I might just have to wipe the hard drive and start again??
     

    Attached Files:

  21. WilliamsEynon

    WilliamsEynon Private E-2

    Right, I've just bought 1Gb of ram off of ebay. 4X 512MB Kingston pc800-40 RDRAM RAMBUS RIMM. Solid gold????? Hmmmmm;)

    Im also gonna mod my cooling system and upgrade my HD to a Seagate 500gig!!!!

    I might even glue some horns to the sides of the tower and wear a crash helmet when turning it on?????:D
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that is a good sign anyway.

    It's possible that something has corrupted your OS since we have not found any major malware issues other than WareOut but it has not been know to cause the kind of problems you are seeing.

    I'm looking at your logs now. I'll let you know if I find anything.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still do not see any reasons for you problems but I do have some steps for you to take.

    First I suggest that you avoid saving so much stuff on your Desktop like you currently have. I suggest you move everything but .lnk files someplace else if you really need them. Even the GetRunKey and ShowNew folder should not be here as requested in the READ ME. The more you put on your Desktop the more you can impact your PC's performance. You Desktop has to get refreshed all the time, and the act of doing this can cause an antivirus prorgam (which you don't have right now since we uninstalled it) to scan each of these Desktop files everytime the Desktop refreshes. In addition, the Desktop is not really a safe place to save things you may need long term because malware likes to play around with your Desktop.

    Now let's cleanup after Norton/Symantec a little.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)

    After clicking Fix, exit HJT.

    Something else of possible concern is that you svchost.exe files appears to have been recently updated/changed. I see this
    Code:
     
    "C:\WINDOWS\system32\"
    svchost.exe   22 Oct 2007       14336  "svchost.exe"
    Do you have your Windows XP SP2 boot CD?
     
    Last edited: Oct 24, 2007
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also just to be on the safe side, let's check for rootkits. Run the below and attach the requested log.

    Running GMER to detect rootkits


    Do all of your symptoms/problems also occur if you boot in safe mode?
     
  25. WilliamsEynon

    WilliamsEynon Private E-2

    Hi Chas

    No, my system is fine in Safe Mode. I have a XP SP2 boot CD. I've cleaned up my desktop, only the waste basket and a few shortcuts to folders on my other part of my hard drive.

    On that subject. When my new Hard Drive was installed. The guy partitioned it, making 20gb with the operating system on it and the other 60gb with nothing on it. I have most of my files and folders on the larger partition. On the 20gb part i have 8.7gb free and on the 60gb side I have 55gb free????? Novice geek here, not sure how much this makes sense??

    Also I have the my virtual memory set to system defined? Its total paging size for all drives is 1149mb?? Although the recommended is about 500mb??

    I don't know if any of this is relevant??

    Thanks again for your time?? As a carpenter I wish I could offer my services as way of repaying you for your time/good karma/aloha!!! But I'm in the UK and I reckon you're probably in the US somewhere!!!

    Thanks... Simon
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No rootkits were found which is good!

    Okay I'm not sure exactly what is causing your problem right now but I would like to eliminate the possibility of two other programs loading at startup before we pursue potential issues with the svchost.exe file for no reason at all. Also I want to remove an unnecessary item from your HJT log.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

    After clicking Fix, exit HJT.

    Nopw please uninstall Webroot Window Washer and AVG Antispyware and then reboot. Does this have any signficant effect on your PC.

    It is more a matter of choice with everyone on how they partition things. I would not have made your Windows boot partition that small. In fact with an 80 GB drive I would have just kept one partition, or I would have made two 40 GB partitions.

    Maybe & maybe not. You are missing some additional info that should be on this Virtual Memory form. While the below will not match your settings, you get the idea of what should be on the form.

    VirtMem.jpg

    Next time I'm adding on to my house, I'll give you a shout. :D
     
  27. WilliamsEynon

    WilliamsEynon Private E-2

    I removed the Google BHO and then uninstalled Window Washer and AGV. No change after a few reboots.

    I've also added another 512mb of RAM and there is no change. I'll have the other 512mb arrive on Monday. But to be honest I don't think its lack of RAM as i'm running 768mb at the moment. If I kill off the svchost there is a noticeable change in the speed from the new RAM!!

    I really am thinking of just building a new system on a new hard drive now!! This is affecting both my work and social life!!!!!!:cry I've spent almost two weeks trying to sort this out now. I'm very close to giving up and leaving the empire and the dark side and going to join the rebel alliance (MAC)!!!:guns
     
  28. WilliamsEynon

    WilliamsEynon Private E-2

    Having just read up about Windows XP boot CD's I don't actually have one. I have a Boot floppy and a XP Installer CD?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes right now it would sound like it. However for your future use, the new RAM is a very good investment.

    Yes but you need the svchost processes. Anything you kill would obviously have a inpack on perfomance. The question is why is this one svchost process causing such a big problem. It sounds like you have some kind of issue within the Windows OS or with a driver. This does not appear to be malware. Since it does not happen in safe mode, there is something that loads in normal boot mode that is causing the issue. I wanted to try using a Windows boot CD to boot to the recovery console so that you could replace the svchost.exe file with one from your CD just to see if it was somehow related. I was questioning the recent date change on your svchost.exe file. Are you sure that your CD is not a bootable CD? Have you ever tried to boot from it?

    This could be the best alternative for you right now especially if you have no boot CD. But you will have to backup all of your data and you will have to have CDs to reinstall your OS and all drivers for your PC.
     
  30. WilliamsEynon

    WilliamsEynon Private E-2

    Hi,

    I just tried the CD and it is a boot CD. What do I have to do with the recovery console to replace the svchost.exe????

    Thanks

    ps. If you ever do decide to rebuild your house then sort out airfare, bed and board and i'm there!!!:major Not sure how I'd get my truck load of tolls there though???:D
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First before starting the below steps, create a new folder in the root of drive C and name the folder MGtmp. Thus you should have C:\MGtmp

    Now I want you to put the Windows CD into your CD drive, but do not reboot to the CD yet. We are going to copy a file from it first. Once you have the CD in the drive, access the CD with Windows Explorer ( you run Windows Explorer by right clicking Start and selecting Explore). On the CD double click on the i386 folder to enter this folder. Scroll down to the svchost.ex_ (yes the underscore is correct) and right click on it and select copy. Then navigate back to the C:\MGtmp folder and then right click in the MGtmp folder and select paste. This should create a copy of the svchost.ex_ file in this temp folder. If this does not work, STOP and tell me. If it works, then continue. Leave this Windows Explorer window open monitoring the MGtmp folder.

    Now click Start and select Run and enter cmd and click OK. This should open a command prompt window. In the command prompt window enter the below commands in black bold print

    cd C:\MGtmp
    expand svchost.ex_ svchost.exe
    exit


    Note: there are spaces after the cd, after the expand, and after the svchost.ex_
    The exit command should close the command prompt. Now back in your Windows Explorer window we left open, check to see that you now have svchost.ex_ and schost.exe in that folder. If not, STOP and tell. It you do have both files, continue.


    The Recovery Console Part

    Now read thru the below to familiarize yourself with it and print it so you can refer to it while offline since you will now be able to browser once starting the below.
    1. Put the Windows XP CD into the CD ROM tray and close the tray. You may get a popup window asking about installing Windows XP. If you do, just close that window.
    2. Then restart your computer
    3. This should cause your computer to boot from the CD instead of the hard drive..(if not your you'll need to enter the BIOS and set the boot order so the CD ROM is first in the list.)
    4. You should get a "Press any key to boot from CD" message! Press a key to do that otherwise it will by pass the CD boot.
    5. After it boots up, you will see it load a bunch of files (be patient it can take a little while) and eventually you will see a menu where you can select the "Recovery Console" by pressing R It is normally the middle item in the list. Press R
    6. You will see a list of possible Windows partitions with numbers next to them. Select your Windows Installation (which is C:\Windows) by typing the number next to it (which should be 1) and press enter.
    7. It will ask you for the Administrator password is next (so make sure you know it). It you never gave it a password it is probably blank. If it is blank, just press enter. If you have set one then type it in and hit enter. It will tell you if you enter the wrong password.
    8. When you enter the correct password you will get a prompt that looks like this: C:\WINDOWS>
    Now from this command prompt window, here are some things I want you to do. Enter the below commands in the order given. I will add comments in purple.

    cd system32 <-- the prompt should change to C:\WINDOWS\SYSTEM32>
    ren svchost.exe svchost.bad <-- this will rename the current file
    copy c:\MGtmp\svchost.exe <--- this should copy into the system32 folder the file we created earlier. Make sure you get a message indicating 1 file was copied
    cd dllcache <-- the prompt should change to C:\WINDOWS\SYSTEM32\dllcache>
    copy c:\MGtmp\svchost.exe <--- this should copy into the system32\dllcache folder the file we created earlier. Make sure you get a message indicating 1 file was copied
    exit <--- this will exit the Recovery Console and boot to Windows

    If your PC still boots to the CD, remove the CD and reboot.

    After reboot, attach a new log from ShowNew also tell me if there is any change at all to your problems. If not, click Start and select Run and enter cmd and click OK. This should open a command prompt window. In the command prompt window enter the below commands in black bold print

    sfc /scannow

    The above will run a system file check looking for potentially bad or corrupted system files. If may ask for your Windows CD so be ready to put it back into the CD drive if it asks for it.

    Did any of the above help?
     
  32. WilliamsEynon

    WilliamsEynon Private E-2

    Hi Chas

    I managed to get as far as the recovery console part? I reached the part where I had to copy c:\MGtmp\svchost.exe and I was met with Access is denied?????

    Everything was going fine. Did the CD boot, I pressed R for the recovery console and then reached which partition to use! I only had one option C:\Windows - I wasn't asked for a password when I selected it (by pressing 1) and ended up with C:\WINDOWS> which I presumed to be ok! I then went through the steps entering the commands.

    I reached the copy part and got the Access is denied message. I decided to change the svchost.bad files back to svchost.exe just in case I couldn't boot up without them. Also I hoped to leave everything as I found it :confused

    I didn't do the sfc/scannow as I didn't coplete the previous task?? I hope I did the right thing??

    Very tired...had to sit up till 5am last night???? Go Socks!!!!:D:D:D Can you believe a pitcher with no hits all season driving in two runs, kicking off a six run inning!!! Matsu the expressionless rocks!!!!
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do the svchost.ex_ and svchost.exe file exist if you look in the C:\MGtmp folder right now in normal boot mode. Also if you right click on the svchost.exe file and select Properties, which Attributes are checked.?

    Run this right now anyway and tell me what happens.

    Hate the socks! :(
     
  34. WilliamsEynon

    WilliamsEynon Private E-2

    Yes they are!!!

    Neither Read Only or Hidden!!

    Will do!

    I'm a Yankees fan. Plus Anaheim are cool to go see when I'm in CA. But when there's only two sides, you gotta shout for one!! An I like the way they're attacking each game as if they want to. I stand by the Sox shout!!!! LOL

    Which colours do you wear Chas???
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! When you did the cd system32 did the prompt change to C:\WINDOWS\SYSTEM32> as I said it should


    I grew up as a Yankee fan and I play on a team named after the Yankees.


    Let me know the results of the sfc \scannow also attach a new log from ShowNew.
     
  36. WilliamsEynon

    WilliamsEynon Private E-2

    Yes it did!

    I don't understand why they treated Torre like they did??? Madness in anyone's eyes.


    The sfc /scannow fired up the checker. But it checked and just closed itself not producing a prompt or log or anything???
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That just means that based on what it checks for that nothing was found or that it automatically just fixed anything it needed to fix.

    When you did the ren svchost.exe svchost.bad command at the recovery console did it complain at all. The reason I ask is that I do not see a file named svchost.bad in your system32 folder. That would mean that the rename did not work.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know how to copy (while in normal boot mode) the svchost.ex_ file into the c:\windows\system32 and c:\windows\system32\dllcache folder without me explaining? If yes, please do that now.
     
  39. WilliamsEynon

    WilliamsEynon Private E-2

    I did it in this order roughly!!

    cd system32
    ren svchost.exe svchost.bad
    copy c:\MGtmp\svchost.exe
    access denied
    ren svchost.bad svchost.exe
    exit

    It didn't complain once!

    Also when I ran sfc /scannow the XP cd was in the drive and it did spin up a few times and flashed its green light!!

    Will copy the svchost.ex_ file to the c:\windows\system32 and c:\windows\system32\dllcache folders! Should I copy the svchost.exe also??
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means that it did repair something automatically. Are you still noticing problems with excess CPU use on svchost.exe ?


    This would more than likely be denied because multiple svchost.exe process will be running and thus the file could not be overwritten. This was the reason for wanting to copy it after booting to the Recovery Console. Windows is not running when you boot this way. Thus the svchost.exe process and all other Windows process are not running which makes it possible to repair/replace them.

    Did you get the svchost.ex_ copied to system32 and to dllcache? Look with Windows Explorer to make sure they are there.
     
  41. WilliamsEynon

    WilliamsEynon Private E-2

    I'm trying to copy the svchost.ex_ now. Its slow going as I only seem to get a few seconds every five minutes now??? It really labours over opening up files on my C: drive....Lock central. Its strange how I can still use Firefox to browse while I wait????
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can use safe boot mode to do this steps since you said it runs better in safe mode.
     
  43. WilliamsEynon

    WilliamsEynon Private E-2

    rolleyes doh
     
  44. WilliamsEynon

    WilliamsEynon Private E-2

    Done!!!!

    Good night J Lester....Nice innings...2-0....

    More beer!!!!

    Bottom of the 6th already!!!
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so did you get the svchost.ex_ file copied to both folders.

    It's now 3 to nothing!;)
     
  46. WilliamsEynon

    WilliamsEynon Private E-2

    Both copied!:p

    3 - nothing and I had my head in the refrigerator an missed the homer!!!:cry
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I thinking about how to approach the next steps.

    3 to 1
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you will use the same procedure to boot to the Recovery Console but use the below set of commands in black print. Purple is again just comments.

    cd system32\dllcache <-- the prompt should change to C:\WINDOWS\SYSTEM32\dllcache>
    del svchost.exe <-- delete the current file in this folder
    expand svchost.ex_ svchost.exe <-- creates a new svchost.exe from your original
    dir svchost.exe <-- should show you the svchost.exe file if created properly
    cd .. <-- yes the dot dot is correct. This should cause the prompt should change to C:\WINDOWS\SYSTEM32>
    ren svchost.exe svchost.bad <-- this will rename the current file.
    expand svchost.ex_ svchost.exe <-- creates a new svchost.exe from your original
    dir svchost.exe <-- should show you the svchost.exe file if created properly
    exit <--- this will exit the Recovery Console and boot to Windows

    If your PC still boots to the CD, remove the CD and reboot.
     
  49. WilliamsEynon

    WilliamsEynon Private E-2

    In command prompt it wouldn't let me change system32\dllcache\svchost.exe as it wasn't there?? I restarted in safe mode and found there is no svchost.exe in the c:\windows\system32\dllcache

    There is only a svchost.exe in c:\windows\system32 ?????

    Can't believe ARod is leaving. The ball club is haemorrhaging is best players????:(
     
  50. WilliamsEynon

    WilliamsEynon Private E-2

    I reckon I can work out how to adjust the commands to do what's needed. I just need a nod from a more enlightened soul!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds