svchost and starbar trouble

Discussion in 'Malware Help (A Specialist Will Reply)' started by WilliamsEynon, Oct 17, 2007.

  1. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ok then just skip the dllcache part and continue.

    Yeah! He is probably hoping Boston will pick him up. I would take Lowell anyday.
     
  2. WilliamsEynon

    WilliamsEynon Private E-2

    Entered the commands ok. Found that if I wrote "expand svchost.ex_ svchost.exe" it didn't like it. I wrote "expand svchost.ex_" instead and it expanded it to .exe and wrote it to disk etc!!!

    I then rebooted and reached my desktop with its pretty wallpaper. That's as far as I can get now??? No startbar or icons or anything???

    I can boot in safe mode but it stalls for about five minutes as if its searching for something. Then it flashes to life???
     
  3. WilliamsEynon

    WilliamsEynon Private E-2

    My normal mode does work eventually! Its just taking a bit longer to load up now. Still the freeze persists????:cry
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a new log from ShowNew. I want to see what versions of svchost.exe are in your folders.
     
  5. WilliamsEynon

    WilliamsEynon Private E-2

    Here you go??? I hope it did it right???
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that actually looks better from the perspective that svchost.exe does not show in the log now. And that is what we expect because the ShowNew.bat program is only showing files that have file dates within the last 90 days. Getting the copy from your CD would use the file date from your CD which is older and thus it would not show.

    Now using Windows Explorer, goto the c:\windows\system32 folder and locate the svchost.exe file and right click on it and select Properties. What do you see for the Size (in bytes), Size on disk (in bytes), and the Created date? Then click the Version tab (on the Properties form) and tell me what File Version you see.
     
  7. WilliamsEynon

    WilliamsEynon Private E-2

    Hi,

    c:\windows\system32\svchost.exe
    Size = 12.5kb (12,800 bytes)
    Size on disc = 16.0kb (16,384 bytes)
    Created 29th October 2007 13:01:10
    File version 5.1.2600.0
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What SP level of Windows XP is on the CD that you booted from?

    I bet that it is SP1 and not SP2 which means it does not match what you have installed.
     
  9. WilliamsEynon

    WilliamsEynon Private E-2

    Todays not been good!!! Massive problems with Device Drivers, net connection, CD drive not working, super long freezes!!!! I've had to re-install IE7 and my modem software just to get back on the net!!!!:eek Only able to use the damn thing in Safe Mode now. Normal is far from!!!! Safe is unstable. CD is erratic and works and then doesn't???

    Its a Dell OS CD. Its neither SP1 or 2?? I'm just exploring the CD now!!!! Can't find any mention of what version it is, so I presume it the first??
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Assuming you can get your CD and PC to work, you should be able to see the SP level a couple of ways on your Dell CD.
    1. when you insert it in the CD drive a Window will normally popup after a few seconds about installing Windows XP. Just close the window down, then use Windows Explorer to look at your CD drive and you should notice a volume label like XPSP1a_ENG_PRO or similar. The SP1a is the important part.
    2. Also if you access the CD drive from Windows Explorer, some of the files in the root folder will reflect the SP level. For example you may see a file named WIN51IP.SP1 This will not tell you it is SP1a but it does tell you it is SP1
    3. Also there may be a file name SPNOTES.HTM in the root folder of the CD. If you double click on this file it will open in your browser and show the SP level. But again it will only say SP1 or SP2. It will not show the "a"
    However all that said, I'm positive that your CD is SP1a and we know you were running SP2 on your system which means at some point in time you upgraded. Thus do the below if possible.

    Click Start and select Search
    Now Select "All files and folders"
    Enter the svchost in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    • Search system folders
    • Search hidden files and folders
    • Search subfolders
    Then click the Search button.

    Tell me where you find matches for svchost. What I'm looking to do is find an svchost.exe from SP2 but not one of the possibly bad ones we renamed or deleted and then use this to replace to one currently in system32 with the correct version.

    Also before we actually replace the file, I want to know does your System Restore feature work.
     
  11. WilliamsEynon

    WilliamsEynon Private E-2

    System Retore does not work as it was switched off since step 8 of the "READ & RUN ME FIRST"

    The CD is XP2_PER_ENG??
    The file WIN51IC is as it is??
    There is no SPNOTES.HTM on the CD.

    I downloaded the service packs when I was prompted by Auto Update!!! I remember downloading/installing SP1 and SP2.

    Heres what the search found:
    C:\MGtmp\SVCHOST.EX_
    C:\MGtmp\svchost.exe
    C:\WINDOWS\svchost.ex_
    C:\WINDOWS\$NtservicePackUninstall$\svchost.exe
    C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.PF
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.ex_
    C:\WINDOWS\system32\svchost.bad
    C:\WINDOWS\servicepackfiles\i386\svchost.exe
    C:\WINDOWS\system32\dllcache\svchost.exe
    C:\WINDOWS\system32\dllcache\svchost.ex_

    I've also just been backing up all my files and folders to format my HD and reinstall the OS!! Easy burning is a bit of a quirky writer. Works really well though, very pleased with it!!
     
  12. WilliamsEynon

    WilliamsEynon Private E-2

    I finally caved in!!!! :cry

    I just finished reformatting and reinstalling everything. Nice really, I've just got all the newest betas and updated and installed everything. My system is running sweet now. Plus i've made a few restore points and a few system backups!!!

    Many thanks for the help Chaslang.:major I think youre a legend for trying to help when I was in deeep sheeet!!!!

    Ta ta for now. Till the next time????:D
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy to hear you have things working smoothly now.

    It's just as well! I was going to suggest you bite the bullet and do this anyway since you system appeared to have load of issues within the Windows OS itself. All the malware was gone but it is possible that it could have created unrepairable issues within your system.

    Make sure you work thru the below A.S.A.P:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds