PC S.O.S.! Restoring svchost.exe and possibly Windows XP Functionality
By DuoMaxwell
@DuoMaxwell (953)
United States
August 14, 2007 2:00pm CST
This happened to me last night, and it's a long story, so please keep up on what i'm saying here. My computer's in trouble and I need to let you know on my grave situation.
Last night I ran into a nasty little sucker of spyware that kept restarting and restarting my computer, and it also slowed down my computer as well. I figured that this spyware piece is coming from:
C:\windows\system32
So I had to get there and whadya know? THERE IT IS! So as I got closer to the spyware, selecting it and deleting it, I keep getting that it's being used and it can't be deleted until I shut it down. That's where I used both the Task Manager and recently Process Lasso, the same program that stopped my Windows Explorer issue. (I gotta thank the user who gave me the site earlier...)
I shut down the infecting programs, and then I went back to System32 and deleted all of the files, ESPECIALLY svchost.exe which could've been corrupted (since I can tell that the date was the same with the files of the spyware I deleted). I went back to the Task Manager and Process Lasso to shut down svchost.exe in its multiple forms, and I deleted it.
By then, it kept doing the countdown clock before it shuts down, and I had to go to the MS-DOS command program, and thanks to learning some commands like "shutdown -a" (to abort the shutdown procedure), I kept Windows XP open.
However, I had to get through ALL of the accounts in order to eliminate it.
Now keep in mind that my computer has Windows XP Home Edition, and not Professional.
When it shut down by itself again, it's not back to normal as the account slowly started up, and I started the Task Manager. That was when it wasn't in the Windows XP Blue skin, but in its barebones Windows 98-ish Classic body exposed. Later on, the taskbar and Start Menu was the same, and when I opened Windows Explorer, it showed up, but it wasn't in the taskbar. I found the problem.
I deleted svchost.exe because it might've been infected by the spyware, but at the same time, it disabled my ability to do these things:
-System Restore
-Drag and Drop
-Cut, copy and paste
-Surf the internet
-svchost.exe was still in my Recycle Bin, but I couldn't restore it or cut it.
I was getting even MORE stressed out, and since I have a lot of files I still need to backup and delete, I can't reinstall Windows XP. It's an eMachines.
svchost.exe was missing from my Task Manager and my system32 folder, and today i've read that it was an integral part of my PC. I know i've learned my lesson, but I couldn't let it infect my PC at the same time.
I don't have a Windows XP CD, and i've looked inside my eMachines Restore Disk for the same file, but it wasn't there, and even if it was, I can't drag, drop, cut, copy or paste it back to System32.
Is there any way I can restore svchost.exe back to system32 and restore my PC's functionality, and it's regular Windows XP look, back to normal?
2 responses
@pendragon (3348)
• United States
14 Aug 07
System restore is in your menu list, have you tried that?It'll restore your settings to the last previous backup or whatever date you choose,it's worked for me umpteen times.We have windows xp as well.
@DuoMaxwell (953)
• United States
14 Aug 07
I've already mentioned it before, it DISABLED System Restore! Without svchost.exe, not even System Restore can undo the damage done.
I tried it already and got the same message over and over. Trust me, I already tried it. And it failed.
@DuoMaxwell (953)
• United States
14 Aug 07
HOT DAMN YEAH!!!!! I DID IT!!!
I finally restored my PC computer back to normal!!
I was heading towards college looking for a solution, and then it hit me! I can grab THEIR svchost.exe so that I can restore at least the drag, drop, cut, copy and paste functions, not to mention that the taskbar shows the windows that are active!
So as I was at college, the first thing I did was grab it, and then look for other secondary solutions including websites about svchost.exe, which told me to leave it very well alone, to telling me that I should download AND stay behind firewalls and add some anti-spyware for my PC. So I downloaded some from snapfiles.com, and even if I did empty my recycle bin taking my original svchost.exe file, I got freeware file recovery tools like Undelete Plus and Restoration so that I could find it and restore it.
But thanks to the college's svchost.exe file, I dragged my home PC's version into the "My Documents" folder, overwritten the college's one, restarted it, ran msconfig (System Configuration), checked all of the boxes that activate the normal stuff and restarted again.
And voila! Everything, except for the checkpoints of System Restore, were back to normal. I definitely learned my lesson here.
NEVER EVER mess with the svchost.exe file, and keep a backup copy of it at all times! IF it gets fragged by spyware, adware or ANY malware, simply overwrite it with your previous one. Always keep a backup of a clean svchost.exe file with you.
@Sutocu (65)
•
14 Aug 07
Assuming you can get your hands on a WinXP install cd (borrow from a friend, or whatever), this thread explains what you need to do:
http://forum.pcvsconsole.com/viewthread.php?tid=9852



