svchost.exe

J

John-Paul

I am having a few issues with my machine that I think are
related:

-after I have been online for a while i get an error
message that says:"SVCHOST.EXE has encountered errors and
will be closed by Windows. You will have to restart the
program" (not verbatim). Once this happens, it keeps me
from doing a lot of things on my PC like visiting some web
pages, links on pages don't work, can't open other files
on my machine e.g. access database, text files...I have to
restart my computer and not get on the net for anything to
work properly again.

I thought this might be virus related, so I updated my
virus definitions and found out I had w32.blaster.worm as
well as the C,E, and F variants. Norton anti virus
removed this and I deleted some keys from the registry
corresponding to the virus files. Norton found no other
viruses at the time, but later when I was on the net again
it found w32.hllw.gaobot.gen. The file couldn't be
repaired so I went to find it and delete it. The computer
couldn't find it! When I go explore that directory,
nothing comes up--no icons for items in that directory. I
downloaded the tool for the worm removal and it couldn't
find it either. (scanned in safe mode as well as
regular). The message indicating that I have this virus
in file C:\winnt\system32\winhlpp32.exe keeps coming up,
but I can never find the file and Norton doesn't get rid
of it.

Later Norton said it found w32.welchia.b.worm in file
c:\documents and settings\default User\Local Settings\Temp
Internet Files\Content IE5\EPOLYXQJ|WksPathc[1].exe.
Norton didn't do anything about this file, so I found it
and deleted it.

The problem is that I keep getting the SVCHOST.exe error
and I can't figure out why. I am updating Windows now,
but that error keeps me from doing it a lot of times
(comes up during the downloads).

Sorry for the length!! Can anyone help???
 
A

Alias

If I were you, I'd reformat. The time you've spent so far is probably longer
than a reformat and installing your programs would take.

Alias

"John-Paul" wrote
 
E

Enkidu

The problem is that I keep getting the SVCHOST.exe error
and I can't figure out why. I am updating Windows now,
but that error keeps me from doing it a lot of times
(comes up during the downloads).
There are removal tools for both blaster and welchia. Get the Welchia
tool too, and the latest virus defs, *take the machine off any
network* and run the Welchia and Blaster removal tools and then your
virus checker. It would be preferable to get the virus defs by some
other machine that the problem machine.

Cheers,

Cliff
 
F

Frank

I had what seems to be the same problem.
After following instructions from Norton and Microsoft I got additional
help from Dell.
Here is a copy of my note to Dell and their reply.
Let me know if this helps.
Frank C.

Dell Prob Rpt
Svchost exec has generated errors. Restart Computer.

Problem occurs about 5 min. after connecting to ISP.
Also Find command doesn't work until after reboot.

Installed Microsoft fix Article 319161
Installed Microsoft Blaster Patch.
Ran Norton Virus detector and virus tool for Blaster worm One file found
and quarantined: msblast.exe Installed "Shoot the Messenger" from Gibson
Research to disable port 135.

I Scanned WINNT files again - No virus found
I ran the Norton tool again - No Blaster Worm found.
I looked for msblast.exe in:
HKEY_LOCAL_MACHINE\Software\Windows\Current Version\Run
with regedit RUN was not there.
I looked for msblast.exe in Windows\System32 - Not found


Instructions from Dell modified for Windows 2000 -fgc

1. Set Windows Distributed COM to Off
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

The worm file specifically attacks the COM utility which is
seldom used but turned on by default. Step one is to turn it
off:

* Turn off your computer and disconnect your cable or DSL modem
from the wall.

* Turn the computer back on.

* Click [Start] | Run

* In the Open: box type

Dcomcnfg.exe

· Click [OK] or press [Enter].

· See the "Distributed COM Configuration Properties" screen

* On the Default Properties tab clear the "Enable Distributed
COM ..." check box.

* Click [Apply] Then [OK] and close the Component Services window.

* Shut down Windows, turn off the computer, and reconnect your
cable or DSL modem, and turn Windows back on.
 
F

Frank

Sorry; I forgot to add step two from Dell.
Frank

2. Run the Anti-Virus Removal File for this Worm
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top