Question about Microsoft Windows XP Home Edition

1 Answer

I have deleted svchost.exe accidently from windows xp and cannot now log onto windows. I have tried expanding the file from dos however still cannot log on

Posted by on

  • muggles300 Dec 02, 2008

    tried going the d:i386 and finding %systemroot%\system32 but path was not found



  • Anonymous Apr 13, 2009

    I have similar problem but I didnt deleted SVCHOST I  just disabled it in msconfig/startup menu and cannot now log onto windows. Is there any solution for this problem?

×

1 Answer

  • Level 3:

    An expert who has achieved level 3 by getting 1000 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    Genius:

    An expert who has answered 1,000 questions.

  • Master
  • 1,605 Answers

This is going to be a tough one to fix. since I don't know which svchost you have deleted from the system.
usually when that happen the only solution is to reinstall the OS. even try to fix it from the registry key, the key and the pointer will be there, but not the excution file, and there is not way which svchost control what services.

The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services allows for better control and easier debugging.

Svchost.exe groups are identified in the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\SvchostEach value under this key represents a separate Svchost group and appears as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service names that are extracted from the registry key.

Posted on Dec 02, 2008

  • Frank
    Frank Dec 02, 2008

    the choice is to over write the WIndows OS.

    insert the OS CD, if you have one, let it run to a point asking to install a fresh copy of Windows or repair the system.

    install a copy of Windows OS, but don't format the hard drive, just over write the old one. you may lost some of the short cut and some of the icons may not work. but you will not lost any of the files.

×

1 Suggested Answer

Dipu007
  • 2110 Answers

SOURCE: I have deleted svchost.exe from windows xp

To complete part one, follow these steps:

  1. Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer.
    Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted to do so.
  2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
  3. If you have a dual-boot or multiple-boot computer, select the installation that you want to access from the Recovery Console.
  4. When you are prompted to do so, type the Administrator password. If the administrator password is blank, just press ENTER.
  5. At the Recovery Console command prompt, type the following lines, pressing ENTER after you type each line: md tmp
    copy c:\windows\system32\config\system c:\windows\tmp\system.bak
    copy c:\windows\system32\config\software c:\windows\tmp\software.bak
    copy c:\windows\system32\config\sam c:\windows\tmp\sam.bak
    copy c:\windows\system32\config\security c:\windows\tmp\security.bak
    copy c:\windows\system32\config\default c:\windows\tmp\default.bak

    delete c:\windows\system32\config\system
    delete c:\windows\system32\config\software
    delete c:\windows\system32\config\sam
    delete c:\windows\system32\config\security
    delete c:\windows\system32\config\default

    copy c:\windows\repair\system c:\windows\system32\config\system
    copy c:\windows\repair\software c:\windows\system32\config\software
    copy c:\windows\repair\sam c:\windows\system32\config\sam
    copy c:\windows\repair\security c:\windows\system32\config\security
    copy c:\windows\repair\default c:\windows\system32\config\default
  6. Type exit to quit Recovery Console. Your computer will restart.

Posted on Dec 02, 2008

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

2 Answers

I set my admin account to limited user and i cant open it anymore..please help to retrieve this user account.thank you..


i assume you are using Windows XP.
try log off and login as "Administrator", if you remember the password. Try blank password first. if it doesn't show in the list, press Ctrl-Alt-Del twice and type it in.
if no joy, you can download this iso, burn it onto CDR as disk image, not data.
restart and boot from this CD, then you have the chance to change/reset/blank any user's password. but take care not to do other thing. follow the author's instructions.
good luck!

Aug 08, 2011 | Microsoft Windows XP Professional

1 Answer

When I try to uninstall "Yahoo Messenger" there is message that says that I need to Open/Find Install.Log file. But the file is not in Windows XP. Should I try DOS?


First of all, DOS is an operating system on its own. It is not in Windows XP. Secondly, try running a search for the Install.log file. Without looking at the problem, I would say that it is just telling you that there is a log of the uninstall process. If it isn't letting you uninstall, run the search for the log file and go from there. Another approach would be to simply delete the Yahoo Messenger folder in the Program Files folder on the hard drive.

Jul 19, 2010 | Microsoft Windows XP Professional for PC

2 Answers

Redirct and error at 0x00000 when closeing IE or FireFox


Well it is quite obvious however. I ll include manual removal instructions. Please follow the steps carefully.
There will be 2 executable files which are Sysinternals Antivirus.exe and svchost.exe. Svchost is invoked by the other executable. There may be another one named alggui.exe
You have to kill these two processes. First of all you have to do this:
  1. Start the Task manager by right clicking on the Taskbar.
  2. Go to Processes.
  3. Observe the processes.
  4. Right Click on processes and select End process for Sysinternals Antivirus.exe and alggui.exe. You will not be able to kill the svchost.exe however since there will be more than one and each represents a Valid system process. To find the exact process run by the file which resides in the "Program Files", I recommend you to use the Security Task manager for Windows.Here is the Link
  5. Use the tool and kill the exact process.
Locating malicious files. The list of files I have already mentioned. But there are more.
  • C:Program Filesskynet.dat
  • C:Program Filessvchost.exe
  • C:Program Filesalggui.exe
  • %UserProfile%DesktopSysinternals Antivirus.lnk
  • %UserProfile%Start MenuProgramsSysinternals AntivirusSysinternals Antivirus.lnk
  • C:Program Filesadc_w32.dll. You must unregister this. Otherwise it will run again.
  • C:Program FilesSysinternals AntivirusSysinternals Antivirus.exe
  • %UserProfile%Start MenuProgramsSysinternals Antivirus
  • C:Program FilesSysinternals Antivirus
  • In variants there will be additional files (Sysinternals Antivirus.exe adc_w32.dll alggui.exe extra1.dat extra2.dat nuar.old skynet.dat svchost.exe wp3.dat wp4.dat dbsinit.exe wispex.html ccsmn.exe ccsmn151.acf csmn151.ltd ccsmn151.lti ccsmn151_0.acb ccsmn151_0.aci ccsmn151_0.mt ccsrr.exe wmharun.log wmrun.log Sysinternals Antivirus.lnk)
You have to search and delete each and every file.
We have to set some additional things in order to see the Hidden and System files which are protected.
  1. Open My Computer.
  2. Go to Tools and then Folder Options.
  3. Click on View tab.
  4. Under the Option "Hidden Files and Folders", set it to "Show ..."
  5. Untick the "Hide Protected Operating System Files (Recommended)" as well.
  6. Now go to C partition and check whether you can see .sys and other hidden files including the System Volume Information folder. If so the procedure was successful. Otherwise you have to edit the registry or have to use the DOS command window to locate and delete these files.
  7. Use Windows search tool to search the files. Before searching set the More Advanced Options. Check for "All files and Folders". Drop down "More advanced options" and tick the Search System Folders, Search Hidden files and folders, Search Sub-folders options. Then do the search. If you find any file or folder you have to delete it. Before deleting, there is one more thing to do.
  • You have to stop the Startup Processes.
  • Click on the Start menu and hit on Run. Or type in Run if you have Vista.
  • Type in the Run box this. msconfig
  • Hit Enter.
  • Go to "Startup" tab. Examine the processes and remove the unwanted ones. You can browse for the valid ones.Specially note the Autorun.inf files. You must remove them if exist.Remember the path to each malicious file. Then uncheck the boxes. Hit Apply button. Then OK button.
  • Do not Restart the System when you have been asked.
Stopping the System Restore services
  1. Go to Properties of My Computer.
  2. Go to System Restore.
  3. Turn off.
Now you are ready to delete the files. Click on each file and Click SHIFT+DEL. Do not Right Click and Delete.
Alternative way if Hidden files and folders are now shown
  • Get the Run box again and type in cmd and press Enter.
  • Type cd and hit Enter.
  • Now you will be in the System drive (C: most probably)
  • You have to use: cd foldername to move within folders.
  • Example: Type cd program files and hit Enter to go in to Program Files.CD denotes Change Directory.
  • To change the Partition you have to type Partition: and hit enter.
  • Example: D:
  • Locate each file and delete Except the adc_w32.dll because we have to Unregister it.
  • Go to each location which I have included here as well as shown in the msconfig tool.
  • Then use DIR /a /q to get the list of files.
  • Type DIR /a /q and hit enter.
  • Note: Note the spaces.
  • Now if you see the files type this and hit enter.
  • attrib -s -h -a -r
  • Then type Del with the file name.
  • Example: Del alggui.exe
  • What the attribute command does is changing the File attributes to normal ( - is used to remove the attributes. S is for System, H is for Hidden, A is for Archive, R is for Read Only).
  • Make sure you go to Root of each partition and check for Autorun.inf files (There may be batch files as well - .bat files, exe files etc. Check whether they are valid executables using the browser)
  • Now that part is done!
Unregistering the DLL file before Deleting:
  • Get the Command Windows again using cmd.
  • Type in Regsvr32 /? and hit enter. If you get a Dialog Box that means its functioning.
  • If you do not have it obtain from here. Place the file in Windows/System32.
  • Type in Regsrv32 /u C:Pathadc_w32.dll and hit enter.
  • Path is the path to the file. It may be in the Program Files or Windows or WindowsSystem32. Use Search or Command Windows to find it. (Might be in the Startup in msconfig as well).
  • You can run this command without the Command Windows as well. Just enter it in the Run box and hit Enter. If you do properly it will show you a dialog box containing the Success message.
Contd...

Jul 09, 2010 | Microsoft Windows XP Professional

2 Answers

Everytime i open my computer, ah pop-up windows say's WINDOWS CANNOT FIND SCVHOST.EXE


Hi,

First, I'll let you know what's going on, then I'm going to post from Microsoft, what svchost.exe does, and how to find out where the problem is. I can help you further if you need it.

Svchost.exe is a program in WIndows XP Pro that will start services in your computer during startup. It sounds like you have deleted a program and "service host" is still looking for it to open on startup. This can happen if the program was removed without using the correct removal procedures. It is still listed in the registry and your computer is still trying to access it. DO NOT edit your registry unless you know what you are doing. You could create a catastrophic failure of Windows. There are programs that will remove registry entries if those entries are no longer valod. You can fing a free program for this function at web sites like www.nonags.com

Following is information from the Microsoft web site:

The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services allows for better control and easier debugging.

Svchost.exe groups are identified in the following registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\SvchostEach value under this key represents a separate Svchost group and appears as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service names that are extracted from the following registry key, whose Parameters key contains a ServiceDLL value: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Service To view the list of services that are running in Svchost:
  1. Click Start on the Windows taskbar, and then click Run.
  2. In the Open box, type CMD, and then press ENTER.
  3. Type Tasklist /SVC, and then press ENTER.
Tasklist displays a list of active processes. The /SVC switch shows the list of active services in each process. For more information about a process, type the following command, and then press ENTER: Tasklist /FI "PID eq processID" (with the quotation marks) The following example of Tasklist output shows two instances of Svchost.exe that are running. Image Name PID Services
========================================================================
System Process 0 N/A
System 8 N/A
Smss.exe 132 N/A
Csrss.exe 160 N/A
Winlogon.exe 180 N/A
Services.exe 208 AppMgmt,Browser,Dhcp,Dmserver,Dnscache,
Eventlog,LanmanServer,LanmanWorkstation,
LmHosts,Messenger,PlugPlay,ProtectedStorage,
Seclogon,TrkWks,W32Time,Wmi
Lsass.exe 220 Netlogon,PolicyAgent,SamSs
Svchost.exe 404 RpcSs
Spoolsv.exe 452 Spooler
Cisvc.exe 544 Cisvc
Svchost.exe 556 EventSystem,Netman,NtmsSvc,RasMan,
SENS,TapiSrv
Regsvc.exe 580 RemoteRegistry
Mstask.exe 596 Schedule
Snmp.exe 660 SNMP
Winmgmt.exe 728 WinMgmt
Explorer.exe 812 N/A
Cmd.exe 1300 N/A
Tasklist.exe 1144 N/A
The registry setting for the two groupings for this example are as follows: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost:
Netsvcs: Reg_Multi_SZ: EventSystem Ias Iprip Irmon Netman Nwsapagent Rasauto Rasman Remoteaccess SENS Sharedaccess Tapisrv Ntmssvc
RApcss :Reg_Multi_SZ: RpcSs

Jun 18, 2009 | Microsoft Windows XP Professional for PC

1 Answer

Svchost.exe boot up problem


Virus worm...get a good antivirus not a trial version

Try this

Your files must be un-hidden (Files option)

Here is the site that will help you

http://www.plumchoice.com/tempfiles5.html

Feb 27, 2009 | Microsoft Windows XP Professional for PC

4 Answers

I have deleted svchost.exe from windows xp


To complete part one, follow these steps:
  1. Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer.
    Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted to do so.
  2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
  3. If you have a dual-boot or multiple-boot computer, select the installation that you want to access from the Recovery Console.
  4. When you are prompted to do so, type the Administrator password. If the administrator password is blank, just press ENTER.
  5. At the Recovery Console command prompt, type the following lines, pressing ENTER after you type each line: md tmp
    copy c:\windows\system32\config\system c:\windows\tmp\system.bak
    copy c:\windows\system32\config\software c:\windows\tmp\software.bak
    copy c:\windows\system32\config\sam c:\windows\tmp\sam.bak
    copy c:\windows\system32\config\security c:\windows\tmp\security.bak
    copy c:\windows\system32\config\default c:\windows\tmp\default.bak

    delete c:\windows\system32\config\system
    delete c:\windows\system32\config\software
    delete c:\windows\system32\config\sam
    delete c:\windows\system32\config\security
    delete c:\windows\system32\config\default

    copy c:\windows\repair\system c:\windows\system32\config\system
    copy c:\windows\repair\software c:\windows\system32\config\software
    copy c:\windows\repair\sam c:\windows\system32\config\sam
    copy c:\windows\repair\security c:\windows\system32\config\security
    copy c:\windows\repair\default c:\windows\system32\config\default
  6. Type exit to quit Recovery Console. Your computer will restart.

Dec 02, 2008 | Microsoft Windows XP Home Edition

1 Answer

Unknown file


In software Svchost.exe is a generic host process name for services that run from dynamic-link libraries (DLLs) within the Microsoft Windows operating system.
At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services permits better control and easier debugging, but it also causes some difficulty for end users wishing to see the memory usage or vendor legitimacy of individual services and processes. End users in Windows XP Professional (and derivatives, such as Windows Server 2003 and Windows XP Media Center Edition) can run the following command at the system prompt to get a breakdown:
tasklist /svc /fi "imagename eq svchost.exe" (NB: This command does not work in Windows XP Home.)
Due to being widespread among running processes, svchost.exe has long been a common disguise used by malware to hide its presence from the user. (One of the common trojan horses deceptively uses scvhost.exe). Users may then run tasklist with no arguments and match the reported PIDs with the previously shown Svchost instances. If memory usage appears abnormal, the user can look up the service names shown by their command on the internet to see if it is a known service or malware.
The Svchost.exe file is located in the %SystemRoot%\System32 folder. The main registry key involved at bootup is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost (values in this key will show the user at least a partial list of the actual processes behind instances of svchost).
The 30 April, 2007 release of WSUS 3.0 led to reports of svchost.exe issues, including 100% CPU usage, memory hogging, and excessive laptop fan/power usage.[1]

[edit] See also

Oct 29, 2008 | Microsoft Windows Server Standard 2003 for...

1 Answer

Svchost


"Svchost.exe" (Generic Host Process for Win32 Services) is an integral part of Windows OS. It cannot be stopped or restarted manually. It manages 32-bit DLLs and other services. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. In normal conditions multiple instances of Svchost.exe run at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging. The svchost.exe file is located in the folder C:\Windows\System32. In other cases, svchost.exe is a virus, spyware, trojan or worm! To detect if it's a virus sometimes it will add letters to the Svchost to read thus SSVCHOST or SVCCHOST or something like that, thus making multiple services to run and slow down the computer, if that is the case the current antivirus you are using is not removing the virus, this can be done in the registry, its a complicated process if you do not know how to do it, so i would suggest you purchase a registry cleaner. NOTE: remember to backup the registry before you clean it

Aug 15, 2008 | Microsoft Windows XP Professional

3 Answers

Svchost.exe


Go to start>all programmes>accesories>system tools>system restore and restore the pc to a date before you deleted the file

Nov 01, 2007 | Microsoft Windows XP Professional for PC

2 Answers

Windows cannot Find SCVHOST.exe.


Boot from your Windows XP disk and use recovery console, follow the onscreen stuff and put the admin password in that you setup when you installed windows, you should now be at a prompt EXAMPLE: C:\WINDOWS>

At the end of the prompt type: cd F:\I386
F is the letter of the drive where your XP disk is so you will need to change it to your drive letter. The prompt should now be F:\I386>

After the prompt type: Expand svchost.ex_ C:\windows\system32
C is the letter of you HD were windows XP is installed, needs to be changed accordingly. At the prompt type: exit
Your sytem will re-boot and you will now have a copy of svchost.exe in your system32 folder again.

If you have found this solution helpful please rate it as Solved, otherwise please ask again.

Thank you

Nov 01, 2007 | Microsoft Windows XP Professional for PC

Not finding what you are looking for?
Microsoft Windows XP Home Edition Logo

308 people viewed this question

Ask a Question

Usually answered in minutes!

Top Microsoft Operating Systems Experts

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

Scott Fryer

Level 2 Expert

80 Answers

Carlos L. Burgos
Carlos L. Burgos

Level 2 Expert

508 Answers

Are you a Microsoft Operating System Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...