hello guys,
unsaon pagtangtang kini na virus?"scvhost.exe"windows cannot fine'scvhost.exe'.
make sure you typed the name correctly, and then try again.
help me pls..
ako nmn giscan ug avg, nod32
pero la japon na tangtang.
help me..
thnx.
hello guys,
unsaon pagtangtang kini na virus?"scvhost.exe"windows cannot fine'scvhost.exe'.
make sure you typed the name correctly, and then try again.
help me pls..
ako nmn giscan ug avg, nod32
pero la japon na tangtang.
help me..
thnx.
na-delete na ang virus ana bro. ang imo lang buhaton ay tang-tangon nimo sa registry sa startup kana na value. you can use hijackthis.
Originally Posted by jouho
the virus made a script inside your windows shell in the registry that is why everytime you something or in boot mode, that warning sign will show up.
(if shows on post boot usage) though this is very risky and can kill your system in instant if mishaps shall happen, do this at your own risk:
- enter the registry, find that scvhost.exe and delete the script of which string it combines, this is usually in windows shell string value.
asa nko makita sa registry brod?
have a gud day!
ang windows nimu nawala iya sscvhost.exe, google or yahoo it up, and put the error message u will get your solution.
start>run>regedit>press enterOriginally Posted by jouho
start>run>regedit>press enter
asa banda nko xa edelete sa registry?
hkey_local_machine...blah..blah..blah..
To remove the virus manually, (try this it works with my computer but if you can’t try using an ANTI-VIRUS like McAfee or NOD32):
Boot your system in Safe Mode Command Prompt Only (Press F8 when your computer restarts, a menu will be shown and select the option)
After you log-in the command prompt will be opened (LOG-IN AS ADMINISTRATOR).
Type CD C:\WINDOWS\SYSTEM32 (assuming that your Windows System files are located at Drive C)
Type DIR /AH, this will display all hidden files of this folder. You will see the following file which is used by the virus to spread itself: AUTORUN.INI, BLASTCLNNN.EXE, and SCVHOST.EXE
Type ATTRIB -H -R -S SCVHOST.EXE
Type ATTRIB -H -R -S BLASTCLNNN.EXE
Type ATTRIB -H -R -S AUTORUN.INI
Type DEL SCVHOST.EXE
Type DEL BLASTCLNNNN.EXE
Type DEL AUTORUN.INI
Type CD\
Type ATTRIB -H -R -S AUTORUN.INF
Type DEL AUTORUN.INF
After removing the virus/worm files, it should be removed from the registry of your system.
From the command prompt type REGEDIT.EXE this will run the Registry Editor
From the registry, look for the key: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run, you will see an entry Yahoo! Messengger (it’s spelled like this) with a value c:\windows\system32\scvhost.exe, Delete this entry.
Look again for the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, there’s an entry named: SHELL, it has a value = Explorer.exe SCVHOST.EXE , don’t delete this entry!!! Just edit this entry and REMOVE the SCVHOST.EXE so that Explorer.exe will be the only value that will remain from this registry entry.
Removal instructions for scvhost.worm:
Overview
Scvhost.worm spreads over Windows network shares. The worm's main file is called scvhost.exe, trying to mimic the legitimate svchost.exe file is located in %SystemDir%. Note: Do not delete %SystemDir%\svchost.exe.
Note: %SystemDir% is a variable (?). By default, this is C:\Windows\System (Windows 95/98/Me), C:\WINNT\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP). Manual removal
Please follow the instructions below if you would like to remove Scvhost.worm manually. Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If Scvhost.worm remains on your system after stepping through the removal instructions, please double-check by stepping through them again.
Start your computer in safe mode.
Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run'
In the right pane, delete the value called 'Config Loader', if it exists.
Browse to the key:
'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ RunServices'
In the right pane, delete the value called 'Config Loader', if it exists.
Exit the registry editor.
Restart your computer.
Start Windows Explorer and delete:
%SystemDir%\scvhost.exe
Note: %SystemDir% is a variable (?). By default, this is C:\Windows\System (Windows 95/98/Me), C:\WINNT\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
Type:
Worm
Executables:
scvhost.exe
ako advice pag try ug Kaspersky Anti-virus then full system scan.
pero trial rana cya 30 days. kkk..
Similar Threads |
|