welcome

welcome to my destiny :)
I'm just a guy who is smile a lot
and the god give me a power
-------------------------------------------

You say anything Just tell me all your sweet lies

-------------------------------------------------

Time may change my life
But my heart remains the same to you
Time may change your heart
My love for you never changes

Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Monday, September 7, 2009

Registry Editing has been disabled by your administrator

Removing the DisableRegistryTools restriction

For standalone Windows XP systems, perform the steps below to remove the registry editing restrictions.

Method 1: Using the REG.EXE console tool

1. Click Start, Run and type this command:

You should be able to launch Tweak UI, as well as the Registry Editor.

Method 2: Using the Group Policy Editor (Windows XP Professional only)

  • Click Start, Run and type gpedit.msc and press ENTER
  • Go to the following location:

User Configuration | Administrative Templates | System

  • Double-click Disable registry editing tools and set it to Not Configured
  • Or Prevent access to registry editing tools and set it to Not Configured
  • Exit the Group Policy Editor
http://windowsxp.mvps.org/tweakuirest.htm

Thursday, August 20, 2009

Avira AntiVir Premium 2009 9.0.0.420 + 3 Year Licence torrent

Avira AntiVir Premium 2009 9.0.0.420 + 3 Year Licence



Avira AntiVir Premium reliably protects you against all threats from viruses, worms, trojans, rootkits, phishings, adware, spyware, bots, and dangerous “drive-by” downloads. Best detection rates and top-class security with several updates every day.
Advanced protection: Includes basic antivirus protection PLUS: email protection (POP3) , AntiPhishing, AntiSpyware, AntiAdware and more.
With real-time on-access scanning, profile-based on-demand scans and scheduling of full system scanning and updates it offers premium protection. It includes a POP3 based MailScanner that scans emails before they are stored on your machine. With a user-friendly control center, quarantine management, fast performance and world leading detection rates the Avira AntiVir Premium provides essential protection for your PC.

AntiVir Personal offers effective protection against computer viruses for the individual and private use on a single PC-workstation. It detects and removes viruses and includes an Internet-Update Wizard for easy updating. The built in resident Virus Guard serves to monitor file movements automatically, for example when downloading files from the internet. Heuristic scanning protects Protection against previously unknown macro viruses. Even though viruses have now grown very numerous, one thing hasn't changed: our commitment to provide you with all-round protection. The reliability of AntiVir is demonstrated in numerous comparison test and references featured in independent trade journals.

Premium Protection:

* AntiVir
* AntiAd/Spyware
* AntiPhishing
* AntiRootkit
* AntiDrive-by
* AntiBot
* EmailScanner
* WebGuard
* RescueSystem

Premium functions:

• Protection against viruses, worms and Trojans
• Protection against expensive dialers
• Detects and deletes rootkits
• NEW: Raised scan speed
• NEW: Redesigned visual appearance
• Protection against phishing
• Protection against spyware
• Special protection against email viruses (POP 3)
• Fast updates through Premium Server
• 5 Euro donation to Auerbach Foundation
• Protection against annoying adware
• NEW: System to create a Rescue-CD


Avira's Homepage :
http://www.free-av.com/

- Scanned with KIS 7 ; It's virus free

Instructions :

1. Unpack
2. Install
3. Use key when asked for activition
4. Enjoy!

download torrent

http://extratorrent.com/torrent_download/1870232/Avira+AntiVir+Premium+2009+9.0.0.420+%2B+3+Year+Licence+h33t+-+CaZoR.torrent

http://www.h33t.com/details.php?id=5f9aeb55ba20051175ae3432fee041912511f522

Thursday, August 13, 2009

Avira AntiVir Premium 2009 V9.0.0.420 License key for 2015



Avira AntiVir Premium 2009 V9.0.0.420 License Till 2015 | 30.1 MB

ใช้ได้6ปีเต็มๆๆ ระดับ premium




Avira AntiVir Premium reliably protects you against all threats from viruses, worms, trojans, rootkits, phishings, adware, spyware, bots, and dangerous “drive-by” downloads. Best detection rates and top-class security with several updates every day.

Advanced protection: Includes basic antivirus protection PLUS: email protection (POP3) , AntiPhishing, AntiSpyware, AntiAdware and more.
With real-time on-access scanning, profile-based on-demand scans and scheduling of full system scanning and updates it offers premium protection. It includes a POP3 based MailScanner that scans emails before they are stored on your machine. With a user-friendly control center, quarantine management, fast performance and world leading detection rates the Avira AntiVir Premium provides essential protection for your PC.

AntiVir Personal offers effective protection against computer viruses for the individual and private use on a single PC-workstation. It detects and removes viruses and includes an Internet-Update Wizard for easy updating. The built in resident Virus Guard serves to monitor file movements automatically, for example when downloading files from the internet. Heuristic scanning protects Protection against previously unknown macro viruses. Even though viruses have now grown very numerous, one thing hasn’t changed: our commitment to provide you with all-round protection. The reliability of AntiVir is demonstrated in numerous comparison test and references featured in independent trade journals.

Premium Protection:
* AntiVir
* AntiAd/Spyware
* AntiPhishing
* AntiRootkit
* AntiDrive-by
* AntiBot
* EmailScanner
* WebGuard
* RescueSystem

Premium functions:
• Protection against viruses, worms and Trojans
• Protection against expensive dialers
• Detects and deletes rootkits
• NEW: Raised scan speed
• NEW: Redesigned visual appearance
• Protection against phishing
• Protection against spyware
• Special protection against email viruses (POP 3)
• Fast updates through Premium Server
• 5 Euro donation to Auerbach Foundation
• Protection against annoying adware
• NEW: System to create a Rescue-CD

Download
http://rapidshare.com/files/220777731/Avira_AntiVir_Premium_2009_V9.0.0.420.rar

http://board.yimwhan.com/show.php?user=not2527&Cate=16&topic=1

Monday, September 8, 2008

Restore Folder Hidden

how to Restore hidden Folder
the folder has been hidden by virus
and can't restore
so i got this program can make the folder restore unhidden folder
this application made by lao

you can download below
hope it work and help you !!!



ເປັນອີກບັນຫາໜຶ່ງທີ່ເຈີກັນເລື້ອຍອັນເນື່ອງຍ້ອນ
ຈາກໄວລາດມັນເຮັດມັນເຊື່ອງໂຟນເດີ້ແລະ
ບໍ່ສາມາດແປງໃຫ້ກັບມາຄືນະພາບ
ເດີມໄດ້
ອັນນີ້ແມ່ນໂປແກມ Restore Folder Hidden ທີ່ຈະເຮັດໃຫ້ Folder ບໍ່ຖືກ Hidden ຂອງຄົນລາວນິລະທົດລອງໃຊ້ເບິ່ງ






ດາວໂຫລດໄດ້ທີ່ນີ້


Wednesday, September 3, 2008

how to remove fullhouse Drive

it's easy to remove or kill Virus Full house Drive
you just download and Click Remove
that's all

how to kill full house virus
run the program and remove
trust me !!!!!!

ບັນຫາມີຢູ່ບ່ອນວ່າໃນຊ່ວງນີ້ໄວລັສສາຍພັນນີ້ ລະບາດກັນໜັກຕິດກັນໄປທາງ Flash Drive
ສິ່ງທີ່ໄດ້ມາແມ່ນ Virus Full House Drive ເປັນຜົນງານໃໝ່ຂອງ Full House ເພາະວ່າແຕ່ກ່ອນຈະເປັນ
Full House Folder ມາຮອດມື້ນີ້ມັນພັດທະນາໄປອີກກ້າວໜຶ່ງ ເລີຍເອົາວິທີຈັດການງ່າຍໆ ຄື Anti Virus
lao

ທີ່ເຮັດຈາກ ຄົນລາວນິລະ ດາວໂຫລດໄດ້ທີ່
























ຫວັງວ່າຄົງຊ່ວຍເນາະ
ສາດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດດ ຟູຮາວ

Wednesday, August 27, 2008

แก้ไขไวรัส"SCVHOST.exe"




SCVHOST.exe
มันจะปิดระบบต่าง ๆ ที่เกี่ยวข้องกับการ ปรับแต่งของวินโดว์ หรือ ปิดระบบการทำงานในระดับ Administrator ครับ.. และออกแม่แพร่พันธุ ในเครื่องเรา โดยสร้างไฟล์ ไอคอนรูป Folder ที่มีสกุลเป็น .exe ในเครื่อง นอกจากนั้นยังฝังตัวเองไปกับ Handy Drives พร้อมกับไฟล์ Autorun.ini และ New Folder.exe เพื่อขยายพันธุไปเครื่องอื่น ๆ ต่อไป แหมครับแบบนี้มันแน่มากครับ ไอ้คนทำมันแสบจริง ๆ นะครับ..

เอ้ารู้วิธีการทำงานมันแล้วมาดูวิธีแก้บ้าง...
วิธีแก้ใขก็มีครับ แต่ขั้นตอนนั้นเยอะมาก ๆ ผมเลยหาเครื่องทุ่นแรงมาไว้ช้วยโดยต้องมี สิ่งเหล่านี้ก่อนเอาไว้เชือดมันแบบไม่ให้กลับมาสร้างความรำคาญให้เราอีกต่อ ไปเลยครับ

1. โปรแกรม Taskmanager16 เป็นรู้ทดลองใช้ครับแต่ใช้ได้เหมือนกัน มีหน้าที่ตรวจสอบว่ามีโปรแกรมใดที่รันอยู่ในระบบวินโดว์ของเราบ้าง
2. โปรแกรม NOD32RegistryRecovery ชื่อก็บอกครับว่าเป็นตัวที่ใช้คืนค่าให้กับระบบ อย่างที่บอกไปครับเจ้า SCVHOST.exe มันจะไปปิดระบบต่าง ๆ ในวินโดว์ของเรา เจ้าตัวนี้ซึ่งเป็นชุด Service ของ NOD32 จะช่วยให้เราไม่ต้องลำบอกไปตามแก้ Register ของวินโดว์ที่โดนแก้ไข หรือถุกปิดไปโดยเจ้าไวรัสนี้
3. AVG Anti-Virus ครับเป็นตัวฟรี จริง ๆ แล้วจะเป็น Anti virus ตัวอื่นก็ได้ครับขอให้ Update ฐานข้อมูลไวรัสได้ตลอดก็ OK แล้วครับ ที่เลือกตัวนี้เพราะ Update ได้ทุกวันเลยฟรีด้วย ถึงฟังชั่นจะไม่ครบ แต่ก็ใช้ได้ดีกับการฆ่าไวรัสแบบ Worm ครับ.
4. อีดตัวสุดและสุดท่าย เป็นด่านแรกเลย หรือเรียกว่าคุณ รปภ. ก็ได้ครับนั้นคือ ARDV102 (Anti Removable Disk Virus เวอร์ชั่น 1.02)ทำหน้าที่ตรวจจับไฟล์ที่น่าสงสัยเมื่อมีการเชื่อต่ออุปกรณ์ประเภทต่าง ๆ ฝ่านท่าง port USB. ถึงแม้จะฆ่าได้บ้างไม่ได้บ้าง แ่ต่เราก็รู้ว่า ไอ้ที่เสียบเข้าไปที่ USB. Evil or Very Mad นะมันมาแว้ววววววววว...... Twisted Evil ถ้าฆ่าไม่ได้หรือไม่แน่ใจ คุณ รปภ. ARDV เข้าก็จะย้ายไฟล์ดังกล้าวไปไว้ที่โฟล์เดอร์ ชื่อขึ้นต้นด้วย ardv_ ก็ไม่ต้องตกใจครับ เพราะเมื่อโดยย้ายแบบนี้มันก็ทำงานไม่ได้ครับ..

หลังจากอาวุธครบมือแล้วมาดู ขั้นตอนกันครับ

1. ติดตั้งโปรแกรม Taskmanager16 แล้วรันโปรแกรมขึ้นมา ในรายการจะเห็นไฟล์ชื่อ SCVHOST.exe หรือ SCVVHOST.exe หรือ SVVCHOST.exe ทำนองนี้ครับให้เลือกแล้ว กดปุ่ม Delete ที่แป้นพิมพ์ได้เลย แต่ต้องดูดี ๆ นะครับ ถ้าเป็นไฟล์ svchost.exe นะลบไม่ได้ ย้ำนะครับว้า svchost.exe นะลบไม่ไ้ด้มันเป็นไฟล์จริง ๆ ของวินโดว์ไม่ใช่ไวรัส เมื่อกด Delete ที่แป้นพิมพ์แล้วให้ตอบ Yes จนไฟล์ดังกล้าวหมดไปครับ จากนั้นทำการย่อหน้าต่างโปรแกรม Taskmanager ลงไม่ต้องปิดนะครับ
2. สั่งรันไฟล์ NOD32 Registry Recovery.exe ครับ คลิกที่ 'I Agree' แล้วติ๊กเครื่องหมายถูกหน้าหัวข้อสุดท้า่ย 'Scan and Clear with NOD32' ให้หายไป แล้วคลิกที่ปุ่ม 'Do it now' โปรแกรมจะทำการ คืนค่าต่าง ๆ ที่ไวรัสมันแก้ไขไว้ให้กลับมาเหมือนเดิม ถ้าในระหว่างทำงานโปรแกรมแสดงหรือให้คลิกอะไรก็คลิก 'ใช่' ไปเลยครับพอเสร็จแล้วก็ 'Close' หน้าต่างลง
3. หลังจากนี้ถือว่าเรามีเอกราชไปกว่าครึ่งแล้วครับ เหมือนกับว่าเรายึดป้อมปืนใหญ่ของฝ่ายตรงข้ามได้เพราะเราจะสามารถทำงานใน โหมดคำสั่งของ Administrator ได้แล้ว เป็นทีเราบ้างแล้วครัีบ
4. เมื่อทำงานในโหมดคำสั่งของ Administrator ได้ให้เราไปที่ Start --> Run.. จะขึ้นหน้าต่างโปรแกรม Run ขึ้นมาให้พิมพ์คำสัี่ง regedit ในช่อง Open:
5. ไปที่เมนู Edit --> Find.. แล้วพิมพ์ค้นหาไฟล์ชื่อ SCVHOST.exe หรือไฟล์ต่าง ๆ ที่เราปิดไปในขั้นตอนที่ 1. เมื่อพบไฟล์ดังกล้าวก็ให้ลบออกไปโดยกดปุ่ม Delete บนแป้นพิมพ์ แล้วตอบ Yes กด F3 เพื่อค้นหาอีกเมื่อเจอก็ให้ลบไปเรื่อย ๆ จนโปรแกรมค้นหาบอกว่า ไม่เจอไฟล์ที่คนหาแล้ว ลบให้หมดนะครับ ไม่ว่าจะเป็น SCVHOST.exe หรือ SCVVHOST.exe หรือ SVVCHOST.exe ชื่อแปลก ๆ ประมาณนี้ที่เราปิดมันไป ลบมันให้หมดเพราะตอนนี้มันทำไรเราไม่ได้แล้ว แต่ถ้าปล่อยมันไว้แล้ว คุณจะเสียใจและเสียน้ำตาถ้าหากว่าเปิดคอมครั้งต่อไปแล้วมันเข้าวินโดว์ไม่ ได้ นะครับขอบอก
6. ทำตามขั้นตอนที่ 2 อีกครั้งครับ คราวนี้มันจะไม่ฟ้องให้ตอบ Yes / No อีกแล้ว.. และก็หมายความว่า มันถูกลบการทำงานออกไปจากระบบเรียบร้อยแล้ว แต่อย่างพึ่งดีใจนะครับ ต้องทำอีก หลายขั้นตอนอยู่ เพื่อให้มันหายไปจากเครื่องเราจริง ๆ
7. เข้าไปที่ c:/windows และหาดูไฟล์ที่ชื่อ SCVHOST.exe และ Autoexec.ini แล้วลบมันโดย กด Shift + Delete จากนั้นเข้าไปที่ C:/windows/system32/ มองหาไฟล์ที่ชื่อ SCVHOST.exe และ Autoexec.ini แล้วลบมันออกไปโดยกด Shift + Delete
8. ไปที่ Start --> Search ให้คนหาไฟล์ *.exe ใน My Computer จากนั้นให้ลบไฟล์ที่มี Icon เป็นรูป Folder ที่มีสกุลเป็น .exe ให้หมดโดยกด Shift+Delete อย่างหลงเปิดมันะครับ ไม่งั้นคุณต้องเริ่มใหม่ทั้งหมด ต้องระมัดระวังเป็นอย่างมากเพราะผมเคยไปหลง ดับเบิลคลิกมัน เซงสุด ๆ เพราะไอ้พวกนี้เป็นเหมือน บริวารผู้จงรักภักดี พอดับเบิลคลิกปุ๊บ เจ้าตัวโป่ใหญ่มันก็ทำการคืนชีพกลับมาครอบครองระบบของเราใหม่ ผมต้องเริ่มทำใหม่หมดเลยตั้งแต่ขั้นตอนตแรก เซงสุด ๆ Confused
8. จากนั้นให้ไปที่ Start --> Run.. แล้วพิมพ์ msconfig จะมีหน้าต่างของ System Configurtion Utility ขึ้นมา ไปที่แท็บ Startup ดู Item ที่ชื่อ SCVHOST.exe ถ้ามีให้เอาเครื่องหมายถูกออก แล้วก็ OK ไม่ต้อง Restart นะครับเลือกที่ Exit Without Restart ครับ
9. ลงโปรแกรม AVG Anti-Virus อย่างลืม Update ด้วยนะครับ เลือกที่ Check for Update เลื่อย ๆ จน สถานะของโปรแกรมขึ้นเป็นสีเขียว มันให้ Up อะไรก็ Up ให้หมดเลยนะครับ เพราะเป็นของฟรี ใครชอบของฟรี ๆ ก็ดีตอนนี้ละครับ
10. ลงโปรแกรม ARDV102 เสร็จก็ Restart เป็นอันเสร็จครับ

รับรองได้ ทำตามนี้ แล้วจะรุ่งนะครับ... มันจะไม่กลับมารบกวนเราอีก นอกจากว่า มันจะมากับ Handy Drives ซึ่งก็ยากส์.... เพราะเรามี ARDV102 คอยดักรอตีหัวมันอยู่ "ถึงมันไม่ตาย แต่ก็ไม่โต" อย่างที่โบราณว่าไวครับ...

Source

http://www.lookdee.com/webboard1/viewtopic.php?p=16

Monday, August 25, 2008

How to recover system32\win.exe and windows\inf\other.exe

win.exe and other.exe are not files of windows or office. Those are viruses or spyware.

select Start>Run and type msconfig. goto startup items. uncheck strings if then load win.exe or other.exe. restart and delete those files.

or try to get a good antivirus


Both those exe files seem to be virus because neither Windows nor MS Office contains such files. Try using an antivirus like AVG Free Edition or Lavasoft AdAware 2007 Personal

Saturday, August 9, 2008

How to Fix svchost.exe using 100% CPU / Memory Leak

How to Fix svchost.exe using 100% CPU / Memory Leak

As a computer technician, here is a problem I have been coming across more and more. About 30secs to 1 minute after booting into Windows the computer starts lagging heavily. When CTRL+ALT+DEL is pressed it shows that svchost.exe is using up maximum CPU resources and only occurs when Automatic Updates is enabled. Microsoft has recognized this problem and has released a patch. However, on all computers I have worked on with this problem, the Microsoft patches don’t fix the problem. This is a guide on how to fix this problem with svchost using maximum CPU.

First of all, to identify if you have this problem you need to press CTRL+ALT+DEL all at the same time, go to the “Processes Tab” and then press “Mem Usage”. If you have this svchost.exe memory leak bug after about 1 minute you will see that the amount of memory usage svchost.exe uses will keep increasing until CPU becomes 99 or 100%. Below is an example of what this looks like:

svchost.exe memory leak shown in Windows Task Manager


How to stop svchost.exe using up 100% system resources (Windows XP Only):

  • Visit the Microsoft website and Download Windows Update v3 WindowsUpdateAgent30-x86.exe and save it to your C:\ drive
  • Download this file fix_svchost.bat (right click and choose save as..) and save it to your C:\ drive
  • Download this file WindowsXP-KB927891.exe (right click and choose save as..) and save it to your C:\ drive
  • Reboot the computer and log in to Windows XP in safe mode. To do this, press F8 just before the WindowsXP logo shows up during boot and press up to choose “Safe Mode”
  • Once Windows has loaded and you have the option of which user account to use, log on as “Administrator”.
  • Click Start > Run, choose the Browse button and find the fix_svchost.bat file you saved before, press Open, then OK.
  • A black screen will pop up and white text will scroll past. Wait for this process to finish as it could take several minutes. It will close itself when its finished.
  • Once the black screen disappears, Click Start > Run, choose the Browse button and find the WindowsUpdateAgent30-x86.exe file you saved before, press Open, then OK. Follow the prompts as it installs.
  • When Windows Update Agent finishes installing, Click Start > Run, choose the Browse button and find the WindowsXP-KB927891.exe file you saved before, press Open, then OK. Follow the prompts as it installs.
  • Reboot the computer

How to remove “scvhost.exe - New Folder.exe - AutoRun.inf” virus?

How to remove “scvhost.exe - New Folder.exe - AutoRun.inf” virus? (Broken link fixed)

Just this night I got a good mood after I fixed the "scvhost.exe - New Folder.exe - AutoRun.inf" virus in Windows XP. But of course, before I was able to fix it, I did have a damn whole bad day. What about this virus (or Worm, Trojan, Spyware?) anyway, and how it pissed me off really bad? Well, though I can just give you the details about my experience while this was running on my PC, I’m not really an expert when it comes to virus thingy. Anyway, here are the details:

The first thing you would experience is that your Task Manager will be disabled. It will prompt, "Task Manager has been disabled by your Administrator." Of course, obviously, this gives you a clue that the virus prohibits the user to end its process. But not just that, when you try to open your Registry through "Regedit", it will also prompt that your Registry has also been disabled. Later, as it progresses in the long run, you will soon find out that it automatically closes some opened windows application. The worse, even the "Command Prompt" and "Folder Options" won’t be accessed anymore. You can even experience that the "Accessories" on your Start Menu will be gone. Therefore, you cannot access your Command Prompt unless you would directly run it through your system32 folder. Just stressing this out, if you’re thinking that you can still access "Command Prompt" using your "Run" command, nope… The same parasite will disable some of your keystrokes. Meaning, you won’t be able to type anything. Simply, almost all the possible means of knowing the tasks running (since you can also view a list of tasks using Command Prompt then tasklist.exe) has been blocked.

Funny to say but I had a rather, logical means of trying to solve this. Since I cannot open "cmd" or "Command Prompt", I thought of "gpedit.msc" to somehow re-enable my "Task Manager". Well, what I did was to open my "Run" command. I didn’t type anything since I knew I couldn’t type anything at all. So, I was beginning searching for characters which I can copy to my clipboard and paste to my "Run". Got the view? Literally, I was copy-pasting characters until I spell out the word "gpedit.msc". Hehehehe… I did open my gpedit, but unlicky, this still wasn’t able to solve the problem. The "gpedit.msc" window appeared only for a second, and it closed immediately.

I couldn’t find anymore ways, but finally, I thought of a program created in VB which I used before to stop a Spyware from running. Thanks to "Visual Basic Beginner" from PSCode.com. He created a program which he called "The Terminator". Designed specifically to stop running applications even at the same time. Plus, it displays the exact location on where the running program is located. Also, I used a tool which can unlock restrictions, the "Remove Restrictions Tool (RRT)" from www.Sergiwa.com. I have compiled these two applications into one compressed folder which you can download here. And please don’t forget that the credits should be given to them. How were these applications able to help me?

Hmmm… Luckily, though the virus has the ability to close some opened window, but these applications weren’t part of those restricted by this virus. Strictly guys, you should do these when you already have those applications on your PC:

1. Run RRT and then press "Check All" then "Remove". By doing this, all the restrictions made by the virus should now be unlocked.

2. Access your Folder Options, in either in the Control Panel, or simply on one of the menus under "Tools" in any opened folder. Select "View" tab and "Show hidden files and folders".

3. You may not be able to fully access your Task Manager, so use "The Terminator" instead. Run "The Terminator" and check all the processess having the following descriptions:

  • Any running process having "scvhost" in it. Strictly, you should be able to notice carefully that it is "scvhost" and not "svchost". Since you might crash the PC if you accidentally end the "svchost" task.
  • If there is a task running with the file extension ".pif" then include it as part of the checklist to terminate.
  • There are certain processess in the list wherein as you notice in its location where it is running, the Filename is named the same as its folder where it is located. For example, "C:\Program Files\Games\Games.exe". As you notice, the "Games.exe" that is running is located to a folder name "Games", since the virus also creates replications named after its location. Include these processess in the list.

4. After checking all the necessary processess, then press "Terminate all checked processess".


After doing this, you may already notice that you can once again normally use your keyboard, access your task manager, command prompt and regedit, like you can before. But this doesn’t end here. You are still half way the progress. Next things you must do are the following:

1. Go to your My Computer. Right click on it and choose "Search". This time, we’ll search for those replications manually. Basically, we have to remove ALL of them. As I noticed, all replications have common characteristics. First, they are all executable files but categorized as an "Icon" file. It has an obvious icon the same as a "Folder" icon. You can easily notice it since it has a low resolution icon image. All of these replications have a common size at 221 kb.

2. Specify your searching options. Search for "All files and folders". Just leave "All or part of the file name" and "A word or phrase in the file" blank. Select "More advanced options". Check all options except for "Case sensitive" and "Search tape backup". Select the "What size is it?" option, and choose "specify size (in kb)", "at least 220 kb". Then begin searching by pressing the "Search" button.

3. As soon as searching is done, sort out all the found items according to size. Then highlight all items which are 221 kb in size, and file type is "ICON". They are actually executable files in which IF you accidentally open will result you to start again from the very beginning. So be careful not to double-click it. Delete all these files using "Shift+Delete" to permanently remove them.

4. If you are able to successfully remove all these files, then celebrate! Since you are almost done. The next one will be a bit more complicated. Go to your hard drives (if there are lots of partition then check all partitions). You may notice a file called "Autorun.inf". This is basically the reason why the heck when you open your hard drive it will ask you how to open it as if it is a file. So remove also these files. Also, go to your startup directories such as "C:\Documents and Settings\All Users\Start Menu\Programs\Startup" and other user startup directories for Documents. Delete the file AdobeGamma.pif (if there’s any) and the "Desktop.ini" file. I’m not totally sure but I think these files are unnecessary.

File removal: Done! Final step: Editing the Registry.

The easiest way to change back the Registry to normal is:

1. Open your "regedit" by typing in your "Run" command, "regedit" then press OK.

2. In your Registry Editor, go to "Edit | Find" or simply press "Ctrl+F". Type there "scvhost". Make sure all check boxes are checked.

3. Everything that is found using this search must either be deleted OR left blank. I assume you are already knowledgable enough whether what keys to delete and what to not. But if you do not know what you are trying to edit, then it’s better to change all strings having the "scvhost" string to blank. Be careful when you reach to a search wherein there is "C:\WINDOWS\explorer.exe scvhost.exe" or something like that. Just remove the "scvhost.exe". Don’t include "C:\WINDOWS\explorer.exe".

So, until you finally are able to find no more entries in the Registry about "scvhost" then Congratulations! Though I’m not really that sure if the virus has been completely removed but as I noticed, even if I already restarted the PC, I can already feel my PCs running smooth again.

If you have some comments or clarifications or perhaps additional information about this virus (?) please leave it here. I would be grateful to hear it out from you. Thanks! emoticon


all content by http://ronaldborla.blogsome.com/

LinkWithin

Related Posts Plugin for WordPress, Blogger...

Fm-radio-on-my-site

for you forever

Birthday - 13/12/1964 Death - 02/05/1997 bye bye hide

google analysis

ຊີວິດກໍ່ເໝືອນລະຄອນຕ່າງທີ່ບໍ່ສາດມາດຫຼິ້ນຄືນໃໝ່ໄດ້
ຊີວິດແມ່ນການສະແດງ ທີ່ບໍ່ມີຜູ້ກຳກັບ

online
Online Casino


website counter