Вы находитесь на странице: 1из 2

Is your personal computers performance wasnt good today? Or are you familiar with scvhost.exe, svchost.exe virus?

Sometimes this virus used a name of a system files running to your computer. It will hide or replace the original system file that cause of a windows system performance malfunctioning. What is SVCHOST.EXE? In Windows XP, svchost.exe is a generic host process name for services that run from dynamic-link libraries (DLLs). This a system file of your windows that runs automatically when your windows is loading on and use to communicate the DLLs. What is SCVHOST.EXE or SCVHOSTS.EXE? If you have this file running into your computer, these executable files are virus. Scvhost.exe or Scvhosts.exe are virus called W32/YahLover.Worm.gen as detected by McAfee and Win32/Autorun.R.worm for NOD32 Antivirus. If you have this virus running in your computer please remove it immediately. This are very harmful that might cause a data lost and system malfunctioning. This viruses are set in hidden attributes that may occur in your system drive or a removable disk drive (USB). In a removable drive, simply open and check by using the RUN at start menu or pressing Window + R key in your keyboard and type the location of the removable drive (ex: D:, E:, F:) and enable your Folder Options to show hidden files setting. What are the Symptoms of SCVHOST.EXE or SCVHOSTS.EXE Virus? We must what are the symptoms of this SCVHOST.EXE virus or SCVHOSTS.EXE virus so that we can figured out if our computer are infected with this kind of virus.

Task Manager is not working (when pressing the Ctrl+Alt+Delete) Registry Editor is not working (the REGEDIT) Folders and sub folders become and executable file .EXE some of your folders and sub folders are now change into a .EXE executable file. It will change your folders(not all folders) into a .EXE and hide your original folders and copy the its filename. It also duplicate folders and sub folders.

Solutions on How to Remove SCVHOST.EXE Virus or SCVHOSTS.EXE Virus: Heres some procedure on how you remove scvhost.exe virus manually into your computer without using any antivirus installed in your system. You may use it this procedure with your own risk. 1. Restart your PC and quick go to Safe Mode by pressing the F8 function of your keyboard. 2. On the Safe Mode, log on as a Administrator account. 3. Go to your command prompt by typing CMD in your Run

In your command prompt: Type ATTRIB -H -R -S SCVHOST.EXE Type ATTRIB -H -R -S SCVHOSTS.EXE.EXE Type ATTRIB -H -R -S AUTORUN.INI Type DEL SCVHOST.EXE Type DEL SCVHOSTS.EXE Type DEL AUTORUN.INI Type CD\ Type ATTRIB -H -R -S AUTORUN.INF Type DEL AUTORUN.INFType cd C:\windows\system32 Type dir /ah, to display all hidden files on this directory folder. You will see the following files which is used by the virus to spread itself: AUTORUN.INI, SCVHOSTS.EXE, BLASTCLNNN.EXE, and SCVHOST.EXE. Restart and go to Registry Editor, if your REGEDIT is not working try to run Local Group Policy Editor by pressing window + R and type gpedit.msc then hit Enter, the Group Policy Editor will appear and disable the Prevent the access to registry editing tools on the User Configuration > Administrative Templates > System > Prevent the access to registry editing tools disable it. After that go to regedit and run again and locate the following entry but before doing this make sure to have backup of your registry. Try this on your own risk. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, if you see an entry Yahoo! Messengger (its spelled like this) with a value c:\windows\system32\scvhost.exe, Delete this entry. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, in the entry named: SHELL, a value = Explorer.exe,SCVHOST.EXE. Edit this value, delete the SCVHOST.EXE only and the value must be Explorer.exe. Once you delete all this value, your computer will not login anymore. Restart you PC and smile, and say goodbye virus! For a better security, it is must to used an updated Antivirus in your PC. Hope I helped you guys! For your request and concern regarding this issue, please leave me a comment below. Thank you and have a nice day!