Re: Effective Solution to Remove Virus in SCVHOST.EXE

From: Malke (malke_at_nospoonnotreally.com)
Date: 01/04/05


Date: Tue, 04 Jan 2005 06:25:44 -0800

it_exprt wrote:

>
> Maybe you should search through the registry and delete the tags that
> have the virus name under SVCHOST.EXE.
>

I really hope you don't think this is expert advice. In addition, please
quote at least something of the original post for clarity.

To the OP, it is totally possible to remove the scvhost malware. You
said, "I have downloaded many different virus scan and cleaning
software from the net, however, these products cannot clean the above
virus in my computer", but you didn't say exactly what you've done.

Start by using TrendMicro's Sysclean program, as follows:

TrendMicro's Sysclean is an extensive antivirus tool which has the
advantage of not needing to be installed. It requires two parts - the
scanning engine and the virus pattern files.

1. Create a new folder on your Desktop or the C: drive named something
useful like "Sysclean".
2. Go here and download the two parts of the program to that folder:

http://www.trendmicro.com/download/dcs.asp - Sysclean
http://www.trendmicro.com/download/pattern.asp - virus pattern files

The pattern files will be zipped - extract them with your unzipper (like
WinZip) or if you have XP, you can just open the folder. You need to
put the extracted files in the Sysclean folder you made.

3. Restart your computer in Safe Mode. Get into Safe Mode by repeatedly
tapping the F8 key as the computer is starting up to get to the proper
menu.

4. Go to the Sysclean folder you made and double-click on sysclean.com.
Start the scan. After the scan is finished, look at the log. You may
need to make a note of where any viruses were found if they were not
able to be removed so you can manually delete them.

Now you should be able to install a full-featured antivirus (if you
don't already have one). In either case, update the virus definitions
and return to Safe Mode. Do a full system scan.

If you are running Windows ME or XP, you should disable/enable System
Restore because malware will be in the Restore Points. With ME, you
must disable System Restore completely. With XP, you can delete all but
the most recent (presumably clean) System Restore point from the More
Options section of Disk Cleanup (Run>cleanmgr).

If after you have tried these things you are still unable to clean your
computer, take the machine to a good local professional (not a BestBuy
or CompUSA type of store). The professional will be able to put your
computer right.

Malke

-- 
MS MVP - Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"


Relevant Pages

  • Re: virus problem
    ... > prompts me to this virus but cannot delete it. ... *not* contained only in System Restore points. ... Mode with TrendMicro's Sysclean: ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Accessing "c:system volume information...
    ... >I downloaded a virus, ... > Access is denied when I navigate to that folder. ... temporarily disable system restore, then using windows explorer, unhide ... folder, select Properties, security tab, press Advanced button. ...
    (microsoft.public.windowsxp.general)
  • Re: Taskmgr Virus
    ... There are anti virus News Groups specifically for this type of discussion. ... Dump the contents of the IE Temporary Internet Folder cache ... Download SYSCLEAN.COM and place it in that directory. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Virus writing to _restore emp
    ... > you've got a virus it too late to load the anti-viral program. ... Sysclean from a known-clean computer that has never been connected to ... Create a new folder on your Desktop or the C: ... connecting to the Internet on the infected machine it would be better), ...
    (microsoft.public.security)
  • Re: Run-Msconfig and Run-Regedit
    ... TrendMicro's Sysclean is an extensive antivirus tool which has the ... scanning engine and the virus pattern files. ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.general)

Quantcast