How to Remove SCVHOST.EXE, SVCHOST.EXE Virus Manually
What is SCVHOST.EXE?
In some antivirus they are detected as W32/YahLover.Worm.gen from McAfee Antivirus and Win32/Autorun.R.worm from NOD32.
- When pressing Ctrl+Alt+Del it blocks to launch the Task Manager
- It blocks the Registry Editor.
- When you try to go to the command prompt CMD, it will restarts the computer.
- The shared folders will duplicates itself to different locations of. The duplicated virus uses a FOLDER icon with an .exe file extension. The configuration of your Yahoo Messenger has been changed.
OK here we go, you must follow this step on how to remove this virus in manually method:
- Restart your PC and press F8 and select the option Safe Mode Command Prompt Only
- And after you log-in the command prompt you must log-in as Administrator.
- Type cd C:\windows\system32
- Type dir /ah, to display all hidden files on this directory folder. You will see the following files which is used by the virus to spread itself: AUTORUN.INI, BLASTCLNNN.EXE, and SCVHOST.EXE
- Type ATTRIB -H -R -S SCVHOST.EXE
- Type ATTRIB -H -R -S BLASTCLNNN.EXE
- Type ATTRIB -H -R -S AUTORUN.INI
- Type DEL SCVHOST.EXE
- Type DEL BLASTCLNNNN.EXE
- Type DEL AUTORUN.INI
- Type CD\
- Type ATTRIB -H -R -S AUTORUN.INF
- Type DEL AUTORUN.INF
Go Start Menu and click the Run and type the REGEDIT command. Take note guys before make any changes into your Registry Editor you must make a full back-up to your registry to avoid system errors. :)
Look the location entry: