How to remove SCVHOST.exe (W32/YahLover.Worm.gen or Win32/Autorun.R.worm)
This virus/worm installs itself in autorun.inf and once double click it will spread itself unto your system. Furthermore, it copies itself through all the shared folders on your computers throughout the network and installs itself in the registry entries remotely.
Here are indication that your computer is infected with this virus.
* This virus/worm blocks the task manager
The worm changes the registry to prevent running task manager and editing registry for harder detection.
* It automatically restarts the computer when you try to go to the command prompt.
* It duplicates itself to different locations of the shared folders. The duplicated virus/worm uses a FOLDER icon with an .exe file extension. WARNING! DO NOT double click these folders.
* It autostart via registry keys Windows->Run and add itself to WinNT->WinLogon->Explorer.exe
How to remove the virus
You can use NOD32 or any strong antovirus programs to remove this virus but if you don’t have a anti-virus or your antivirus can’t remove this virus try following the steps below to remove it manually.
* Boot your system in Safe Mode Command Prompt Only
* After you log-in the command prompt will be opened (LOG-IN AS ADMINISTRATOR).
Post a Comment