There’s a strain of computer virus/worm that hide itself using the name SCVHOST.EXE or SCVHOSTS.EXE, (don’t mistaken it as SVCHOST.EXE, it’s one of the vital programs of Windows, see the difference in spelling). It was detected as W32/YahLover.Worm.gen of McAfee Antivirus and as Win32/Autorun.R.worm by NOD32. This virus infects your computer by different means.
Characteristic of the Virus
To remove the virus manually, (try this it works with my computer but if you can’t try using an ANTI-VIRUS like McAfee or NOD32):
After removing the virus/worm files, it should be removed from the registry of your system.
I’ve tried this steps and this works. You should try this if you’re only know how to edit registry entries. (try it at your own risk) Hope this will help you.
Technorati Tags: autorun.inf virus, yahlover virus
Hi,
thanks for your solution… but I’m also a filipino whose USB (with my PhD thesis work) has been affected by this WORM. Im not sure if my laptop got infected too. Though our anti-virus here said laptop files are not infected.
Can you help me please.
VA
Posted by VA at February 15, 2008, 3:09 pmimmanuel,
REGEDIT is usually located @ c:\windows so when you started on Safemode Command Prompt (the “Black Desktop”), type C:\WINDOWS\REGEDIT.EXE on the prompt then ENTER key. This will invoke REGISTRY EDITOR.
To restart your computer, type SHUTDOWN -R
Posted by bleuken at February 15, 2008, 6:24 pmVA, is your laptop connected to the internet, if not your anti-virus s not updated. What’s your antivirus?
you’ll know if ur infected if some of your programs will start then terminates / ends immediately. Another symptom is when u press CTRL+ALT+DEL combination the task manager closes or an error message displays.
Posted by bleuken at February 15, 2008, 6:28 pmThanks, Bleuken. Will try it again.
Posted by Immanuel Magalit at February 19, 2008, 9:01 amThanks a million for these instructions. I had a hard time getting rid of this virus on my wife’s laptop until I found these instructions.
I had to modify your approach somewhat - including following the steps you outline above when logged in as my wife as well as as Admininstrator, but your instructions gave me enough to go on.
In my case file scvhost.exe had also copied itself to the C:\windows directoy (as well as \System32). It was a hidden file there too.
If you have this virus you need to complete the unhide and file deletion steps before it’ll let you near the registry. It looks like the files may have variant names - you need to substitute the particular file name that’s appearing on your system into the instructions .
Thanks again for this - it was a big help to me.
Posted by Strombone at February 20, 2008, 9:02 amThanks much! I was able to remove the Virus using the steps you provided. Although I had to use a program called RRT because the virus prevented me from performing a registry edit. Thanks again!
Posted by kenny_cebu at March 12, 2008, 6:10 pmI will try this. happy to see this. on My laptop this virus does not allow me install any antivirus also. so can not clean it using the antivirus. let me try your way.
Posted by SP at March 13, 2008, 5:25 pmThanks Bleuken, but even after trying all the steps, I still find the scvhosts.exe running in the taskmgr.
Please help.
Posted by Mona at March 14, 2008, 7:16 pmmaybe you see svchost.exe instead, make sure w/ the spelling, svchost.exe is a window system file and not a virus.
Posted by bleuken at March 14, 2008, 8:51 pmtol!
Ano po ang meaning ng mga letran ito?
-H -R -S?
I’m pretty sure there is a meaning of each letter.
Just wondering, coz maybe one day someone will ask me about this H R & S thingy, lalo na kung chix, baka ndi ko masagot…hehehe..
Rubbish talk I have.
Anyways, thanks in advance
H R S stands for Hidden, Read-Only, System. they are attributes of file. -H -R -S parameter on attrib resets this attributes of a file. Type ATTRIB/? for detail of the command ATTRIB and the option -H -R -S.
Posted by bleuken at March 19, 2008, 7:39 amhow 2 use registry entries
Posted by mjwafu at March 27, 2008, 3:58 pmi am using xp sp2 , i had the problem in showing the hidden files and folder i have tried nod32 and antivir antivirus but none of them are working. whenever i go to folder option and check the show hidden files button, the check mark rolls back to donot show hidden files option due to which i am unable to see the hidden files and remove the virus by knowing the name of the virus.can u help me out of this?
thanks
try reading my post about autorun.inf virus, there’s an instruction there how to remove this kind of virus. To enable show folder options, Try this:
1. save this txt below as a reg file (ex… folder.reg) in your desktop
2. double click it to execute…
—–COPY BELOW———————————
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
“NoFolderOptions”=dword:0000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
“NoFolderOptions”=dword:0000000
———COPY ABOVE——————————
note:
you can’t enabled folder options if your registry is disabled! try to enable the registry by using REGISTRY TOOLS, read my post on it. Good luck
Posted by bleuken at March 28, 2008, 8:28 amhi..i wanted to know some steps on how can I get rid of the virus of my computer..it says that my running module contains Trojan program ‘SpamTool.Win32.Agent.ib’ and cannot be disinfected…I wanted to reformat my computer but i cant bcoz evrytime i boot my computer to cd it wont boot to cd..what should i do!!…
Posted by gary at April 19, 2008, 8:35 pmHi thanks bleuken you are the life saver as all other options failed i had this virus both in my PC and Laptop as i was using memory card to transfer data from one to another. As per your virus removal procedure i am able to remove this virus from my PC. In my case only SCVHOST.EXE file and no BLASTCNN.EXE, or AUTORUN.INI file was there and there was no registry entry in the H Key Current user——–/yahoo messenger as you mentioned but in the H KeyLocal machine——-/ Shell explorer.exe Scvhost.exe was there which i edited as per your instruction. In my PC I am able to open REGEDIT& Task Manager IN SAFE mode but in normal mode it still gives a dialog box that the registry edit has been disabled by the administrator. In case of Laptop there is no SCVHOST.EXE Blastclnnn.exe or Autorun.ini fil in system32. In SAFE MODE I am not able to open regedit & Task manager but in normal mode i can open Regedit and Task Manager. Any Advice ? Thanks again
Posted by i.s.gambhir at April 22, 2008, 12:21 pmi.s.gambhir, try this post http://bleuken.i.ph/blogs/bleuken/2007/12/18/enabling-or-disabling-the-registry-regeditexe/
Posted by bleuken at April 22, 2008, 12:53 pmThanks bleuken
I update my mcafee AV which helped in removing the SSCVHOST.EXE
but now im not able to access taskmanager, regedit also ‘folder option’ is missing.
I am realy surprised to have such detailed information about stated virus, and thank you very much for helping me.
Regards
Atta Jilani
i will surely try this.
thanx anyway.
Hi! Thanks for this. I’ve tried it several times, unfortunately I can’t seem to get rid of the virus. First, the virus in my computer is called SSCVHOSTII.EXE. It behaves exactly as you describe, but as you can see the name is different. Second, I can’t seem to do the REGEDIT part of the procedure. The files you mention there don’t exist on my comp. Finally, after I’ve followed the steps, I don’t know how to get out! Do I just do a hard reboot? I get this safe mode blank desktop, with nothing to click or type. Hope you can give me extra instructions. Thanks! RTW, my dad was born in Capiz.
Posted by Immanuel Magalit at February 14, 2008, 9:16 am