<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCTechNotes :: PC Tips, Tricks and Tweaks &#187; Win32/Autorun.R.worm</title>
	<atom:link href="http://pctechnotes.com/tag/win32autorunrworm/feed/" rel="self" type="application/rss+xml" />
	<link>http://pctechnotes.com</link>
	<description>PC Tips,Tricks and Tweaks</description>
	<lastBuildDate>Thu, 29 Jul 2010 03:25:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>How to remove SCVHOST.exe (W32/YahLover.Worm.gen or Win32/Autorun.R.worm)</title>
		<link>http://pctechnotes.com/how-to-remove-scvhostexew32yahloverwormgen-or-win32autorunrworm/</link>
		<comments>http://pctechnotes.com/how-to-remove-scvhostexew32yahloverwormgen-or-win32autorunrworm/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 04:20:54 +0000</pubDate>
		<dc:creator>slavezero</dc:creator>
				<category><![CDATA[Virus Removal]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[how to start windows in safe mode]]></category>
		<category><![CDATA[mode command]]></category>
		<category><![CDATA[registry entries]]></category>
		<category><![CDATA[registry keys]]></category>
		<category><![CDATA[SCVHOST.EXE]]></category>
		<category><![CDATA[svchost exe]]></category>
		<category><![CDATA[Win32/Autorun.R.worm]]></category>
		<category><![CDATA[windows program]]></category>

		<guid isPermaLink="false">http://pcremix.com/?p=379</guid>
		<description><![CDATA[This type of worm hides itself as SCVHOST.EXE or SCVHOSTS.EXE so it will look like the legitimate Windows program SVCHOST.EXE. This type of virus usually spread through Yahoo Messenger. This virus is also known as W32/YahLover.Worm.gen and Win32/Autorun.R.worm. One way to avoid infection from this virus is to ignore any invites from unknown friends. This [...]


Related posts:<ol><li><a href='http://pctechnotes.com/how-to-remove-worm-mymp3vbs/' rel='bookmark' title='Permanent Link: How to Remove Worm MyMP3.vbs'>How to Remove Worm MyMP3.vbs</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-autoruninf-and-prevent-virus-spreading-and-infection/' rel='bookmark' title='Permanent Link: How to remove autorun.inf and prevent virus spreading and infection'>How to remove autorun.inf and prevent virus spreading and infection</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-virus-from-usb-device/' rel='bookmark' title='Permanent Link: How to Remove Virus from USB Device'>How to Remove Virus from USB Device</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-pretty-park-worm/' rel='bookmark' title='Permanent Link: How To Remove Pretty Park Worm'>How To Remove Pretty Park Worm</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-jayexe-virus/' rel='bookmark' title='Permanent Link: How to Remove JAY.EXE and MVEO.EXE Virus'>How to Remove JAY.EXE and MVEO.EXE Virus</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-taga-lipa-are-virus/' rel='bookmark' title='Permanent Link: How to remove TAGA LIPA ARE! Virus'>How to remove TAGA LIPA ARE! Virus</a></li>
<li><a href='http://pctechnotes.com/remove-w32navidad-navidadexe/' rel='bookmark' title='Permanent Link: How to remove W32:Navidad (Navidad.Exe)'>How to remove W32:Navidad (Navidad.Exe)</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-funxls/' rel='bookmark' title='Permanent Link: How to remove FUN.XLS'>How to remove FUN.XLS</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-msblastexe-worm-virus/' rel='bookmark' title='Permanent Link: How to Remove MSBLAST.exe worm virus'>How to Remove MSBLAST.exe worm virus</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-happy99exe-ska/' rel='bookmark' title='Permanent Link: How to Remove Happy99.exe (ska)'>How to Remove Happy99.exe (ska)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">This type of worm hides itself as SCVHOST.EXE or SCVHOSTS.EXE so it will look like the legitimate Windows program SVCHOST.EXE. This type of virus usually spread through Yahoo Messenger. This virus is also known as W32/YahLover.Worm.gen and Win32/Autorun.R.worm. One way to avoid infection from this virus is to ignore any invites from unknown friends.</p>
<p style="text-align: justify;">This virus/worm installs itself in autorun.inf and once double click it will spread itself unto your system. Furthermore, it copies itself through all the shared folders on your computers throughout the network and installs itself in the registry entries remotely.</p>
<p style="text-align: justify;">Here are indication that your computer is infected with this virus.</p>
<ul style="text-align: justify;">
<li>This virus/worm blocks the task manager.(<a href="http://pctechnotes.com/the-easy-way-to-fix-your-task-manager/">way to fix your task manager</a>)</li>
</ul>
<ul style="text-align: justify;">
<li> The worm changes the registry to prevent running task manager and editing registry for harder detection. (<a href="http://pctechnotes.com/how-to-fix-registry-editing-has-been-blocked-by-an-administrator">way to enable registry editor</a>)</li>
</ul>
<ul style="text-align: justify;">
<li> It automatically restarts the computer when you try to go to the command prompt.</li>
</ul>
<ul style="text-align: justify;">
<li> It duplicates itself to different locations of the shared folders. The duplicated virus/worm uses a FOLDER icon with an .exe file extension. WARNING! DO NOT double click these folders.</li>
</ul>
<ul style="text-align: justify;">
<li> It autostart via registry keys Windows-&gt;Run and add itself to WinNT-&gt;WinLogon-&gt;Explorer.exe</li>
</ul>
<p style="text-align: justify;"><strong>How to remove the virus</strong></p>
<p style="text-align: justify;">You can use NOD32 or any strong antovirus programs to remove this virus but if you don&#8217;t have a anti-virus or your antivirus can&#8217;t remove this virus try following the steps below to remove it manually.</p>
<ul style="text-align: justify;">
<li>Boot your system in Safe Mode Command Prompt Only (<a href="http://pctechnotes.com/how-to-start-windows-in-safe-mode/">How to start Windows in safe mode</a>)</li>
</ul>
<ul style="text-align: justify;">
<li>After you log-in the command prompt will be opened (LOG-IN AS ADMINISTRATOR).</li>
</ul>
<ul style="text-align: justify;">
<li> Type CD C:\WINDOWS\SYSTEM32 (I assume that your Windows System files are located at Drive C)</li>
</ul>
<ul style="text-align: justify;">
<li> Type DIR /ah, this will display all hidden files on this directory folder. You will see the following files which is used by the virus to spread itself: AUTORUN.INI, BLASTCLNNN.EXE, and SCVHOST.EXE</li>
</ul>
<ul style="text-align: justify;">
<li>Type ATTRIB -H -R -S SCVHOST.EXE</li>
</ul>
<ul style="text-align: justify;">
<li> Type ATTRIB -H -R -S BLASTCLNNN.EXE</li>
</ul>
<ul style="text-align: justify;">
<li> Type ATTRIB -H -R -S AUTORUN.INI</li>
</ul>
<ul style="text-align: justify;">
<li> Type DEL SCVHOST.EXE</li>
</ul>
<ul style="text-align: justify;">
<li> Type DEL BLASTCLNNNN.EXE</li>
</ul>
<ul style="text-align: justify;">
<li> Type DEL AUTORUN.INI</li>
</ul>
<ul style="text-align: justify;">
<li> Type CD\</li>
</ul>
<ul style="text-align: justify;">
<li> Type ATTRIB -H -R -S AUTORUN.INF</li>
</ul>
<ul style="text-align: justify;">
<li> Type DEL AUTORUN.INF</li>
</ul>
<p style="text-align: justify;">After following the steps on removing the virus/worm files, the virus should now be removed from the registry of your system.</p>
<ul style="text-align: justify;">
<li>At the command prompt type REGEDIT and press ENTER key. This will run the Registry Editor</li>
</ul>
<ul style="text-align: justify;">
<li> From the registry, look for the keys: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, you will see an entry Yahoo! Messengger (it’s spelled like this) with a value c:\windows\system32\scvhost.exe, Delete this entry.</li>
</ul>
<ul style="text-align: justify;">
<li> Look again for the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, there’s an entry named: SHELL, it has a value = Explorer.exe SCVHOST.EXE , DON’T delete this entry!!! Just edit this entry and REMOVE the SCVHOST.EXE so that Explorer.exe will be the only value that remains from this registry entry.</li>
</ul>
<p style="text-align: justify;">After carefully following all the steps restart your computer on normal mode and the virus should now be gone.</p>


<p>Related posts:<ol><li><a href='http://pctechnotes.com/how-to-remove-worm-mymp3vbs/' rel='bookmark' title='Permanent Link: How to Remove Worm MyMP3.vbs'>How to Remove Worm MyMP3.vbs</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-autoruninf-and-prevent-virus-spreading-and-infection/' rel='bookmark' title='Permanent Link: How to remove autorun.inf and prevent virus spreading and infection'>How to remove autorun.inf and prevent virus spreading and infection</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-virus-from-usb-device/' rel='bookmark' title='Permanent Link: How to Remove Virus from USB Device'>How to Remove Virus from USB Device</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-pretty-park-worm/' rel='bookmark' title='Permanent Link: How To Remove Pretty Park Worm'>How To Remove Pretty Park Worm</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-jayexe-virus/' rel='bookmark' title='Permanent Link: How to Remove JAY.EXE and MVEO.EXE Virus'>How to Remove JAY.EXE and MVEO.EXE Virus</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-taga-lipa-are-virus/' rel='bookmark' title='Permanent Link: How to remove TAGA LIPA ARE! Virus'>How to remove TAGA LIPA ARE! Virus</a></li>
<li><a href='http://pctechnotes.com/remove-w32navidad-navidadexe/' rel='bookmark' title='Permanent Link: How to remove W32:Navidad (Navidad.Exe)'>How to remove W32:Navidad (Navidad.Exe)</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-funxls/' rel='bookmark' title='Permanent Link: How to remove FUN.XLS'>How to remove FUN.XLS</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-msblastexe-worm-virus/' rel='bookmark' title='Permanent Link: How to Remove MSBLAST.exe worm virus'>How to Remove MSBLAST.exe worm virus</a></li>
<li><a href='http://pctechnotes.com/how-to-remove-happy99exe-ska/' rel='bookmark' title='Permanent Link: How to Remove Happy99.exe (ska)'>How to Remove Happy99.exe (ska)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://pctechnotes.com/how-to-remove-scvhostexew32yahloverwormgen-or-win32autorunrworm/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
