Question about Computers & Internet

1 Answer

How to delete hidden virus in windows\system32\xp-eb2df064.exe

With file attrib "shr"

Posted by on

1 Answer

  • Level 1:

    An expert who has achieved level 1.

  • Contributor
  • 1 Answer

How we can delete hidden virus from computer

Posted on Dec 03, 2008

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

2 Answers

Antivirus for ''doomsday'' virus


I had this virus, and the following procedure seemed to work in getting rid of it for me. Hopefully it works for you as well.
open command prompt my going Start > Run and typing cmd.
You should be in a directory called something like “C:\Documents and Settings\User”. if you are not, change to it by typing ‘cd’ and the directory above (replacing ‘user’ with your username), and then pressing enter.
type ‘attrib’ and press enter. There should be a file called svchost.exe, and will have the attributes SHR (which stands for System-file, hidden, and read-only).
type ‘attrib -s -h -r svchost.exe’. This removes the SHR properties and allows you to delete the file.
type ‘del svchost.exe’. This should delete the virus from your computer.
NOTE: svchost.exe is a critical system file if it is located in C:\WINDOWS\System32. If it is located elsewhere (as this one is), it is generally a virus.
Then, insert infected pen drives (memory sticks, iPods etc.) which carry the virus. Change the directory to the pen drive by typing ‘E:’(or whatever letter it is) ENTER. Then type ‘attrib’ as above.
there should be the files ‘protector.exe’ and ‘autorun.inf’ which also have the properties SHR. type ‘attrib -s -h -r’ ENTER, and then delete the files by typing ‘del autorun.inf’ ENTER then ‘del protector.inf’ ENTER. This should remove the virus. Autorun.inf might reappear, but this shouldn’t be a problem.
Do not open the pen drive after you insert it, and cancel any autorun windows that come up.

May 13, 2010 | Computers & Internet

Tip

How to remove Autorun.inf


Here are some typical malware which can install autorun.inf.exe file to your computer and give your computer a critical strike.
Autorun.inf virus contains three execute files which are kavo.exe, ntdelect.com and autorun.inf. All of them are hidden files. You cannot find the by showing hidden files. The only way to find them is to use DOS command.

Not all user have computer savvy. I was suffered from this virus a lot. Success got rid of it using RegTool and want to share it with you.

To remove Autorun.inf

Tools you need RegTool and AVG anti-virus.

Also here is an easy way to remove Autorun.inf manually!

click Start>Run>enter “CMD” them you will see and command window. In the command prompt, you can search for any exe.files. First we can disable “read only” and “hidden” attributes.
Enter the word in prompt.
Check C drive: key in dir c:\/a/w
2 then
attrib -s -h -r c:\autorun.inf
attrib -s -h -r c:\ ntdelect.com
You can use the same way to disable attributes of other drive such like D, E, etc.
3 OK, everything is done, we can now remove these two files.
For C drive, you can enter
del c:\autorun.inf
del c:\ntdelect.com

The same to D drive
How about kavo.exe? You need to repeat step1 and step 2 to disable attributes.
The delete command is different with them.
attrib -s -h -r c:\windows\system32\kavo.exe
del c:\windows\system32\kavo.exe

last thing you should do:
Open registry editor by entering Regedit.
Go to HKEY_LOCAL-MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Remove Kavo value.

on Jun 01, 2010 | Computers & Internet

3 Answers

How to solve rahul's virus protection.vbe


First
Open task manager and kill process wscript.exe.

Then
Delete VirusRemoval.vbs and Autorun.inf files from all usb drives if u have the virus in them.

Then
Go to c:\Windows\System32 and delete the file VirusRemoval.vbs. It is super hidden so first go to Folder Options and check show hidden and check boxes. Also required for the above files.

Then
go to start>run and type regedit and enter
Go to HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
On the right side look for Shell which should have value of just explorer.exe.
delete anything at right side of explorer.exe if there is anything.

Under same key Winlogon also look for Userinit which should have value of
c:\WINDOWS\system32\userinit.exe,
Delete all the **** after the comma.

Then
Go to HKCU\Software\Microsoft\Internet Explorer\Main
On the right side locate Window Title and delete its value i.e. Sujin.com.np

Feb 21, 2010 | Computers & Internet

2 Answers

Missing dcim.exe file


Hi! I had same problem and fix it no time. Well this is trick! virus hide dcim folder and make only visible dcim.exe. 1. so anti-virus will delete that virus "dcim.exe" (or can you) 2. go to start/run and type cmd 3. there you type "attrib -s -h e:dcim" (assuming that your cam is assigned e:) Now go to My Computer and DCIM shoud be there!!

Sep 16, 2009 | Sony Cyber-Shot DSC-T1 Digital Camera

1 Answer

Funny UST scandal!!!


How to remove the virus:
first download taskiller in here or here and install it to your computer because you can’t use task manager to terminate the virus(the virus automatically close task manager).

run taskiller and left click it on the system tray(the one with a skull icon)
click processes
to close the virus, select process and click yes to the question

(process to close)

  1. killer.exe
  2. lsass.exe
  3. smss.exe
note: close only file that have the same icon of Funny UST Scandal.avi.exe
CMD STEPS
  1. now, click “start” then “run”
  2. type “cmd” without quotes
  3. type “cd\” without quotes
  4. type “attrib -h -s smss.exe” without quotes
  5. type “attrib -h -s autorun.inf” without quotes
  6. type “start c:” without quotes (a new window will open)
  7. select smss.exe, autorun.inf, Funny UST Scandal.avi.exe and delete it
If theres any drive or a partition type “d:” in command prompt without quotes “d” is the drive letter then repeat the CMD STEPS number 4-7 above…….
  • now type this on the command prompt “cd windows” without quotes.
  • type “attrib -h -s smss.exe” (without quotes)
  • type “start c:\windows” (without quotes)
  • delete the file smss.exe
  • now, goto c:\documents and settings\all users\startmenu\programs\startup
  • delete lsass.exe
click “start” then “run”
type “regedit” without quotes then delete the registry entries above….

“VIRUS REMOVE”
Or just simply download this UST VIRUS REMOVER (not tested)

Mar 20, 2009 | Microsoft Windows XP Professional With...

1 Answer

Ssvichosst.exe


GO TO DOS PROMPT AND DEL THIS FILE e.g goto start-->run-->cmd than press ok than you will be at c:\documents and setting\ so type c:\documents and setting\cd\ and enter than goto system32 directory by c:\cd windows\system32 and than run the following commands
c:\windows\system32\attrib -s -h -a ssvichosst.exe and than run c:\windows\system32\del ssvichosst.exe this will remove this virus file.



Dec 12, 2008 | Computers & Internet

1 Answer

Start up msg


First
Open task manager and kill process wscript.exe.

Then
Delete VirusRemoval.vbs and Autorun.inf files from all usb drives.
Delete "c:\WINDOWS\system32\userinit.exe"

Then
Go to c:\Windows\System32 and delete the file VirusRemoval.vbs. It is super hidden so first go to Folder Options and check show hidden and check boxes. Also required for the above files.

Then
go to start>run and type regedit and enter
Go to HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
On the right side look for Shell which should have value of just explorer.exe.
delete anything at right side of explorer.exe if there is anything.

Under same key Winlogon also look for Userinit which should have value of
c:\WINDOWS\system32\userinit.exe,
Delete all the **** after the comma.

Then
Go to HKCU\Software\Microsoft\Internet Explorer\Main
On the right side locate Window Title and delete its value i.e. Sujin.com.np

Under the same key locate Start Page and delete its value i.e. http://sujin.com.np/

then go to Start Menu -> Run -> msconfig -> Startup tab -> uncheck .vbs files

Restart System

Jul 23, 2008 | Computers & Internet

2 Answers

Virus


Hi, there are some xp virus removal visit this site /www.Selecta.site.com

Feb 01, 2008 | Computers & Internet

6 Answers

Funny UST scandal virus


first download taskiller in http://www.rsdsoft.com/task_killer/index.php4
and install it to
your computer because you cant use taskmanager to terminate the virus(the
virus automatically close taskmanager).

-run taskiller and left click it on the system tray(the one with a skull icon)

-click processes

-to close the virus, select process and click yes to the question

(process to close)
1.killer.exe
2.lsass.exe
3.smss.exe

note: close only file that have the same icon of Funny UST Scandal.avi.exe


CMD STEPS
1-now, click "start" then "run"
2-type "cmd" without quotes
3-type "cd\" without quotes
4-type "attrib -h -s smss.exe" without quotes
5-type "attrib -h -s autorun.inf" without quotes
6-type "start c:" without quotes(a new window will open)
7-select smss.exe,autorun.inf,Funny UST Scandal.avi.exe and delete it

-if theres any drive or a partition type "d:" in command prompt without quotes
"d" is the drive letter then repeat the CMD STEPS number 4-7 above.......

-now type this on the command prompt "cd windows" without quotes(na naman!)
-type "attrib -h -s smss.exe" without quotes(uli)
-type "start c:\windows" without quotes(hay naku!)
-delete the file smss.exe
-now, goto c:\documents and settings\all users\startmenu\programs\startup
-delete lsass.exe

-click "start" then "run"
-type "regedit" without quotes then delete the registry entries above....

Note:
If you have problems opening drives in My Computer open regedit find
"\smss.exe" then erase values like: "c:\smss.exe", "d:\smss.exe" etc..


Hope this helps

Jan 16, 2008 | Computer Associates eTrust PestPatrol...

2 Answers

Drive not open


maybe you have accidentally change something or what? especially to the setting or something you have downloaded software which is malicious maybe not right!

Oct 24, 2007 | Microsoft Windows XP Professional With...

Not finding what you are looking for?
Computers & Internet Logo

Related Topics:

40 people viewed this question

Ask a Question

Usually answered in minutes!

Top Computers & Internet Experts

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

kakima

Level 3 Expert

102366 Answers

David Payne
David Payne

Level 3 Expert

14161 Answers

Are you a Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...