Question about Computers & Internet

3 Answers

How to locate a virus using command prompt?

Now, we facing a problem of our computers, some computers have a virus, that is why,our work is very slow now in progressing.

Posted by on

  • 1 more comment 
  • seinsah Nov 27, 2008

    find virus

  • Anonymous Jan 11, 2009

    how to get virus using cmd
    what is the code for that?


  • pankswet007 Mar 09, 2009

    how to locate virus in system & delete by using cmd.

×

3 Answers

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    MVP:

    An expert that got 5 achievements.

    Novelist:

    An expert who has written 50 answers of more than 400 characters.

    Governor:

    An expert whose answer got voted for 20 times.

  • Expert
  • 109 Answers

I don't know how to locate a virus using command prompt. Is there any reason why you want to do that?

I bet there are some virusscanners around which can be controlled using the Command Prompt. You can just install a free scanner like AVG AntiVirus Free Edition. And let it scan in Safe Mode.

Here's a link to it:
[Grisoft AVG AntiVirus 7.5 Free Edition]

I hope this helps. Please rate.

Greetings,

DarkNeogen.

Posted on Feb 11, 2008

  • Level 3:

    An expert who has achieved level 3 by getting 1000 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    President:

    An expert whose answer got voted for 500 times.

  • Master
  • 2,351 Answers

What can one say. I'm going to suggest you download & run SOPHOS. Free software with instructions. Click the link below. Follow the instruction on the page.
http://www.sophos.com/support/knowledgebase/article/13252.html

Posted on Feb 11, 2008

  • Level 1:

    An expert who has achieved level 1.

    Corporal:

    An expert that has over 10 points.

    Mayor:

    An expert whose answer got voted for 2 times.

  • Contributor
  • 4 Answers

Acjsabcjsc sjbncjsabnc

Posted on Apr 16, 2010

1 Suggested Answer

6ya6ya
  • 2 Answers

SOURCE: I have freestanding Series 8 dishwasher. Lately during the filling cycle water hammer is occurring. How can this be resolved

Hi,
a 6ya expert can help you resolve that issue over the phone in a minute or two.
best thing about this new service is that you are never placed on hold and get to talk to real repairmen in the US.
the service is completely free and covers almost anything you can think of (from cars to computers, handyman, and even drones).
click here to download the app (for users in the US for now) and get all the help you need.
goodluck!

Posted on Jan 02, 2017

Add Your Answer

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

1 Answer

How to Remove Shortcut Virus on Windows?


Connect the affected USB drive to your computer. When the files on your USB drive have been changed to shortcuts, your files are actually still there in a hidden location. This process will restore the files so that you can see them again.
  • Do not run any of the shortcuts on the USB drive, or you risk spreading the infection.


26319209-bxzhjmonsmllydp0qa2riq2g-2-0.jpg
Determine the drive letter of the USB drive. You'll need to know the drive letter for the USB drive or memory card that has been affected by the virus. The quickest way to find this is to open the "Computer"/"This PC" window. The drive letter for the USB drive will be listed next to the drive label.
  • Press Win+E to open the window on any version of Windows.
  • Click the Folder button in your taskbar to open the window.
  • Click "Computer" in the Start menu if you're using Windows 7 or Vista.
26319209-bxzhjmonsmllydp0qa2riq2g-2-2.jpg
Open the Command Prompt. You'll be performing the fix using a few quick Command Prompt commands. The process for opening the Command Prompt varies depending on the version of Windows you are using:
  • Any version - Press Win+R and type "cmd" to launch the Command Prompt.
  • Windows 8 and newer - Right-click the Windows button and select "Command Prompt."
  • Windows 7 and older - Open the Start menu and select "Command Prompt."


26319209-bxzhjmonsmllydp0qa2riq2g-2-5.jpg

Type .attrib -h -r -s /s /d X:\*.*and press? Enter. Replace Xwith your USB drive's letter. For example, if your USB drive's letter is E, typeattrib -h -r -s /s /d E:\*.* and press ? Enter.[1]
  • This will unhide the files, remove any read-only attributes, and remove the shortcuts.
  • The process may take a while to complete, depending on how much data is on the USB drive.
26319209-bxzhjmonsmllydp0qa2riq2g-2-14.jpg
Open the unnamed folder created on your USB drive. This folder will contain all of the data that was previously hidden by the infection.

26319209-bxzhjmonsmllydp0qa2riq2g-2-20.jpg Copy the recovered data to a safe location on your computer. This is a temporary location while you finish cleaning the drive. You can create a folder on your desktop to hold the files for now. Just drag the files from your USB drive to whichever folder you choose.
  • It may take a while to copy large amounts of data.
26319209-bxzhjmonsmllydp0qa2riq2g-2-27.jpg
Right-click on your drive in "Computer"/"This PC" and select "Format." This will open the Format window.
  • The formatting process will completely erase the drive, so make sure that you've copied your data off of it first.
26319209-bxzhjmonsmllydp0qa2riq2g-2-35.jpg
Uncheck "Quick Format" and click "Start." Unchecking "Quick Format" will scan for and remove the infection on the USB drive. The format process will likely take a while to complete. 26319209-bxzhjmonsmllydp0qa2riq2g-2-44.jpg

Oct 20, 2016 | Microsoft Computers & Internet

Tip

How to remove the scvhost.exe Virus.


Svchost.exe is the name of a generic host process for services that run from dynamic link libraries (DLLs). A variety of worm malware programs spread a similarly named file <b>Scvhost.exe </b>via Yahoo! Messenger that blocks the Task Manager and Registry Editor, as well as use of the command prompt.<br /> <br /> <b><u>Warning</u></b><br /> Manual removal of Scvhost.exe may be very difficult as the removal process requires knowledge of the Operating System's command prompt and Registry Editor. If not performed properly, your computer system might experience permanent damage. Consequently, manual removal might be best for experienced users. Less experienced users might want to consider using an automatic spyware removal application, such as that offered by Trend Micro. This worm duplicates itself to different locations of shared folders. The duplicated program uses a folder icon that has an .exe file extension. DO NOT double click on any of these folders.<br /> <br /> <b><u>Follow these step by step instructions to remove the scvhost.exe virus.</u></b><br /> <b></b> <br /> <b><u>Step 1 (Turning off System Restore)</u></b><br /> This is so that if you ever need to use System Restore after you have removed the virus, it doesn't restore the virus aswell.<br /> <br /> If the operating system of the infected computer is either Windows Me or Windows XP, turn off System Restore while this fix is being implemented. To turn off System Restore within Windows Me, click <b>Start &gt; Settings &gt; Control Panel</b>. Double-click <b>System</b>. Select F<b>ile System</b> from the Performance tab. Left click the <b>Troubleshooting</b> tab and check the <b>Disable System Restore</b> box. Click <b>OK</b>. <br />To turn off System Restore within Windows XP, log in as Administrator and click <b>Start</b>. Right click <b>My Computer</b>" and select <b>Properties</b> from the shortcut menu. Check the <b>Turn off System Restore</b> option for each drive on the System Restore tab. Left click <b>Apply</b> and <b>Yes</b> to confirm when prompted. Click <b>OK</b>.<br /> <b></b> <br /> <b><u>Step 2 (Run in safe mode)</u></b><br /> Restart your computer in Safe Mode and log in as Administrator. Press <b>F8</b> after the first beep occurs during start up, before the display of the Microsoft Windows logo. Select the first option, to run Windows in Safe Mode from the selection menu.<br /> <b></b> <br /> <b><u>Step 3 (Accessing Command prompt)</u></b><br /> Access the command prompt. Click <b>Start &gt; Run</b>. Type <b>cmd</b>. Click <b>OK</b>. Then in the command prompt type <b>cd </b>to<b> </b>change directory then press the space bar. <br />Type the name of the full directory path of the folder containing your Windows system files. It will be either <b>C:\Windows\System </b>or<b> C:\Windows\System 32</b><br /> <b></b> <br /> <b><u>Step 4</u></b><br /> From the command prompt, type the following to unprotect the files for removal:<br /><b>attrib -h -r -s scvhost.exe</b> and press <b>Enter</b>;<br /><b>attrib -h -r -s blastclnnn.exe </b>and press<b> "Enter</b>;<br /><b>attrib -h -r -s autorun.inf</b> and press <b>Enter</b>.<br /> <br /> <b><u>Step 5</u></b><br /> Delete the files by typing the following from the command prompt:<br /><b>del scvhost.exe</b> and press <b>Enter</b>;<br /><b>del blastclnnn.exe</b> and press <b>Enter</b>;<br /><b>del autorun.ini</b> and press <b>Enter</b>.<br /> <b></b> <br /> <b><u>Step 6</u></b><br /> Type "<b>cd\</b>" to return to the main Windows directory.<br />Unprotect and delete the Autorun.inf file by typing the following from the Windows directory command prompt:<br /><b>attrib -h -r -s autorun.inf</b> and press <b>Enter</b>;<br /><b>del</b> <b>autorun.inf</b> and press <b>Enter</b>;<br />Type <b>regedit</b> and press <b>Enter</b> to open the Registry Editor.<br /> <b></b> <br /> <b><u>Step 7</u></b><br /> Locate the following entry:<br /><b>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run</b>.<br />Delete the incorrectly spelled Yahoo! Messenger entry with the value<br /><b>c:\windows\system32\scvhost.exe.</b><br /> <b></b> <br /> <b><u>Step 8</u></b><br /> Locate the following key:<br /><b>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</b>.<br />Within the key, there is a <b>shell</b> entry with the value of <b>explorer.exe, scvhost.exe</b>. Edit the entry to remove the reference to Scvhost.exe, leaving Explorer.exe as the remaining value in the registry entry.<br /> <br /> <b><u>Step 9</u></b><br /> Locate the following key:<br /><b>HKEY_LOCAL_MACHINE&gt;SYSTEM&gt;CurrentControlSet&gt;Services&gt;<br /></b>Delete the following subkeys from the left panel:<br /><b>RpcPatch</b><br /><b>RpcTftpd <br /></b>Exit the command prompt and return to the operating system. Type <b>Exit</b>, and press <b>Enter</b>.<br /> <br /> <b><u>Step 10</u></b><br /> Reboot the PC.<br />If Scvhost.exe still resides on the computer, repeat these steps or try using an automatic removal program from McAfee or Symantec.<br /> <br /> <br /> <br />

on Feb 25, 2011 | Computers & Internet

3 Answers

I need to restore my computer without disc, what should I write in command prompt?


To access the System Restore Gui from command prompt you will need to type in rstrui.exe
OR
%Windir%\System32\rstrui.exe

Other Thoughts
--------------
If you are experiencing Boot issues you will need to install a boot manager. If your system is missing a file or a file is broken, you may need to replace that file with a working version that's compatible with your OS Version.

Aug 07, 2015 | Dell OptiPlex GX270 PC Desktop

2 Answers

Slow performance


Go into command prompt and stop all programs. If that does not work, get a bigger hard drive

Dec 08, 2012 | Computers & Internet

4 Answers

Slow


1st of all clean ur pc from viruses and also remove registry errors from reginout

Jul 26, 2010 | Acer Aspire One PC Notebook

1 Answer

How to remove sowar virus on my pc


1. Go to Start, Run and type: cmd press Ok.

2. At the command prompt, type in your primary drive location, usually C:

3. You may need to change the directory. If so type: cd \ hit Enter.

4. Type: attrib -s -h -r -a autorun.inf hit Enter.

5. Type: dir and hit Enter. This will allow you to see and confirm the Autorun files.

6. Type: del autorun.inf hit Enter. Repeat the above commands for each drive on your computer including your flash/usb drive.

7. Now search for and remove sowar.vbs, SysRes.vbs, Cool USEP Scandal.vbs
  • At the command prompt, type in your primay drive location, usually C: hit Enter.
  • Type: attrib sowar.vbs.* -s -h -r -a hit Enter.
  • Type: dir /s sowar.vbs Hit Enter.
8. If the file is present, type: del sowar.vbs hit Enter.
  • Repeat the above commands for each drive on your computer including your flash/usb drive.
  • Then repeat these instructions to search for and delete SysRes.vbs, Cool USEP Scandal.vbs on each drive if present.
9. Exit the command prompt and reboot normally.

10. Disable autorun.

Dec 21, 2009 | Microsoft Windows Server Standard 2003 for...

1 Answer

Virus


Use sav32cli and scan your pc in command prompt.

http://www.sophos.com/support/disinfection/pedis.html

  1. Download an emergency copy of SAV32CLI. On an uninfected Windows computer, run this file to extract the contents into a SAV32CLI folder on a medium that can be write-protected. Copy the SAV32CLI folder produced onto a medium that can be write-protected. Add any relevant IDEs to this folder and write-protect the disk (on a CD/R or CD/RW close the session).
  2. Restart the computer in Safe Mode with command prompt.
  3. At the infected computer, place the CD in the CD drive (D: in this example). At the command prompt type
    D:
    to access the CD drive. Type:
    CD SAV32CLI
    Then type:
    SAV32CLI -DI -P=C:\LOGFILE.TXT
    to disinfect the virus.
    All other files must be deleted. Some of these were dropped by the virus and need not be restored. Others should be recovered from backups.
    SAV32CLI -REMOVE -P=C:\REMOVLOG.TXT
    This command writes a report to the root of the C: drive. This report can be used to check which deleted files should be restored from backups.
    In Windows 2000/XP/2003/Vista, when disinfection and deletion have finished, restart the computer in Windows.
    Install or reinstall Sophos Anti-Virus then run an 'All files' scan to check that the virus has gone.
  4. Before leaving Safe Mode, check any registry entries mentioned in the virus analysis recovery instructions, and edit them if necessary. If problems persist, contact support.

Dec 24, 2008 | Symantec Norton AntiVirus 2008: Windows

1 Answer

My outlook 2007 instant search is not working properly, can you help me. Even after indexing (Rebuild) the message pops up that it is indxing and computer slow because of use activity


first make sure there are no unwanted program run as the computer starts and eat all memory to see that type following on command prompt
msconfig ¿
then select startup
disable undesirable

check and any virus using good antivirus.
disable autoindexing.
Now download and install desktop search from www.microsoft.com

it will surely do instant search

Zulfikar Ali

Dec 02, 2008 | Microsoft Office 2003 Basic Edition...

2 Answers

Command Prompt shut down my computer


had the same problem and found an exact solution here...

might as well try it on yours

http://www.techykid.com/virus/auto-shutdown-virus.html

thanks

Apr 08, 2008 | Computers & Internet

1 Answer

Driver


restore your files by using sfc command from command prompt.

Nov 19, 2007 | Dell E173FP 17" LCD Flat Panel Monitor

Not finding what you are looking for?
Computers & Internet Logo

Related Topics:

4,375 people viewed this question

Ask a Question

Usually answered in minutes!

Top Computers & Internet Experts

Brian Sullivan
Brian Sullivan

Level 3 Expert

27725 Answers

kakima

Level 3 Expert

102366 Answers

David Payne
David Payne

Level 3 Expert

14161 Answers

Are you a Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...