Microsoft Windows XP Home Edition Logo

Question about Microsoft Windows XP Home Edition

3 Answers

How can I permanently remove NTV.VBS from my pc? It keeps on coming back the moment I delete it.thanks!

Posted by Anonymous on

3 Answers

Anonymous

  • Level 1:

    An expert who has achieved level 1.

    New Friend:

    An expert that has 1 follower.

  • Contributor
  • 1 Answer

I did this with my XP. And now it's working just fine and the ntv.vbs is gone. DISCLAIMER: I've tried many other ways that's been posted in the internet. The other 2 ways that seemed to be the best solutions are:
a.) switch to Linux
b.) reformat the PC

For this other thing that I did, you might as well prepare a back-up for all your files before you do this since I've only done it once. I can't assure you that everything will work the same way as my XP did.

Click Start, click Run
Key in regedit
Click OK
The dialogue box of the Registry will appear
Click View
Click Find in the drop down menu
Find dialogue box will open. Look for autorun.inf
Locate the files containing the autorun.inf in the registry. Delete.
Go back to View. Find next. Continue until you've deleted all autorun.inf's
Follow the same for locating all wscript.exe
Follow the same for locating all jargon.vbs
When all these autoruns, wscripts and jargons are gone, look for the ntv.vbs file in My Computer. Delete it and it shouldn't reappear anymore.

Posted on Oct 02, 2011

Ad

Anonymous

  • Level 1:

    An expert who has achieved level 1.

    New Friend:

    An expert that has 1 follower.

  • Contributor
  • 1 Answer

@echo off

rem Save in Notepad as "ntv-x.bat"
rem A temporary relief for ntv.vbs infection
rem Restart computer after scan!

cls

echo.
echo.
echo NTV.VBS Hunter Release 1
echo Courtesy of Einstein
echo.
echo Please wait while your system is being cleaned...
echo.
echo.

tskill wscript /a

reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v prnshare /f
reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v dnscache /f

del "%allusersprofile%\Start Menu\Programs\Startup\dns cache.lnk" /q

for /d %%v in (c: d: e: f: g: h: i: j: k: l: m: n:) do call :uproot %%v
for /d %%v in (o: p: q: r: s: t: u: v: w: x: y: z:) do call :uproot %%v

echo Done!

goto :eof

:uproot

if not exist %1\con goto :eof

del %1\autorun.inf /ahrs /q
del %1\*.vbs /ahrs /q
del %1\*.lnk /q

goto :eof

Posted on Jul 30, 2010

Ad

Anonymous

  • Level 2:

    An expert who has achieved level 2 by getting 100 points

    All-Star:

    An expert that got 10 achievements.

    MVP:

    An expert that got 5 achievements.

    Vice President:

    An expert whose answer got voted for 100 times.

  • Expert
  • 323 Answers

I think this is what your looking for.

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3AWin32%2FAutorun.FC

Posted on Jan 12, 2010

Add Your Answer

×

Uploading: 0%

my-video-file.mp4

Complete. Click "Add" to insert your video. Add

×

Loading...
Loading...

Related Questions:

0helpful
1answer

How do you delete ge.vbs from my pc

This is a very nasty trojan and i seriously advise a clean install of windows as you will go through more headaches trying to remove this than its worth.
0helpful
1answer

Permanent Desktop icon removal for Symbol MC9090 scanner

Right click the icon. Hold the shift button while left clicking the delete option in the menu. Click ok on the permanent delete.
0helpful
2answers

Can not Find. Script File C:\WINDOWS\System32\CleanViirus.vbs

it is a virus plz follow the instruction bellow to remove this virus:

  1. Go to Task Manager –> Processes and End the following processes in order:
    1. dxdlg.exe
    2. wscript.exe
  2. Go to Start –> Run –> regedit –> Open the following key:
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
  3. In the right hand pane, select Userinit and delete everything except “C:windowssystem32userinit.exe”
  4. userinit-thumb.png
  5. Make sure the processes wscript.exe and dxdlg.exe are not running.
  6. Delete the following files
    1. C:WindowsSystem32dxdlg.exe
    2. C:WindowsSystem32boot.vbs
    3. In your Windows drive, search for boot.vbs and delete all of them.
    4. In your Windows drive, search for kinza.exe and delete all of them.
  7. Disable System Restore and then Enable it again.
  8. Restart your computer.
Hopefully everything will be cleaner now and your computer will be free from boot.vbs virus icon_smile.gif . Please share your experiences.
1helpful
1answer

How to remove sowar virus on my pc

1. Go to Start, Run and type: cmd press Ok.

2. At the command prompt, type in your primary drive location, usually C:

3. You may need to change the directory. If so type: cd \ hit Enter.

4. Type: attrib -s -h -r -a autorun.inf hit Enter.

5. Type: dir and hit Enter. This will allow you to see and confirm the Autorun files.

6. Type: del autorun.inf hit Enter. Repeat the above commands for each drive on your computer including your flash/usb drive.

7. Now search for and remove sowar.vbs, SysRes.vbs, Cool USEP Scandal.vbs
  • At the command prompt, type in your primay drive location, usually C: hit Enter.
  • Type: attrib sowar.vbs.* -s -h -r -a hit Enter.
  • Type: dir /s sowar.vbs Hit Enter.
8. If the file is present, type: del sowar.vbs hit Enter.
  • Repeat the above commands for each drive on your computer including your flash/usb drive.
  • Then repeat these instructions to search for and delete SysRes.vbs, Cool USEP Scandal.vbs on each drive if present.
9. Exit the command prompt and reboot normally.

10. Disable autorun.
1helpful
1answer

I found ntv.vbs folder and shortcut in my

I cant say any thing about folder to delet but you should try to delete it by pressing shift key and del then yes k and as for as lid i dont think there is any problem w ur VGA etc its fault in LID you should not submit it for servicing I think when you dont have any problem during you work with lid then there is no need for servicing. I think you got my point for response please give me your response at [email protected]
1helpful
1answer

Hard disk


Download this file to your desktop.
http://securityresponse.symantec.com/avcenter/UnHookExec.inf
Once on your desktop,Right click and select install.

You have this virus/worm "VBS/Solow-B" or FS6519.dll.vbs and need to delete it.

To delete the value from the registry

Click Start > Run.
Type regedit
Click OK.

Navigate to and delete the following registry entries:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun"FS6519" = "%Windir%FS6519.dll.vbs"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain"Window Title" = "TAGA LIPA ARE!"

Exit the Registry Editor.

Run antivirus scan
0helpful
2answers

Virusremoval.vbs

Are you comfortable going into the registry, if so , do this:

virusremoval.vbs

1. From the start menu click Run -> type Regedit


2. Registry Editor will open


3. In the Registry Editor, go to Edit menu and press find

4. In the find dialog box type - virusremoval.vbs and press find next button
5. The search will end at some folder in the registry at the key - "userint"; doubleclick it; you will find many paths separated by commas - eg: c:windows/system32/userinit.exe,c:/windo... and so on.

Among those paths you will find "C:\windows\system32\virusremoval.vbs". Delete the path. Ensure that remaining paths are unaltered so that your genuine scripts are not affected.


6. Press F3 (find next) to see if the same path exists somewhere else in your registry. If found again at some other place remove the path there also.


7. Repeat F3 until you get a message that search has finished.


If I could be of further assistance, let me know. If this helps or solves the issue, please rate it.
Thanks, Joe



I’m happy to assist further over the phone at https://www.6ya.com/expert/joe_8b8c2cd6ce148309

0helpful
1answer

Start up msg

First
Open task manager and kill process wscript.exe.

Then
Delete VirusRemoval.vbs and Autorun.inf files from all usb drives.
Delete "c:\WINDOWS\system32\userinit.exe"

Then
Go to c:\Windows\System32 and delete the file VirusRemoval.vbs. It is super hidden so first go to Folder Options and check show hidden and check boxes. Also required for the above files.

Then
go to start>run and type regedit and enter
Go to HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
On the right side look for Shell which should have value of just explorer.exe.
delete anything at right side of explorer.exe if there is anything.

Under same key Winlogon also look for Userinit which should have value of
c:\WINDOWS\system32\userinit.exe,
Delete all the **** after the comma.

Then
Go to HKCU\Software\Microsoft\Internet Explorer\Main
On the right side locate Window Title and delete its value i.e. Sujin.com.np

Under the same key locate Start Page and delete its value i.e. http://sujin.com.np/

then go to Start Menu -> Run -> msconfig -> Startup tab -> uncheck .vbs files

Restart System
5helpful
3answers

Problem while starting computer

Hello..

TO remove this error messege follow these steps.


type "regedit" in run dialog box.


Navigate to "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"

There is a string value named "userinit".

The value of this key should "c:\windows\system32\userinint.exe"
Delete anything thing after this.

Now logoff and relogin or Reboot.

Not finding what you are looking for?

1,415 views

Ask a Question

Usually answered in minutes!

Top Microsoft Computers & Internet Experts

David Shaub

Level 3 Expert

2994 Answers

Steve Nordquist
Steve Nordquist

Level 3 Expert

982 Answers

Brad Brown

Level 3 Expert

19166 Answers

Are you a Microsoft Computer and Internet Expert? Answer questions, earn points and help others

Answer questions

Manuals & User Guides

Loading...