<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spy Blogger &#187; Guides</title>
	<atom:link href="http://spyblogger.com/category/more/guides/feed/" rel="self" type="application/rss+xml" />
	<link>http://spyblogger.com</link>
	<description>Social Media, Internet Marketing, SEO, Blogging, Gadgets, Information, Facebook, Twitter, Google Plus, Youtube</description>
	<lastBuildDate>Tue, 27 Mar 2012 14:01:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>SVICHOSSST.exe Virus Removal Guide</title>
		<link>http://spyblogger.com/2009/05/svichossstexe-virus-removal-guide/</link>
		<comments>http://spyblogger.com/2009/05/svichossstexe-virus-removal-guide/#comments</comments>
		<pubDate>Sun, 31 May 2009 06:36:55 +0000</pubDate>
		<dc:creator>SpyBlogger</dc:creator>
				<category><![CDATA[Guides]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[norton]]></category>
		<category><![CDATA[removal]]></category>
		<category><![CDATA[SVICHOSSST.exe]]></category>
		<category><![CDATA[svichosst]]></category>
		<category><![CDATA[tutorial]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://spyblogger.com/?p=113</guid>
		<description><![CDATA[This is a revised tutorial from my previous blog. Often i find people still looking for "SVICHOSST.exe virus removal guides" here goes this post again:

This Virus is detected by only the following Antiviral Software:

1- BitDefender .. it detects it with the name "Win32.Worm.Sohanat.S"
No related posts.]]></description>
			<content:encoded><![CDATA[<p>This is a revised tutorial from my previous blog. Often i find people still looking for &#8220;SVICHOSST.exe virus removal guides&#8221; here goes this post again:</p>
<p>This Virus is detected by only the following Antiviral Software:</p>
<p>1- BitDefender .. it detects it with the name &#8220;Win32.Worm.Sohanat.S&#8221;<br />
2- Dr.Web .. it detected it with the name &#8220;Win32.HLLW.Hang&#8221;<br />
3- FortiNet .. it detects as &#8220;W32/Dloader!tr.dldr&#8221;<br />
4- Kaspersky Anti-Virus .. it detects as &#8220;IM-Worm.Win32.Sohanad.t&#8221;<br />
5- Norton Anti-Virus 2007 (fully updated) .. detects it as &#8220;Win32.FunLove.4099&#8243;</p>
<p><span id="more-113"></span>I Got Norton Anti-Virus 2008, still this virus infected my system!</p>
<p>As soon as i inserted my friends USB, NORTON DETECTED THE VIRUS and gave me the message(as per my habit, before opening any USB from outsider I run a virus scan and then open it). It detected SVICHOSSST.exe in almost all the folders of the USB, plus, it detected NEW FOLDER.exe and then all the folders had a file inside them with the same name as the folder&#8217;s name.</p>
<p>Norton Anti-virus 2007 detected all the infected files, gave me the report that all viruses got FIXED. But nothing was fixed!</p>
<p>First of all, symptoms of this Virus:</p>
<p>- TaskMgr disabled<br />
- RegistryTools disabled<br />
- NoFolderOptions- Command Prompt(CMD) sometimes disabled one minimized when you attempt to open it<br />
- Slow Windows performance, boot, shutdown<br />
- new Folder look-alike files in your removable storage devices, eg.Pendrive, Ex-HD,etc</p>
<p>Ok so here is the GUIDE HOW TO FIX <em>SVICHOSSST.EXE</em> or 	<em>SVICHOST.exe</em></p>
<p>1- You need a tool called &#8220;<strong>HiJack This!</strong>&#8221; (<a href="http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/HijackThis.shtml">Click here to Download it</a>)</p>
<p>2- Run it and click &#8220;DO A SYSTEM SCAN ONLY&#8221;. With that you can see all the current processes on your system (as task manager is disabled so you are not able to see the processes from there).</p>
<p>3- You will find these three following things in there.<br />
F2 &#8211; REG:system.ini: Shell=Explorer.exe SVICHOSSST.exe<br />
O4 &#8211; HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\SVICHOSSST.exe<br />
O7 &#8211; HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1</p>
<p>Check these three and click &#8220;FIX&#8221; button. It will remove these entries from your Processes.</p>
<p>4- Restart your system (<strong>its not yet fixed</strong>).</p>
<p>5- Now you would be able to run REGEDIT.</p>
<p>Goto START MENU &gt; RUN and type REGEDIT and press enter.</p>
<p>6- Okay, next, open Regedit, by navigating to Start &gt; Run &gt; Regedit</p>
<p>Then go to :</p>
<p>HKEY_CURRENT_USER&gt;Software&gt;Microsoft&gt;Windows&gt;CurrentVersion&gt;Policies&gt;System<br />
&amp;<br />
HKEY_CURRENT_USER&gt;Software&gt;Microsoft&gt;Windows&gt;CurrentVersion&gt;Policies&gt;Explorer</p>
<p>Look for values like No FolderOptions, DisableRegistryTools, DisableTaskMgr and so on on the left side of the Regedit.</p>
<p>The REG_DWORD value of these would be &#8217;0&#215;00000001 (1)&#8217; Right-click it and use the option MODIFY and make the value &#8217;0&#8242;. Now you would see it as &#8217;0&#215;00000000&#8242;</p>
<p>7- Next go to :</p>
<p>HKEY_CURRENT_USER&gt;Software&gt;Microsoft&gt;Windows&gt;CurrentVersion&gt;Run</p>
<p>Locate the entry &#8216;Yahoo Messenger&#8217;, note the wrong spelling of &#8216;Yahoo Messenger&#8217;? Delete it right away. Leave the other keys alone. The fake &#8216;Yahoo&#8217; entry tells the system to run the virus every time you boot(start) Windows.</p>
<p>8- Now goto the EDIT menu and choose FIND.</p>
<p>Search the keyword &#8216;SVICHOST&#8217; and then try &#8216;SVICHOSSST&#8217;</p>
<p>If you find any entry with this following keyword, simply remove it! and close Registery Editor.</p>
<p>(Still we have work to do! Don&#8217;t be so happy)</p>
<p>9- Right click on your MY COMPUTER and choose &#8220;EXPLORE&#8221;</p>
<p>Go to the menu TOOL &gt; FOLDER OPTIONS &gt;VIEW and select &#8220;SHOW HIDDEN FILES AND FOLDERS&#8221; and un check &#8220;HIDE EXTENSION  FOR KNOWN FILE TYPES&#8221; and press OK.</p>
<p>NOW REMEMBER &#8230; whenever ask you to goto some folder or drive. USE THE MENU AT YOUR LEFT SIDE. DO NOT DOUBLE CLICK THE FOLDER OR DRIVE ON YOUR RIGHT SIDE.</p>
<div id="attachment_118" class="wp-caption aligncenter" style="width: 310px"><a href="http://spyblogger.com/wp-content/uploads/svichossst.jpg"><img class="size-medium wp-image-118" title="svichossst virus" src="http://spyblogger.com/wp-content/uploads/svichossst-300x114.jpg" alt="svichossst virus guide" width="300" height="114" /></a><p class="wp-caption-text">Svichossst Virus Removal Guide</p></div>
<p style="text-align: center;">.:: Click Image to Enlarge ::.</p>
<p>Go to C:\WINDOWS and locate the files named SVICHOST and SVICHOSSST (first thing I said LOCATED, I never said SEARCH so donot use the SEARCH feature. You have to manually open the drive or folder and look for these files) (secondly both the files looks like a folder, their ICON is of a folder and you will feel like its a folder but its not a folder its a file)<br />
Delete them using SHIFT+DEL (so that it does not go into your recycle bin).</p>
<p>Now go to C:\WINDOWS\SYSTEM32 and look for both the files again and delete them if found. (again using Shift+DEL)</p>
<p>10- Ok we are almost there <img src='http://spyblogger.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  but dont be excited what to do with the infected USB or Removable device drive which infected your computer? Ok so same goes for it. Go to your remove able device drive. (Remember using the LEFT SIDE OF THE EXPLORE, do not double click on the right side). Locate the files SVICHOST.exe and SVICHOSSST.exe and delete them (using SHIFT+DEL).</p>
<p>Voila! You are done! TO HELL WITH SVICHOSSST virus <img src='http://spyblogger.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Restart your system and enjoy your life <img src='http://spyblogger.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://spyblogger.com/2009/05/svichossstexe-virus-removal-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

