How to Get Rid of svchost.exe Virus

  posted by: Dennis Aguilar




Svchost.exe similary named file Scvhost.exe is a worm malware programs

Svchost.exe or also known as Generic Host Process for Win32 Services is a vital part of your system, Obviously, when you remove the svchost exe your operating system will not startup at all because a lot of processes depend on this file. You can see the svchost.exe in the list of running processes in the Task Manager when you press the CTRL + ALT + Del. The path of this file is usually C:\windows\system32\svchost.exe.  Most of the users are wondering what this svchost exe is, because most of the time you will see more than once of svchost.exe processes in the Task Manager.

I have said that svchost exe is a vital part of your system and should not be removed but be reminded that there is also similarly named file like the scvhost.exe which is not a system file but a kind of worm malware programs. Notice that it can be easily mistaken as a system file and not a virus at first glimpse.  Look (svchost.exe -> scvhost.exe virus). Almost similar, right? This virus is also known as the W32/YahLover.Worm.gen and Win32/Autorun.R.worm.

This malware usually spread through Yahoo Messenger. So, accepting invitation from unknown friend is one sure way to get infected with this scvhost.exe virus. What does this virus do is that it disable or blocks the Task Manager and also the Registry Editor and install itself in the autorun.inf file. The malware spreads by copying itself in the shared folders and then remotely install itself in the registry.

How to get rid of scvhost.exe virus:

1. You need to run your system on safe mode, so boot your system and while booting press f8, then choose the Safe Mode.

2. Once you’re on safe mode, go to command prompt by clicking the Start -> Run -> and then type the “cmd”.

3. Command prompt opens, now let’s go to this path C:\Windows\System32 by typing the CD C:\Windows\System32 then enter, Once in the folder, type the following then press enter:

  • attrib -h -r -s scvhost.exe
  • attrib -h -r -s blastclnnn.exe
  • attrib -h -r -s autorun.inf

Note: What are we doing here is that we are changing the attributes of these files for us to be able to delete the files because they are set to hidden,system,and read-only attribute.

4. We can now delete the infected files. Type the following in the command prompt and press enter:

  • del scvhost.exe
  • del blastclnnn.exe
  • del autorun.ini

5. Type CD\ the press enter, then type the following: then press enter

  • attrib -h -r -s autorun.inf
  • del “autorun.inf

6.  Now we have to remove some entries on the registry, type the “regedit” on the command prompt and press enter.
Registry Editor opens, now look for this startup key: HKEY_CURRENT_USER\Software\Microsoft\Window\CurrentVersion\Run. then delete the Yahoo! Messenger entry with the value “c:\windows\system32\scvhost.exe“.

7. Find this key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and then edit the “shell” entry with the value “explorer.exe, scvhost.exe” into “explorer.exe“.

8. Look for this key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ . and delete the following subkeys:

  • RpcPatch
  • RpcTftpd

9.  Reboot the PC and you’re done.

Removing this virus manually may be difficult If you are not a techie type person.  You might want to consider installing your PC with spyware removal application such as NOD32 or any other strong spyware removal application for  you to easily get rid of this virus.


You might also like

Kim Yuna Won a Gold Medal at 2010 Olympics at Vancouver
Kim Yuna - The hot figure skater in South Korea just won a gold medal on thursday (feb 25) a gold medal...

How Many Calories are in an Egg
Most of the foods that we eat such as the bread that we eat in the morning contain egg. Egg is one...

Jocelyn Wildenstein Before and After Plastic Surgery
Right after I’ve posted an entry about Bruce Jenner’s cosmetic surgery which has gone wrong. I...

World’s Fattest Baby at Birth – Heaviest Baby Ever Born
A lucky mother gave birth to an extraordinary baby.  It was a baby girl with the name Nadia Khalina....

5 Responses

kyle Says:December 9th, 2010 at 9:50 pm

This program is not a virus,its a startup task that is sometimes blcoked due to configuration,and it needs accsess cause of it being blocked.To stop it from coming up,go to control panel and manage startup tasks.Find it,disable it,it should be right there.
Here is were the actually file is,DO NOT DELETE IT!Unless u wanna buy a new computer or hours of tech support.It is located at C:/windows/system32/ this can be found under computer,its alphabeticly ordered so jsut try and find it,and btw its not a folder lol.THIS WAS FOUNBD ON WINDOWS IT MAY NOT BE THE SAME FOR MAC!

Denz Says:November 27th, 2010 at 7:08 pm

Welcome tarzen, we’re so happy that you were able to remove the svchost.exe virus by doing the instruction here.

tarzen Says:November 27th, 2010 at 12:13 am

wow, thanks dear for such information, it really helped, be blessed.

austin Says:June 7th, 2010 at 2:31 pm

I tried this but I have it on my flash drive is that any different? I typed in F: instead at the beggining but I dodn’t think it worked :(

Richard Says:January 11th, 2010 at 3:12 am

Thank you for teaching how to remove svchost.exe virus. I was able to remove it manually in my computer.

Join Us On Facebook

Please Wait 60 Seconds...!!!Skip