|
ok... dah settle...
guna portable anti virus..
dah ilang... |
|
|
|
|
|
|
|
portable antivirus ni rasanya mesti yang dari www.data0.net kan? yang tu act versi lama.. 1.5 rasanya.. sekarang ada yang versi beta.. 1.6... |
|
|
|
|
|
|
|
Reply #43 kmkd's post
dah nak keluar yang baru ya meha lama dah tunggu benda ni betul cakap kmkd portable AV ni memang berkesan cuma dia dah lama tak update yang tak best tu |
|
|
|
|
|
|
|
benda ni bukan kmkd punya la.. ramai buat av baru di malaysia ni meha.. tap link kmkd tak ingat.. nanti rajin kmkd bagi ek.. |
|
|
|
|
|
|
|
korunk!!PC aku plak kene menatang rvhost neh...kalu donlod portable tuh ok tak??
aku dah delete file rvhost tuh..tp tak jalan pon.. |
|
|
|
|
|
|
|
korunk!!~~ aku still takleh buang lgk RVHOST neh...pendrive takleh ejek..kuar jeh menatang RVHOST neh..
tp file die aku dah delete...aku jmpe kat C..pastu aku dah pakai portable AV scan..die kata takde virus.. cleanup pon aku pakai..kata takde gak..
camner nih....... |
|
|
|
|
|
|
|
adakah perlu untuk aku clean kan menatang nih dr safemode ??? |
|
|
|
|
|
|
|
task manager pon takleh bukak... |
|
|
|
|
|
|
|
49# skymania
ko donlod SERGIWA RRT tools ni : http://www.sergiwa.com/modules/news/
trial je, takpe. nnt ko check box yg ko nak tu, then klik "remove".
aku rasa tu aje kot. pastu RVHOST tu ko bleh guna hijackthis atau lelain tools untuk buang... |
|
|
|
|
|
|
|
50# bzzts
ok!~~aku terai..arap nih la pilihan tepat tuk removed... |
|
|
|
|
|
|
|
ko tick kotak NO SEARCH tak?
kalo ada, maknanya windows nak re-configure SEARCH kat windows explorer la tu.
skrg ni task manager, regedit, smua dah leh pakai la kan? |
|
|
|
|
|
|
|
55# skymania
jgn la kensel.
bende tu "search" windows.
kasi dia install kasi abis la. |
|
|
|
|
|
|
|
seme!!~`aku dah ilangkan kan mende nih seme..:pompom: |
|
|
|
|
|
|
|
57# skymania
ilangkan? cemana? |
|
|
|
|
|
|
|
Post Last Edit by bzzts at 14-1-2010 11:24
57# skymania
ilangkan? cemana?
bzzts Post at 13-1-2010 02:00
aku dpt RVHOST neh dr YM... mesti psal base siam haremmm tuh..:@
guna cara neh...kawan porem aku (nama kittie) tolong guide..- Follow these steps to completely remove this worm:
- 1-Start>RUN
- 2-Write CMD
- 3-In CMD,write "Taskkill /T /IM "RVHOST.EXE"
- then open a Notepad Start>RUn
- 4-Write "NOtepad"
- 5-in notepad paste these lines below
- On Error Resume Next
- Set shl = CreateObject("WScript.Shell")
- Set fso = CreateObject("scripting.FileSystemObject")
- shl.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Windows\Curr entVersion\Policies\System\DisableRegistryTools"
- shl.RegDelete "HKEY_CURRENT_USER\Software\Microsoft\Windows\Curr entVersion\Policies\System\DisableTaskMgr"
- shl.RegDelete
- 6- save the notepad as "Enable.VBS" and the change the file type to "All"
- 7-double click "Enable.VBS"
- 8-now Start>Run. Write "Regedit" in it and press enter
- 9- Do the following changes in Registy
-
- In the left panel, double-click the following:
- HKEY_CURRENT_USER>Software>Microsoft>
- Windows>CurrentVersion>Run
- In the right panel, locate and delete the entry:
- Yahoo Messengger = "%System%\RVHOST.exe"
- (Note: %System% is the Windows system folder, which is usuallyC:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NTand 2000, and C:\Windows\System32 on Windows XP and Server 2003.)-->
- Removing Other Entry from the Registry
-
- Still in Registry Editor, in the left panel, double-click the following:
- HKEY_CURRENT_USER>Software>Microsoft>Windows>
- CurrentVersion>Policies>Explorer
- In the right panel, locate and delete the entry:
- NofolderOptions = "1"
- Restoring Modified Entries from the Registry
-
- Still in Registry Editor, in the left panel, double-click the following:
- HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows NT>
- CurrentVersion>Winlogon
- In the right panel, locate the entry:
- Shell = "Explorer.exe RVHOST.exe"
- Right-click on the value name and choose Modify. Change the value data of this entry to:
- Explorer.exe
- In the right panel, double-click the following:
- HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>
- Services>Schedule
- In the right panel, locate the entry:
- NextAtJobId = "2"
- Right-click on the value name and choose Modify. Change the value data of this entry to:
- 1
- Close Registry Editor.
- Deleting the Malware File(s)
-
- Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
- In the Named input box, type:
- AT1.JOB
- In the Look In drop-down list, select My Computer, then press Enter.
- Once located, select the file then press SHIFT+DELETE.
- Note: AT1.JOB is a Sheduled Task so you can find this in C:\WINDOWS
Copy the Code |
|
|
|
|
|
|
| |
|