Start > Run >
Certificates – certmgr.msc
Indexing Service – ciadv.msc
Computer Management – compmgmt.msc
Device Manager – devmgmt.msc
Disk Defragmenter – dfrg.msc
Disk Management – diskmgmt.msc
Event Viewer – eventvwr.msc
Shared Folders – fsmgmt.msc
Local Users and Groups – lusrmgr.msc
Removable Storage – ntmsmgr.msc
Removable Store Operator Requests – ntmsoprq.msc
Performance – perfmon.msc
Services – services.msc
Windows Management Infrastructure (WMI) – wmimgmt.msc
source : My Tech World
Remove RVHOST.EXE
This malware is known as Nuqel.A
How to remove RVHOST.EXE?
Delete these files if they exist:
C:\WINDOWS\SYSTEM32\RVHOST.exe
c:\windows\rvhost.exe
%all drives%\new folder.exe
C:\Windows\Tasks\At1.job
Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run in the registry, and you need delete the entries which contain RVHOST.exe in them, or better yet, change them back to their appropriate paths.
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
“DisableTaskManager” = 1 (CHANGE IT TO 0 )
“DisableRegistryTools” = 1 (CHANGE IT TO 0 )
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
“nofolderoptions” = 1 (CHANGE IT TO 0)
Go to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule
“attaskmaxhours” = 0 (CHANGE IT TO 24)
You shouldn’t continue to get this threat once it’s deleted, unless you come into contact with it again. May I suggest using caution with flash drives, and dont open things that you are unsure about.
Delete these files if they exist:
C:\WINDOWS\SYSTEM32\RVHOST.exe
c:\windows\rvhost.exe
%all drives%\new folder.exe
C:\Windows\Tasks\At1.job
Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run in the registry, and you need delete the entries which contain RVHOST.exe in them, or better yet, change them back to their appropriate paths.
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
“DisableTaskManager” = 1 (CHANGE IT TO 0 )
“DisableRegistryTools” = 1 (CHANGE IT TO 0 )
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
“nofolderoptions” = 1 (CHANGE IT TO 0)
Go to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule
“attaskmaxhours” = 0 (CHANGE IT TO 24)
Go to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Shell" = Explorer.exe RVHOST.exe (CHANGE IT TO Explorer.exe)
source : My Tech World
How to remove RVHOST.EXE?
Delete these files if they exist:
C:\WINDOWS\SYSTEM32\RVHOST.exe
c:\windows\rvhost.exe
%all drives%\new folder.exe
C:\Windows\Tasks\At1.job
Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run in the registry, and you need delete the entries which contain RVHOST.exe in them, or better yet, change them back to their appropriate paths.
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
“DisableTaskManager” = 1 (CHANGE IT TO 0 )
“DisableRegistryTools” = 1 (CHANGE IT TO 0 )
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
“nofolderoptions” = 1 (CHANGE IT TO 0)
Go to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule
“attaskmaxhours” = 0 (CHANGE IT TO 24)
You shouldn’t continue to get this threat once it’s deleted, unless you come into contact with it again. May I suggest using caution with flash drives, and dont open things that you are unsure about.
Delete these files if they exist:
C:\WINDOWS\SYSTEM32\RVHOST.exe
c:\windows\rvhost.exe
%all drives%\new folder.exe
C:\Windows\Tasks\At1.job
Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run in the registry, and you need delete the entries which contain RVHOST.exe in them, or better yet, change them back to their appropriate paths.
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
“DisableTaskManager” = 1 (CHANGE IT TO 0 )
“DisableRegistryTools” = 1 (CHANGE IT TO 0 )
Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
“nofolderoptions” = 1 (CHANGE IT TO 0)
Go to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule
“attaskmaxhours” = 0 (CHANGE IT TO 24)
Go to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Shell" = Explorer.exe RVHOST.exe (CHANGE IT TO Explorer.exe)
source : My Tech World
Subscribe to:
Posts (Atom)