Corak the Avatar
Профи
(986)
15 лет назад
Если файл - SVSHOST.EXE, то создай любой файл с расширением .REG, перепиши в него данные ниже строки и запусти его. Далее удаляй SVSHOST.EXE в папке SYSTEM32. Это - вирус, троян.. . Метод обезвреживания разработан мной. Также поудаляй ERASEME_*.exe.
Данные:
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\don't load]
"svshost.exe"="Yes"
"tohel.exe"="Yes"
"msets.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[HKEY_USERS\.DEFAULT\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"svshost.exe"="Yes"
"msets.exe"="Yes"
"tohel.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[HKEY_CURRENT_USER\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"svshost.exe"="Yes"
"msets.exe"="Yes"
"tohel.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[HKEY_USERS\S-1-5-18\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"svshost.exe"="Yes"
"msets.exe"="Yes"
"tohel.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[HKEY_USERS\S-1-5-19\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"svshost.exe"="Yes"
"msets.exe"="Yes"
"tohel.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[HKEY_USERS\S-1-5-20\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"svshost.exe"="Yes"
"msets.exe"="Yes"
"tohel.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[HKEY_USERS\S-1-5-21-823518204-1935655697-839522115-1003\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"svshost.exe"="Yes"
"msets.exe"="Yes"
"tohel.exe"="Yes"
"eraseme_20682.exe"="Yes"
"eraseme_75057.exe"="Yes"
"Mstn.exe"="Yes"
"eraseme_*.exe"="Yes"
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\w4u9w5]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\yeyek]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\w4u9w5]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\yeyek]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\w4u9w5]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\yeyek]