28.3.10

How to Remove RVHOST.EXE Virus From Your PC!

RVHOST.EXE is a dangerous virus. It will spread itself all over your computer and your local area network. It will also copy itself into thumbdrive and spread it to other people.

If you see this process running, you are in big trouble. But dont worry i got a solution here that will remove the virus away from your computer.

This malware is known as Nuqel.A

How to remove RVHOST.EXE?

Delete these files if they exist:
C:\WINDOWS\SYSTEM32\RVHOST.exe
c:\windows\rvhost.exe
%all drives%\new folder.exe
C:\Windows\Tasks\At1.job
Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run in the registry, and you need delete the entries which contain RVHOST.exe in them, or better yet, change them back to their appropriate paths.

Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System
“DisableTaskManager” = 1 (CHANGE IT TO 0 )
“DisableRegistryTools” = 1 (CHANGE IT TO 0 )

Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer
“nofolderoptions” = 1 (CHANGE IT TO 0)

Go to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Schedule
“attaskmaxhours” = 0 (CHANGE IT TO 24)
You shouldn’t continue to get this threat once it’s deleted, unless you come into contact with it again. May I suggest using caution with flash drives, and dont open things that you are unsure about.

Delete these files if they exist:
C:\WINDOWS\SYSTEM32\RVHOST.exe
c:\windows\rvhost.exe
%all drives%\new folder.exe
C:\Windows\Tasks\At1.job
Go to HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run in the registry, and you need delete the entries which contain RVHOST.exe in them, or better yet, change them back to their appropriate paths.

Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System
“DisableTaskManager” = 1 (CHANGE IT TO 0 )
“DisableRegistryTools” = 1 (CHANGE IT TO 0 )

Go to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer
“nofolderoptions” = 1 (CHANGE IT TO 0)

Go to:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Schedule
“attaskmaxhours” = 0 (CHANGE IT TO 24)

No comments: