Hi !
The virus under discussion and the other variants of the same are basically different types of the W32/Sohana-R worm. It disables the Task Manager, CMD, Registry Editor and some processes with the similar name to the windows service SVCHOST.exe. It is usually spread by the removable media storage devices like USB Flash drives.
Following are some of the names which are used by this worm to manipulate your PC integrity. SSVICHOSST.EXE, SVICHOSSST.EXE, RVHOST.EXE, SVICHOSST.EXE, etc.
As far as I know, this worm goes undetected and/or uncleaned by most commercial anti virus softwares. I am referring a couple of very good tools using which you can easily remove the virus.
To manually remove the virus from your system use the following directions.
1) There are two main software tools. One is the procexp which is a third party task manager and much more powerful than the default windows task manager. The other is a batch file. EmergencyVirusFix.bat
2) Use this third party task manager to find that process.
3) You will find a couple (maybe more) of tasks currently run with the above mentioned names or similar. Note the spelling of the task and kill all the instances.
4) Now Edit the batch file after uncompressing it from the rar file. Replace the file name with the process name you just killed.
5) Run the batch file. This will enable the Task Manager, CMD (command prompt), Folder Options and Registry Editor.
6) Now Run the registry Editor and find all the keys with the name of the processor.
7) Usually it copies in the RUN and SHELL keys with tricky names. You will have to delete all the keys except the shell which is altered in the following way:
"EXPLORER.EXE SSVICHOSST.EXE". Modify this key to just EXPLORER.EXE and remove all the extra.
8) After removing all the registry keys your system is clean. Note that the file is still there and can not be accessed in normal way. You have to install a good anti-virus to remove the file.
9) Now the most important step of your virus removing mission. Install a good anti virus e.g.
* Kaspersky ( I recommend this)
* BitDefender
* AVG
* McAfee
* PandA AV
* NOD32
* PC Cilin
Check the following sites:
http://anti-virus-software-review.toptenreviews.com/
http://www.consumersearch.com/www/software/antivirus-software/
http://www.pcworld.com/article/id,124475-page,1/article.html
I have made a very simple sequence to clean the system. If you still need any help; just contact me.
Download the archived file from:
http://files.filefront.com//;6793648;;/http://www.megaupload.com/?d=3GVNDB2DRef: http://www.putera.com/tanya/lofiversion/index.php/t32227.html