Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Reply
 
LinkBack Thread Tools Display Modes
Old 25-01-2012, 07:00 PM   #1 (permalink)
Apprentice
 
KRISHI101's Avatar
 
Join Date: May 2008
Posts: 58
Exclamation How to Remove remaining start up - RUN regestry virus..


I had virus named sservice.exe but i removed it by using IOBIT malware,
but now whenever i start up my PC suddenly error message comes on screen...

cant find C:\WINDOWS\system\sservice.exe

it is so much irritating..

i know it is in registry RUN, but i cant find it..
it is always comes on screen like it is stored in registry to RUN when window starts..

i have WindowsXP service pack 3..
i have used Tuneup utility program to search in registry but cant find it..

sorry for my bad grammar..
KRISHI101 is offline   Reply With Quote
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 25-01-2012, 10:09 PM   #2 (permalink)
Sam
will be back
 
Sam's Avatar
 
Join Date: Jan 2010
Location: Guwahati
Posts: 10,135
Default Re: How to Remove remaining start up - RUN regestry virus..

iobit antimalware is a joke. use malwarebyte instead.

for the program, try checking if its present in system configuration. else try hijack this. also do a scan with malwarebyte if traces of this virus is still left.
Sam is online now   Reply With Quote
Old 26-01-2012, 01:07 AM   #3 (permalink)
Off for a while.
 
dashing.sujay's Avatar
 
Join Date: Nov 2009
Location: Bhopal
Posts: 2,653
Default Re: How to Remove remaining start up - RUN regestry virus..

Check the "sservice.exe" entry in following keys-

1) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

2) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce

3) HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

4) HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\RunOnce

Also search manually "sservice.exe".

Hope this helps.
__________________
Sony Vaio CB35-> i5-2430M | 6630M | 4GB | 1080p | Backlit Keyboard

Read before asking / messaging any moderator for any query: FAQ + answers for new members

Drop Box: Get 500MB free

dashing.sujay is offline   Reply With Quote
Old 26-01-2012, 06:14 PM   #4 (permalink)
Stuck in Time...
 
Vyom's Avatar
 
Join Date: May 2009
Location: Land of Logic
Posts: 2,281
Default Re: How to Remove remaining start up - RUN regestry virus..

Try CCleaner first to remove the culprit program from running at startup.
If that doesn't work, try Autoruns for thorough analysis of which things are running during startup, and disable them.

But, before that you need a scan from a good and updated antivirus.

If all fails then,...

Spoiler:
FORMAT
__________________
Marty: Hey, Doc, we better back up. We don't have enough road to get up to 88.
Doc Brown: Roads? Where we're going, we don't need, "roads!" :)

──── On the Internet you can be Anything you want. It's Strange that, so many people choose to be Stupid! ────
Vyom is offline   Reply With Quote
Old 28-01-2012, 10:45 AM   #5 (permalink)
Human Spambot
 
Join Date: Nov 2008
Location: Guwahati
Posts: 5,798
Default Re: How to Remove remaining start up - RUN regestry virus..

Get any good free AV like Avira. install it in safe mode. do a full scan. remove virus.
If virus still remains, you might have to use a online AV like- HouseCall - Free Online Virus Scan - Trend Micro USA
__________________
My Photography page on- Flickr

Follow me on - Twitter
thetechfreak is offline   Reply With Quote
Old 28-01-2012, 02:29 PM   #6 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: Bhopal, India
Posts: 1,930
Default Re: How to Remove remaining start up - RUN regestry virus..

I will highly recommend you to scan your whole PC using following with latest definitions:

* Free Antivirus: Trial Versions
and
* Malwarebytes : Malwarebytes Anti-Malware PRO removes malware including viruses, spyware, worms and trojans, plus it protects your computer

If possible, analyze your PC with HijackThis and analyze the log here: HijackThis Logfileauswertung

There may be multiple malware on your PC
__________________
- MrinTech :)
mrintech is offline   Reply With Quote
Old 28-01-2012, 04:10 PM   #7 (permalink)
Apprentice
 
KRISHI101's Avatar
 
Join Date: May 2008
Posts: 58
Post Re: How to Remove remaining start up - RUN regestry virus..

i have installed AVIRA premium trial version + malwarebytes

and i also run msconfig to search sservice.exe startup registry,,,
it was in hkcu-software-microsoft-windowsNT-current version-windows-RUN

and i deleted it,,

and also run quick scan with malwarebytes..
it has found a .dll file with big numbering name..

now at start-up i found only one error "cant find sservice.exe" instead three error before..
it means there is also one hidden registry, which is not showing in msconfig..

and i think there is no virus left in PC..
because nothing unusual is happening in PC only startup error is remained..
KRISHI101 is offline   Reply With Quote
Old 28-01-2012, 05:33 PM   #8 (permalink)
Apprentice
 
Join Date: Aug 2010
Posts: 55
Default Re: How to Remove remaining start up - RUN regestry virus..

Use autoruns to cleanuup....its a very powerful utility:
Autoruns for Windows

Use following guide to work with it:
Using Autoruns Tool to Track Startup Applications and Add-ons - How-To Geek
rawgeek is offline   Reply With Quote
Old 30-01-2012, 08:53 PM   #9 (permalink)
Apprentice
 
KRISHI101's Avatar
 
Join Date: May 2008
Posts: 58
Default Re: How to Remove remaining start up - RUN regestry virus..

Quote:
Originally Posted by rawgeek View Post
Use autoruns to cleanuup....its a very powerful utility:
Autoruns for Windows

Use following guide to work with it:
Using Autoruns Tool to Track Startup Applications and Add-ons - How-To Geek
Thanks RAWGEEK its a great utility..
i found the last remained registry entry..
it was in HKLM-----windowsNT-currentversion-winlogon-shell-sservice.exe
and delete it..

and one more thing..
my malwarebytes is showing that it has blocked
222.186.42.186
and something 192.... also

what that means?
is there still any virus?

sorry..

as i seen in malwarebytes LOG
2012/01/30 03:04:21 +0530 MASTER Administrator IP-BLOCK 109.235.55.11 (Type: outgoing)
2012/01/30 03:04:24 +0530 MASTER Administrator IP-BLOCK 109.235.55.11 (Type: outgoing)

and..

2012/01/30 20:42:50 +0530 MASTER Administrator IP-BLOCK 222.186.42.186 (Type: incoming)

can anyone clarify me what this mean?
KRISHI101 is offline   Reply With Quote
Old 30-01-2012, 09:55 PM   #10 (permalink)
Off for a while.
 
dashing.sujay's Avatar
 
Join Date: Nov 2009
Location: Bhopal
Posts: 2,653
Default Re: How to Remove remaining start up - RUN regestry virus..

Attack from 222.* is by some malicious script run on some site which you tried to open.

Attack from 192.* may be DNS Cache poisoning attack. Check your firewall. If antivirus has not inbuilt firewall, enable windows firewall.
__________________
Sony Vaio CB35-> i5-2430M | 6630M | 4GB | 1080p | Backlit Keyboard

Read before asking / messaging any moderator for any query: FAQ + answers for new members

Drop Box: Get 500MB free

dashing.sujay is offline   Reply With Quote
Old 31-01-2012, 09:43 PM   #11 (permalink)
Apprentice
 
KRISHI101's Avatar
 
Join Date: May 2008
Posts: 58
Default Re: How to Remove remaining start up - RUN regestry virus..

I observe a thing..

when i try to download from torrent, at the same time malwarebytes shows these blocking ip addresses..

so i came to know that it was causing by torrent downloading and malwarebytes is blocking some malicious sites..
KRISHI101 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by chris
- by icebags

Advertisement




All times are GMT +5.5. The time now is 02:28 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2