Îäíàê òâîðö³ â³ðóñ³â íå ìîãëè óïóñòèòè íàñò³ëüêè çðó÷íó ìîæëèâ³ñòü, ³ îñü ç`ÿâèâñÿ â³ðóñ, ùî ìຠòó æ íàçâó, â çâ`ÿçêó ç ÷èì íåäîñâ³ä÷åíîìó êîðèñòóâà÷ó ñêëàäíî ³äåíòèô³êóâàòè éîãî â äèñïåò÷åð³ çàâäàíü ³ âçàãàë³ âèÿâèòè éîãî ïðèñóòí³ñòü â ñèñòåì³. Òðèâîæíèì ñèìïòîìîì ïðèñóòíîñò³ öüîãî â³ðóñó â ñèñòåì³ ìîæå ñòàòè ëèøå ïîâ³äîìëåííÿ ïðî ïîìèëêó, ïîâ`ÿçàíó ç svchost.exe ³ ïîâ³äîìëÿº êîðèñòóâà÷åâ³ ïðî òå, ùî «ïàì`ÿòü íå ìîæå áóòè read».  öüîìó âèïàäêó ñë³ä íåãàéíî âæèòè çàõîä³â, ùî äîçâîëÿþòü âèäàëèòè svchost:

1. ³äêðèéòå ðåäàêòîð ðåºñòðó (ââåä³òü êîìàíäó regedit ó â³êí³ «Âèêîíàòè» àáî êîìàíäíîìó ðÿäêó), çíàéä³òü êëþ÷ [HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices] "PowerManager"="% WinDir% svchost.exe" ³ âèäàë³òü éîãî.

2. ³äêðèéòå ìîäóëü óïðàâë³ííÿ ñëóæáàìè Windows (Ïóñê - Ïàíåëü óïðàâë³ííÿ - Àäì³í³ñòðóâàííÿ - Ñëóæáè), çíàéä³òü ñëóæáó PowerManager ³ çóïèí³òü ¿¿ (êëàöí³òü ïî íàçâ³ ñëóæáè ïðàâîþ êíîïêîþ ìèø³ ³ âèáåð³òü «Çóïèíèòè» â êîíòåêñòíîìó ìåíþ, àáî âñòàíîâ³òü êóðñîð íà íàçâó, à ïîò³ì íàòèñí³òü ïîñèëàííÿ «Çóïèíèòè» â ë³â³é ÷àñòèí³ â³êíà).

3. ³äêðèéòå Äèñïåò÷åð çàâäàíü ³ çàâåðøèòå ïðîöåñ òðîÿíñüêî¿ ïðîãðàìè.

4. Âèäàë³òü ôàéëè:



  • % System% svchostc.exe

  • % System% svchosts.exe

  • % WinDir% svchost.exe

  • % WINDIR% svchost.com

  • % Windir% SYSHOST.DLL

  • % WinDir% msrt32.dll

  • % WinDir% sysini.ini

  • % WinDir% msin32.dll

  • % WinDir% nostar.ini

  • % Temp% c1.txt

  • % Temp% c2.txt

  • % Temp% c3.txt

  • % WINDIR% svchost.com

  • % Windir% SYSHOST.DLL

  • % WinDir% msrt32.dll

  • Áóäüòå óâàæí³: «ñïðàâæí³é» svchost çíàõîäèòüñÿ â ïàïö³% WINDIR% system32. Éîãî âèäàëÿòè íå ïîòð³áíî.


5. Ùîá îñòàòî÷íî âèäàëèòè svchost, íåîáõ³äíî ïðèáðàòè àâòîìàòè÷íèé çàïóñê òðîÿíñüêî¿ ïðîãðàìè ç ðåºñòðó. Çàïóñò³òü ðåäàêòîð ðåºñòðó, çíàéä³òü êëþ÷ [HKLMSoftwareMicrosoftWindowsCurrentVersionRun] "svchost" = "% WinDir% svchost.exe" ³ âèäàë³òü éîãî.

6. Çíàéä³òü êëþ÷ [HKCRexefileshellopencommand]. Çì³í³òü éîãî çíà÷åííÿ ç% WINDIR% svchost.com "% 1" % * Íà "% 1" % *

7. Çíàéä³òü êëþ÷ [HKLMSoftwareMicrosoftWindows NTCurrentVersionWinLogon] ³ çì³í³òü éîãî çíà÷åííÿ ç "Userinit"="% System% userinit.exe ,,% Windir% svchost.exe%" íà "Userinit"="% System% userinit.exe,"

8. Çíàéä³òü êëþ÷ [HKLMSoftwareMicrosoftWindowsCurrentVersionRun] ³ âèäàë³òü ïàðàìåòðè "Systems" = "% WinDir% svchost.exe" ³ "Online Service"="% WinDir% svchost.exe"