Enable Reg settings..

gpedit/user conf/adm temp/system/prvnt access to reg editin tools/disabled..

Enable task manager
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0 /f

USER CONFIG>ADMINISTRATIVE TEMPLATES>SYSTEM>CTRL-ALT-DEL OPTIONS

Double click on Remove Task Manager….
click on DISABLED



Enable Folder options..
local machine/win/current version/policies/explorer..
NoFolderOptions = 0



How To Manually Remove SCVHOST.EXE Virus?


In some antivirus they are detected as W32/YahLover.Worm.gen from McAfee Antivirus and Win32/Autorun.R.worm from NOD32

Solution:

* Restart your PC and press F8 and select the option Safe Mode Command Prompt Only
* And after you log-in the command prompt you must log-in as Administrator.
* Type cd C:\windows\system32
* Type dir /ah, to display all hidden files on this directory folder. You will see the following files which is used by the virus to spread itself: AUTORUN.INI, BLASTCLNNN.EXE, and SCVHOST.EXE
* Type ATTRIB -H -R -S SCVHOST.EXE
* Type ATTRIB -H -R -S BLASTCLNNN.EXE
* Type ATTRIB -H -R -S AUTORUN.INI
* Type DEL SCVHOST.EXE
* Type DEL BLASTCLNNNN.EXE
* Type DEL AUTORUN.INI
* Type CD\
* Type ATTRIB -H -R -S AUTORUN.INF
* Type DEL AUTORUN.INF

You are almost done, reboot your PC.

Go Start Menu and click the Run and type the REGEDIT command. Take note guys before make any changes into your Registry Editor you must make a full back-up to your registry to avoid system errors. :)

Look the location entry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, if you see an entry Yahoo! Messengger (it’s spelled like this) with a value c:\windows\system32\scvhost.exe, Delete this entry.

Look the location entry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, in the entry named: SHELL, a value = Explorer.exe,SCVHOST.EXE. Edit this value, delete the SCVHOST.EXE only and the value must be Explorer.exe. Once you delete all this value, your computer will not login anymore.

We are now done. Please Restart your PC now.


Adult finder virus
When do a search for adult or friend or something. You will find a folder located in HKEY Local Machine / Software entitled IasAdp. You can also just do a search for "iasadp". Look at that folder. Do you see the file SHGINASN.xml? That is the file that is fucking our computers.

Do two things. DELETE the folder IasAdp from the registry. Then do a search of your hard drive (Start -> Search -> all files and folders) for "SHGINAS". There should be an XML file called SHGINASN.xml and a DLL file called SHGINAS.dll, both should be located in C:/Windows, if you have a comptuer like mine. DELETE THOSE FILES and anything else that comes up in your search that has that name. For some reason, if I selected everything it didn't let me delete the files, but I could delete them one by one.