Professional Documents
Culture Documents
com/
Downloads
Here are links to some great softwares (that i have created)..
HealAntiVirus
fixes many important registries and delete “autorun.inf” form all drives, pen drives as
well
so be tension-free to double click the pen drives
realtime scanning
http://piyushlabs.googlepages.com/HealAntiVirus1.31.exe (new)
Download my Crackers
Folder Lock Password Crack:
http://piyushlabs.googlepages.com/FolderLockPWCrackerFullVersion.zip
P C Security Password Crack:
http://piyushlabs.googlepages.com/PCSecurityPWCrackerFullVersion.zip
http://piyushlabs.googlepages.com/antidote.zip
Download my HEALS
Heal for SSVICHOSST virus:
http://piyushlabs.googlepages.com/Heal-SSVICHOSST.zip
These programs are witten in C/C++ and AutoIt v3. The size of these tools are in KBs. A
specific program for a specific virus, removes that virus as well as heals your system (re
gistries) from damage caused by the virus… The programs were created on WinXP
considering Windows installed on C drive. If the programs do not run or shows un-
natural behavior then please contact me. When asked to press ‘Y’ to continue, use capital
letter ‘Y’.
it makes your system free from that virus unless you install them again : ) . . .
Your anti SSVICHOSST heal dint work is there any other thing i missed or some
other way to drive away the virus???????
criss,
if it didn’t work then follow the steps by step procedure at
http://piyushlabs.wordpress.com/ssvichosst
if u get only the start up error , e.g. “Windows cannot find ssvichosst” or “error
loading SSVICHOSST”
then perform the small procedure at…
Fix for ” Windows cannot find ssvichosst” on
http://piyushlabs.wordpress.com/ssvichosst
The anti-viruses can delete the virus files but they do not repair the registries….
gud luck…
hi pramit doshi
i think its SOHANAD, ( rather SOHANAND )
if u have that virus can you please upload it somewhere from where i can get it. i
luv to experiment …
to enable RUN…
Open regedit, goto
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\
HKCM\Software\Microsoft\Windows\CurrentVersion\Policies\
some where inside u will find something like “DisableRun”.. delete that key… or
value it 0
thats all..
mithun,
dude it simply depends whats the problem u are facing.
if u have then tell me…
the common problem that one can find are alredy listed on my other pages.
heelo piyushlabs staff you are working for the world people how are facing
problems by viruses. i am thanking you for that. but i have a small problem with
my computer has attaked virus named ssvichosst.exe and i have tryed your
prosidures but the problem is still there please help us to slove this problem. and
the virus is entered in my pendrive last night now i am not able to use my
pendrive in any other computers if i am opeing my pen drive there computer also
effcted by this virus so please help us how to delete this files from pendrive. i
have tryed format but it is still there
PRAVEEN
what r the problems u r facing.
1> can u open task manager,etc?
try the step-ny-step procedure again, or d’load the heal.
if u use a lappy, then copy the taskkill.exe file into ur windows/system32 folder n
then run the program.
2> if u can see the virus file send me the complete detail of the file, its
size,verison,etc
3> at what step u r unable to fix the problem…?
dude what the c++ pro gramme u have written for the folder lock to decode the
first two letters of the password so that the user might get it but if he does ‘nt
come to know the password then what, so i tell u the new way itz what i do every
time i forget the password
1st one — always when u r logging inside the folder lock software u might
mistype the password eg: if the password is nature u might in a hurry may type
naturt the movement u type a wromg pass the wrong passwods are logged by the
windows in the registry of the folder lock logs u might check itz a very simple
way to get back the password , But remember 1 thing the mistyped password will
be in the reverse order like this trutan so guess every thing is easy in world the
path which u have to follow is first got
>> run >>type regedit>> my
computer\hkey_local_machine\software\folderlock\logs
2nd one is the most common way to unistall the folder lock without the password
is while windows boots press f5 initally & boot windows with a safe mode go to
the path where folder lock is installed press shft+del then in add or remove
programes to uninstall clear the registory
SUKANYA
open msconfig n check the startup items. uncheck the unwanted registries. have u
installed some s/w recently ?
ALOK KASHIMATH,
u have done so much of research on registries : )
so u sud be able to find out where the “exact password” is saved in registry.. if u
find out that, u can get the password, which is very simply encrypted.
i dont want to upload the complete pw tool, otherwise what will be the purpose of
such softwares, like FolderLock n PCSecurity.
DO WRITE THE PROGRAMS REALLY OR JUST COPY FROM THE NET &
UPLOAD IT BECAUSE I AM REALLY INTRESTED IN TO CREATIVITY OF
THE PROGRAMS & SOME SMALL PROGRAMS I HAVE CREATED SOME
MAY THEY R IN STILL DEVELOPING I CAME TO KNOW U R A MECH
GUY BUT U SEEM TO BE INTREASTED IN THIS FIELD
Dude, the softwares u hav written r relly cool.. Ur SSVICHOST removal program
did wonders for me.. :). Thanks a ton mate.. Really inspired by what u have done,
Any advice on improving prog skills??..
Hey piyush I downloaded the SSVICHOSST heal from your download page. But
still it is not able to remove the virus from my system. Please suggest me
something dude… Thanks in advance
VAIBHAV
if u have ssvichosst virus, it will surely go. you may have any other virus. What
are the problems u are facing?
open msconfig and check the startup items..
Try rebooting comp in “safe mode with command priompt” and enter the manual
command in CMD prompt as described in SSVICHOSST page…
Try the solution for other common viruses also…
RAJESH
dude, i am not sooo good at programming… ; )
even u can do, just u gottta learn about handling registries using C/C++. You
should search and find it urself on net, hmmm… dats a bit tedious. Coz i didn’t
find any tutorial, just a few examples.
piz
hi piyush
how to use the heal.
there r 3 exe files in zip folder
pls explain
kadam
KADAM
1 file is “taskkill.exe” copy it to C:\
2nd one is short-cut to end task the virus program.
3rd file is the main program/heal file.
Everything is mentiond inside the main program.
AIZAZ
probably ur comp is getting affected from ur mamory card, whenever u use it.
To remove virus from removable drives: :
1. First run my heal program, or follow the manual steps.
2. Make sure u can see all the hidden files, n system files. (eg. ntldr, ntdetect in
C:\)
3. If not, Open MyComputer goto Tools>Folder options>Views ,
Select “show hidden files/folders”
Uncheck “Hide protected system files”
4. Insert ur removable media,
5. Open MyComputer.
6. NEVER DOUBLE CLICK UR PEN DRIVE
7. GotoView>ExplorerBar>Folders
8. You will see a tree structure on left hand side.
9. Single click on PenDrive, in the LHS tree view, to open the pen drive.
10. Open “Autorun.inf” file in notepad n check its contents. This file auto-
launches the virus when ever u double-click the drive.
11. Delete the autorun.inf and the other virus files….
• 33. deepak singh rana | 17 December, 2007 at 12:51 pm
ihave funny ust scandel virus in my pc pls tell the right removel tool
thank u for the instruction i hav removed the virus in harddisk but in pendrive i
can’t identify any file so, using folder option i am not underlook any file.so,
please send solution with step by step process to remove the virus
DEEPAK
it happens due to some virus, which changes the attributes of all folders to
hidden/system.
and corrupts the registries, so that u cant see the hidden files.
open msconfig and check if u have the virus in ur startups.. or else this will
happen again.
DAVINDER
better follow the manual steps,
u will learn…
BALAJI
try the merging the registry,
http://piyushlabs.googlepages.com/reg_ntde1ect.reg
Never double click the pendrives.
MATT
sorry dude, i cant do anything to the hard drive killer, coz i have little knowledge
about such programs which damages the HDD and RAM…
Hi Piyush,
Im using P4 system with 126 RAM, WindowsXP, 40Gb HDD. Recently I have
noticed that my system is getting slow in the process. Please suggest me a
solution for this. I was very much impressed with your solutions particularly the
Nhatquanglan one. Even though I haven’t faced that with my PC, I suggested that
solution to my friends whose PCs, Pen Drives, and Memory Cards were infected.
SATISH
using command prompt, delete the autorun.inf file,
“del X:\autorun.inf \a”
remove the pendrive, and again insert it back.
again do the delete command to check if the file still exists.
if it doesn’t, u can easily double click ur pendrive to open.
open it and dlete the virus files…
ARUN
open msconfig, and to startups…
uncheck the varioous s/w that u dont want to load up at the startup, e.g, qtime,
etc…
u’ll find many s/w that loads up, but u dont need them at all..
RAJESH
u probably have brontok virus, or something like that that resrt comp always,
many times.
Hi,
http://piyushlabs.googlepages.com/Heal-nhatquanglan-104.zip
MAHESH
go for the manual prcedure, as described in the nhatquanglan page. coz there are
many varients of the virus, my program may not work properly.
• 48. mahindra | 8 January, 2008 at 1:27 am
hi,
thanks a lot for your brillant solution i have exchanged around 5 pendrive so far
and have decided to change my drive for 6th time but now my problem have been
rectified bloody nhatquanglan have been completely removed thanx mr now iam
an regullar visitor of this site c u
hi piyuzlab, i was able to delete the autotun.inf, thanks i waznt able to read ur
comment to aizaz, i can open now my jpeg files but again with exe extension.
muchas gracias. can i manually rename it without unwanted consequences?
PAWAN
just delete autorun.inf from other drives.
thses viruses mainly affects the drive where windows is installed + root folders of
other drives. run “Heal for SSVICHOSST” to delete autorun.inf from all drives.
ERIC
if jpg files have got exe extention, those must be worms. scan them with some
latest updates of antivirus and repair them. i dont think, changing the extention
will work. if it works, then well n good : )
Thanks….
yur patches have been effective and saved my day great!!!!
regards
sri
please
Hi.. dude,
was just googeling bout viruses bd their behaviour pattern nd got struck to your
page.. well allthough am a lawyer by profession..but love to play with
softwares… i mean doing trouble shooting nd all.. its nice thatu r helping people
to get rid of malwares nd virus… good work man.. even i do programmnig on C
but been out of touch since i started my law… as of now trying to get bk on it…
i used certain of your tools to repair my frnds comps.. who either dont have
antivirus.. or it is not update… which helped a lot.. thanks a ton man… nd keep it
up…
Hi, I have Windows98, is ur antivirus for ssvichosst run for it? I tried but no
result, what I do?
MEHUL
actually i havn’t tried on Win98. It was mad for XP. If its not giving any results,
then follow the manual procedure, as stated in the other concerning page.
I am having issues.
I’m not computer literate so I was wondering
whether you could give me step by step
instructions on how to remove the virus on my comp.
All I know is this Autolt v3: scvshosts.exe
and it asks me to put a disk in.
I like what you are doing and please keep producing more fixes…..
Please email me directly…. If you can
http://piyushlabs.googlepages.com/Heal-nhatquanglan-104.zip
DINESH
y u need the codes…??/?
btw, the codes are simply stated as in the “Manual Procedure” : )
JP
can u please post the deatils of that exe file, eg file size,version,etc
Hi
Thanks Once again
Hats Off to you
AARONIC
yes dude, i saw that..
its very sad…
i had virus in PC. removed it with antivrus. but now the C and D drive doest open
normally but opening with the window”open with”. please suggest some remedy
to this problem.
TP
this is because there exists a file named “autorun.inf” in those drives.
u need to delete them.
Start>Run>type “CMD”
del c:\autorun.inf /a /f
del d:\autorun.inf /a /f
log off and relogin
thank’s friends
• 75. gulrose | 27 February, 2008 at 7:10 pm
http://blogs.pcmag.com/securitywatch/Results-2008q1.htm
did not receive your mail. probleb still exist. funny ust virus reappear on start up
and please tell me how to run patches of other viruses like new folder, scvhost
GULROSE
please download 1.bat and 2.bat files and follow the steps when u run 1.bat file
for other viruses (wont work for some newer versions of viruses):
download and run other respective heals.
MURTUZA
thnx for that. i’ll upload today.
PRAKASH
please install a good antivirus with latest update.
hi
u r working for others thats nice, i too have a prob , my system is REBOOTING
frequently , n some it reboots immediatly when i start i.e windows, pls help me to
resolve that prob. And am not able to open my local disks when i double click( it
opens a OPENWITH )window whats the reason. plsssssssss
CHANDAN
download and run heal for ssvichosst and for ntde1ect.com
SHIVA
Start>Run>type “CMD”
type
“attrib c:\autorun.inf -h -s”
“attrib d:\autorun.inf -h -s”
and right click explore the drives, and delete the “autorun.inf” files
Log off and relogin
Download Antidote, and disable any virus program that may restrating ur comp.
JAGAN
download 1.bat and 2.bat files and run them.
Run 1.bat simply, and follow the instructions properly.
RAVI
Download Antidote, select the system startup optons.
Disbale the entries like other.exe, winsit.exe, etc
thanx good work the heal for ssivchosst.exe save me from a long work lol
Thank you so much! I’ll bookmark this page so I can visit it again in the future.
GULROSE
copy taskkill.exe to c:\
and also to c:\windows\system32\ (if u have laptop)
please use capital “Y” , when asked for
PIUSH
no.. first of all stop using my name
autorun.inf is not a virus, but just a helping file for viruses.
it helps to target to run the virus file, if u double click the Drives.
simple delete it, for removing.
if it comes back again, that means u have some active virus/trojan
Piyush,
Thanks for your solution. I was able to clean the virus from my system. I have
mentioned abt you in my blog http://rmn-
world.blogspot.com/2008/03/killerexe.html. Do check it out!
Thanks again.
• 97. rahul | 25 March, 2008 at 5:04 pm
i have tried your way to clear ssvihosst.exe virus but failed. can u tell me what to
do.when i start the system it shows that the file ssvihosst.exe is missing.
Hi !
Thanks !
RMN
thnx
RAHUL
did u try the manual process or used the heal software?
follow the last step of manual step
MUDIT
there are a lot of varients of this virus
1 thing common is that they are build on AutoIt
SARVANAN
can u send me the virus file, zipped and password protected
u may be able to fix all thses problems temprarily (u can use my heal ssvichosst)
but it can be fixed permamently after removing the virus from startups, etc
try to fix it urself:->
download my heal_for_ssvichoost.exe and rename it to a.exe and put it in
windows folder
restart in safe mode with command prompt (press F
type a.exe , press capital “Y” to run the heal
type “taskmgr” to run task manager
in the task manager, goto File>new task
run “msconfig”
disable suspected and unwanted startups
this should fix the problems
i cannot open system volume information folder .my folder option does not work
.any vbs script file is unable to run please help me.
PRADIP
users as well as administrators do not have right to open “System Vol Info” folder
in NTFS. Use heal for ssvichosst for folder option problem.i dont know y ur vbs
script is not running..
dear piyush
my right click only displays half and also sometimes it doesnt work at all. also in
the links on webpages it doesnt work at all. this problem is from today only.. i
already hav trend micro internet security installed.. but still im facin the
problem… n also the system has bcome slow….wen i right click on any folder..it
only displays..”create shortcut, delete,rename & properties” only but it doesnt
show ‘OPEN’ at all……..pls help me recover from this
SELVA
there has been possibly a severe changes/damage to the registries. Try if system
restore works…
I thank piyush lab for creating this fantastic softwares.So never stop creating
software like this
hi ..
VISHESH
sure
ANIL
check the page
http://piyushlabs.wordpress.com/regsvr/
MADHAN
mainly spreads through removable media,
take care while using pen drives.
i suggest to install Kaspersky,
and turn ON its registry graurd.
so many malwares coming up nowadays…
u ppl r really doing a gr8 job which is being appreciated by many of my frnz also
bcoz i removed the ntdetec.exe virus frm their pc
Hi Piyush,
My hard disk is making some sounds and its not getting booted. While booting a
message is showing “Primary Hard Disc Error”. But it is recognizing in BIOS. I
can see the HD Name in the IDE Configuration list.
Can suggest me a way to retrive the data from that HD, coz I have very important
files saved on that. Please help me in this regard.
Thank You.
ARUN…..
KADAM
hope u dont have Brontok virus
check the startups from MSCONFIG, and tell me..
also check if it reboots in safe mode also
Perform a “hijackThis” scan and mail me the log file…
ARUN
u can use bootable cd or floppy
or u can use Live Linux CD (best option)
or Bart PE Builder
MAJOR
u have some active malware
reply back with the complete properties of that .exe file that u get on right
click>properties
hi piyush
my system doesnt boot in safe mode at all, i.e, while trying to boot in safe mode,
it just shuts down the system.
reg ‘hijackthis’ scan, i dont know how to do it…pls explain
pls help
KADAM
open regedit and goto
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
and set
AlternateShell = CMD.exe
Wait a few secs and do refresh
If the settings are corrupted again. Then, make the settings and suddenly restart
the comp.
(I thinks this is the worst method found out by me.)
Otherwise u need to change the registry offline form BartPE CD
First try this…
U should always use “safe mode with command prompt” and make changes. Task
manager will be working. Launch files from there. Do not Launch explorer.exe\
Mail me the HiJackThis Log piyushlabs@gmail.com
Hi Piyush,
C:\WINDOWS\hinhem.scr
”http://nhatquanglan.xlphp.net/“
There was also a virus which used to make a dumplicate copy of the same folder
name.
But still, I cannot open Task Manager and regedit..they just come for fraction of
second..
Hi piyush,
Firstly i would like to thank you for extending your support to so many people in
need. Keep it up.
The virus has already started to show its effects. It has started copying files on my
drive i.e. they multiply . So even if i remove the virus, will these duplicate files
get deleted or will i have to manually del them.
• 120. Arun..... | 23 April, 2008 at 8:12 pm
Hi Piyush,
(My hard disk is making some sounds and its not getting booted. While booting a
message is showing “Primary Hard Disc Error”. But it is recognizing in BIOS. I
can see the HD Name in the IDE Configuration list.
Can suggest me a way to retrive the data from that HD, coz I have very important
files saved on that. Please help me in this regard.
Can you please explain a little bit of what happens with Live Linux CD?
Thank You
ARUN…..
hi piyush ,
}
please can u tell me abut this error
thanku,
• 123. Karim MOhammad | 1 May, 2008 at 9:26 am
Hi Piyush this is Karim from India i feel very happy on getting this files cause in
our District in all Government Officer we are facing more problem with virus and
I got from U. Thank you very much
Karim
Also at times during surfing, suddenly series of ‘h’ starts getting typed…it
appears very spooky.
Please help as to how it can be rectified.
Dear Piyush,
Thanks a lot. I got rid of the virus regsvr.exe with your help.
Hi Piyush,
Due to virus, system is creating a .exe file in each folder with the same name and
I can not access taskmanager, regedit, it does not even let me open drives by
clicking on their Icon .
After going thru you site carefully and studyig similiar cases,
I have run folllowing:
Heal-nhatquanglan-104.zip,Heal-SSVICHOSST.zip
I have even tried SAFE Mode but in safe mode also it does not let me use regedit
etc.
One more thing I woud like to share, files copied from this system shows infected
by : (when checked by NORTAN )
Virus:
Trojan Horse, W32. Blastclan, W32 Rajump
with regrads,
Hey Piyush
Thank you for your upload on how to remove SSVICHOSST.exe. I was really
having a hard time. My blessings are with you. Keep up the good work.
Hey piyush,
your antidote & your task kill & nhatquanglan worked for 2 seconds & again the
same things appear.My task manager, reg edit & folder option is not
working.please give me a solution as fast as possible so my computer can work
properly
Thanking you,
Hi Guys,
I am unable to download;
http://piyushlabs.googlepages.com/HealAntiVirus1.31.exe (new)
Can some one zip it and mail across to my mail id which is kurt.cobain@aol.in
Download my Crackers
Hi Piyush,
I have found few files with autorun.inf directing xlu8a8sy.exe and it creates many
files including v.exe, jfvkcsy.bat and xlu8a8sy.exe itself into all drives keeping
them hidden. autorun.inf runs in every few seconds. kindly help
Hey man,
U r doin a good job…of healin virus infected system…
it would be great if u made ur programs open source…
i am a beginner in computers. i down loaded all heals on your site but dont know
how to run those. for example what do you mean by ‘ copy taskkill to c:\, copy
2.bat to windows. pleadse make me understand with easy steps. how do you know
that you have autorun virus and recycler virus on your comp. are autorun.inf and
autorun.ini both viruses. and if you run heals without having viruses on your
comp will that damage your system. pl help
• 133. piyushlabs | 12 May, 2008 at 1:13 pm
SACHIN
use heal_nhatquanglan
PRASHANT
can u send me the virus file
u need a proper step by step solution for such viruses
ARUN
m not sure if it will work or not
get a Live(bootable) Linux CD, (almost all linux cds have live cd option)
eg, UBUNTU
u can ask any of ur friend or any compsci student
BHAGYESH
havnt heard, send me the virus files.
SACHIN
update ur antoivirus, it as old virus
AJAY
check ur mail
SANJIV
Download ProcessXP from sysinternals.com and end task the virus process
probably with pink color
dload and run my Heal_Antivirus
use msconfig to remive from startup
now search for file with size<2mb , *.exe and delete suspected files
SAUMIL
Download ProcessXP from sysinternals.com and end task the virus process
probably with pink color
dload and run my Heal_Antivirus
use msconfig to remove from startup
KURT
y dude, the links are working
VERMA
send me those files
DOUBTYSMURF
all the solutions are open to all as manual steps
just to make it easy to run i’ve made programs
GULROSE
copy the file “taskkill.exe” in your c drive
if u dont understand how to copy, them i can’t help u dude
it wont damage ur comp, if u run without virus in ur comp
autorun.in is helping file for viruses which spreads via pendrives
hi piyush i know how to copy but where in c drive windows or program files or
documents and setting. and what about autorun.inf virus thanx
hi piyush i also have jfvkcsy.bat in my drive like verma has, i can’t seem to delete
it and it’s autorun.inf. i have deepfreeze on my drive c: so it only infects my drive
d. can you please make somethin to remove it. thanks a lot and might i just add
that you are a real hero for helping all of us with pc problems that are beyond our
knowledge to remove. mwah!
hi piyush,
thanx a lot for giving such an good tools open for all, really u are great. well i hv
tried ur tips on 2-3 systems but i was not successful to enable cmd and regedit,
taskmgr in the first 2 system. i guess cuase i had installed avira antivir on those
systems. but when i tried for the 3rd time whre the same avira was been installed i
could able to enable cmd and regedit but not the folder options which was badly
required.
well i will try again, anyways as the comments i read it really seems your tips &
tools really works.
sanat jain
hai sir
thank u
bye
Sudip
hai sir
thank u