

Run Program as Service by using NSSM utility. Run Application as Windows Service by using RunAsService utility. How to Run Any Application as a Windows Service. This tutorial contains step-by-step instructions on how to create a Windows service with any program in Windows 10, 8, 7 & Server OS. Although these methods are effective in most cases, in some cases there is a need to run an application at startup as a Windows service, before user's login or user's interaction. As you know, the common methods to run a program at Windows Startup is to place the program at Windows Startup folder, or to run the program at startup by using the Windows Registry, or to start the application using the Task Scheduler.

Read more: How to Remove a Surabaya Virus | eHow.If you want to run an application as a Service in Windows OS, then continue reading this tutorial. Restart the system and the virus will now be gone. For example, the D drive would be accessed by typing "DD\".ĭelete the "Autorun.inf" and "thumb.exe" files from the command prompt by typing the following commands:Ĭheck the "Autoexec.bat" files on the C drive for any entries that contain the word Surabaya and delete them. Repeat this process for all of the drives by placing the name of the drive followed by "D\". If you receive an error for "System Volume information" while running the command, ignore it. This will allow you to access the C drive. Enable show files by changing the 0 to a 1.Įxit the registry by pressing the "esc" key on your keyboard and enter the command prompt by going to the "start menu" and selecting "Run." Enter the letters "cmd" into the command prompt and press the "enter" key. You will see "CheckedValue" set at 0, which means "showfiles" are disabled. Type HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hideen\SHOWALL into the registry and press enter. Infected computers will have a high volume of entries attached to "Rundll32" that you will need to remove by removing the "Rundll Surabaya" text portion from the registry key. Search for the word "Surabaya" and delete it each time you see it. *note i think you may have to type regedit onthe search function or run command*

Immediately after, two entries will appear as "LegalNoticeCaption" and "LegalNoticeText." Delete these keys. This is the black screen that will appear when you first start the infected computer.

Access the registry by typing "regedit" at the command prompt screen.
