Your best source of information and news about software, software and BIOS on the internet

Vista ARTICLES TOP 50 Spyware Virus Vista SOFT Vista HELP

Virus/Spyware Removal

You are currently browsing the articles from MS Windows Vista Compatible Software matching the category Virus/Spyware Removal.

REMOVE AMVO.EXE

What is it???
AMVO.exe is a trojan/backdoor
Symptoms:

  • Folder Option is not working - you cannot enable the Folder Option or show the hidden files running into you computer.
  • Hidden file problem
  • Always open new windows in all drives
  • Error occur of the memory reference

Here are the steps for removing it manually

  1. Uncheck amvo.exe from msconfig>> startup (type msconfig in run and click on the startup tab) also and restart your system
  1. Click Start > Run and type REGEDIT
  2. Go to HKEY_CURRENT_USER > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced
  3. On the right side, double click the hidden value and give it a value of 1.
  4. Same for HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced > Folder > Hidden > SHOW ALL Change the value of Checked Value to 1.
  5. Check if your Folder Option if its working now. If it works! OK you are now ready to delete the Amvo.exe virus now.
Go to your Folder Option and enable the show all the hidden files and you remove the following files if they are exist in the exact location or directory:
c:\autorun.inf
c:\u.bat
c:\amvo.exe
c:\awda2.exe
c:\d.com
c:\mvo.dll
c:\amvo1.dll
c:\windows\system32\ amvo.exe
c:\windows\system32\ awda2.exe
c:\windows\system32\ d.com
c:\windows\system32\ mvo.dll
c:\windows\system32\ amvo1.dll
c:\windows\system32\u.bat
Lastly go to Run and type cmd then type regedit, press Ctrl + F to find the files amvo.exe and delete it. After that, reboot your PC. OK that’s it. Guys please your comments if your PC is working now for using this procedure.. Thank you..

Written by magakos on September 5th, 2008 with 1 comment.
Read more articles on Virus/Spyware Removal and All and otherSoftware.

Folder option not working ???See this…

Sometimes folder options in your PC may get disabled by some virus and after removing the virus, you can not use folder options
here i am sharing some tricks to activate folder options again

Before doing this first remove that virus from ur computer using some good AV
method:1
type “regedit” in run command and hit enter
find any of the following keys:
User Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\ Explorer
System Key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\ Explorer
Value Name: NoFolderOptions
Data Type: REG_DWORD (DWORD Value)
Value Data: 0 = show options, 1 = hide options
method:2
do: start > Run > Type gpedit.msc > hit enter > User Configuration > Administrative Templates > Windows Components > Windows Explorer > select Removes the Folder Options menu item from the Tools menu. > Right click: > Properties > Disable > Apply
done!!

Written by magakos on August 10th, 2008 with no comments.
Read more articles on Virus/Spyware Removal and All and otherSoftware.

Perlovga Removal Tool (copy.exe)

Error message: Windows cannot find ‘copy.exe’
This virus is spreading through usb flashdisk. An autorun file will work to copy this file to your local disk. so be careful whenever you connect a pendrive
Solution:
Start your computer in Safe mode and run Perlovga Removal Tool. If you have infected floppy/flash disks you can insert them and click start. You must be write enabled your usb disk during the scan process you can repeat this for every disk you have.

Related files :

Copy.exe
Copy2.exe
Temp2.exe
Autorun.inf

This tool also work with :

Trojan-Dropper.win32.Small.apl
Win32.Perlovga.bBackdoor
Win32.small.loW32

QQRob-ABXVirus.Vbs.Small.a

Download Perlovga Removal Tool

Written by magakos on August 1st, 2008 with no comments.
Read more articles on Virus/Spyware Removal and All and otherSoftware.

Remove Desktop.ini & Folder.htt virus HTML.Redlof.A

Redlof is polymorphic virus that embeds itself without any attachment to every e-mail sent from the infected system. It executes when an infected email message is viewed The HTML.Redlof.A is a very pestering virus. From what I gather, neither does it create any loss of data nor does it send any personal information across the net.

But what it does is horrible. It actually comes in the form of a script. The script is copied onto several other .htm, .html, .vbs, .asp, .htt, .jsp files on your hard drive. Then whenever any of these files are executed, the script is copied onto more files which create more files and so on.

VBS/Redlof.A@m executes directly from an infected message by using a security vulnerbility in Internet Exlorer known as Microsoft VM ActiveX Control Vulnerability. More information about the vulnerability and a fix is available from Microsoft: http://www.microsoft.com/technet/security/bulletin/ms00-075.asp

The virus also infects files with extensions “htm”, “html”, “asp”, “php”, “jsp”, “htt” or “vbs”.

Redlof drops the following infected files:

\Program Files\Common Files\Microsoft Shared\Stationery\blank.html
\Windows\System\Kernel32.dll
\Windows\web\kjwall.gif
\Windows\system32\desktop.ini

“blank.html” is used to replace the default stationaries for both Outlook and Outlook Express via registry causing that the every message sent from an infected system will carry the virus.
The “Kernel32.dll” is also set to registry so that it will be executed on the system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Kernel32

Download Removel tools

http://www.gdata.pl/kmdownload/download.php?op=getit&id=61

http://www.softpedia.com/get/Antivirus/Redlof-Remover.shtml

Written by magakos on August 1st, 2008 with no comments.
Read more articles on Virus/Spyware Removal and All and otherSoftware.

Remove Winfixer / win antivirus Pro 2007

( Also known as: Virtumonde, Msevents,and Vundo, Trojan.vundo )

WinAntiVirus Pro is a dangerous, When WinAntiVirus Pro infects your computer system, it will hijack your browser to an unfamiliar webpage like, onlinestability.com or winantivirus.com, WinAntiVirus is also a program that sends false positive scan reports and an array of pop-up advertisements, in order to entice the user into purchasing the full product. This bad application can find its way into your computer without your knowledge or consent. This spyware is associated with the famous spyware application, WinFixer.

Running Processes:

mav_startupmon.exe
uwa7pcw.exe
rtasks.exe
WinAv.exe
wa7pinst.exe


Registry Values:

2178F3FB-2560-458f-BDEE-631E2FE0DFE4
6F520BE0-9B54-4558-816F-224E67997DF3
459F4226-1AAB-43B6-9DC1-B6313EF83749
1AC5C88A-DEA7-462b-A232-04AF5CA42E7E
723D54C7-7483-4EB8-8EED-CE5B2AEA534D

Files:


WinAv.exe
uwa7pcw.exe
mav_startupmon
mav_startupmon.exe
rtasks
rtasks.exe
wa7pinst.exe
IH.exe
WinAntiVirus Pro 2007.lnk
Reinstall or Uninstall WinAntiVirus Pro 2007.lnk
WinAntiVirus Pro 2007 Manual.lnk
uwasffNT.exe
was6.exe
WinAntiVirusPro2007FreeInstall.exe
WinAntiVirus Pro 2007.lnk
WinAntiVirus Pro 2007 Scanner.lnk
WinAntiVirus Pro 2007 Scanner Online Manual.lnk
AsAgents.dll
unins000.exe
unins000.dat
Updater.exe
uwas6chk.dll
uwasffNT.exe
WinAntiVirus Pro 2007 Manual.lnk
WapCHK.dll
rpt.dll
awvtr.dll
yayyvsp.dll
fcyxx.dll
gebxyax.dll
asmngr.dll
fopnl.dll
IEFWBHO.dll
Scnkrnl.dll
settings.dll
sqlite3.dll
WAV6COM.dll
winpgi.dll
BORLNDMM.dll
SCANADWR.dll
SCANBCDR.dll
SCANLDR.DLL
SCANDOS1.dll
SCANEMUL.dll
SCANFUNC.dll
SCANMCRL.dll
SCANOTHR.dll
SCANSCR.dll
SCANTOOL.dll
SCANTROJ.dll
SCANWIN1.dll
UNACPU.dll
UNADBX.dll
unamscan.dll
UNMIME.dll
UNPACK.dll
UNPACKS.dll
UNPACKS2.dll
UNPEPACK.dll
pmmnt.exe or pmsnrr.exe

How To Remove Winfixer
1. Download the Vundo Fix http://www.atribune.org/ccount/click.php?id=4
2. Run VundoFix.exe

3. Place a check in the checkbox labeled ‘Run VundoFix as a task’. You will receive a message stating that VundoFix will close and re-open in a minute or less.

4. When VundoFix re-opens, click the OK button.

5. Click the Scan for Vundo button; when it’s finished scanner, click the “Remove Vundo” button.

6. You will receive a prompt asking if you want to remove the files, click Yes. The desktop will go blank temporarily.

7. When complete, restart your computer. The Spyware infection should now be cleaned from y our computer.

If you are still having problems and cannot remove WinFixer / Trojan.Vundo:

1. Download VirtumundoBegone http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

2. Reboot your computer into Safe Mode.

3. Double click VirtumundoBeGone.exe and follow the on-screen instructions.

4. Exit when complete, and restart the computer.

Fix From Symantec : http://securityresponse.symantec.com/avcenter/FixVundo.exe

Written by magakos on August 1st, 2008 with no comments.
Read more articles on Virus/Spyware Removal and All and otherSoftware.

Orkut Is Banned - Heap41a - win32.USBworm Removal

My friend had a problem with his computer. He was getting the following message when opening Orkut:

ORKUT IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r                                               MUHAHAHA!!

OrkutBanned
On further research I found out that this is caused by a worm called win32.USBworm. It also blocks Firefox from accessing the internet. The following message comes when opening Firefox:

I Dnt Hate Mozilla But Use IE Or Else… with title as Use Internet Explorer U Dope.

FFDisabled
And it also blocks Youtube popping up the following message:

youtube IS BANNED,Orkut is banned you fool`,The administrators didnt write this program guess who did??`r`r                                               MUHAHAHA!!

YoutubeBanned
Follow the steps below to remove this worm from the infected machine:

  1. Open Task Manager –> Processes –> Find svchost.exe under the user account (There will be others under network and system accounts. Don’t close them). There will be two svchost.exe under the user account. Kill both of them.
  2. Then go to Start –> Run –> regedit and find the following key:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
    Delete Winlogon key from the right hand pane.
  3. Enable your “Show hidden files and folders”
  4. After completing step 3, issue the following commands from the command prompt:
    Open command prompt and execute the following command:
    attrib -S -H -R C:\heap41a
    After executing the above command, execute the following command:
    rmdir /s /q C:\heap41a
    Replace C:\ with your system drive.
  5. If you are using a flash drive, remove microsoftpowerpoint.exe and autorun.inf from the drive.
  6. Go to your start menu –> All Programs –> Startup. Make sure there is no unnamed suspicious file in the startup folder.
  7. Turn off system restore and turn it on again.
  8. Restart your computer.

Alt method

Download it and fix the Problem

Hopefully this will remove the worm from the infected system. Please tell us your experiences about this. If you have any doubts, please ask me via comments below.

Written by magakos on August 1st, 2008 with 1 comment.
Read more articles on Virus/Spyware Removal and All and otherSoftware.

« Older articles

No newer articles