- You can't see hidden files and folders, even if you try modifying registry.
- Whenever you double click on drive icon on My Computer, it takes some time to open and always opens in new window.
- Your PC becomes a little slower.
- The Process is packed and/or encrypted using a software packing process
- This Process Creates Other Processes On Disk
- This Process Deletes Other Processes From Disk
- Loads and Executes a System Driver File
- Writes to another Process's Virtual Memory (Process Hijacking)
- Registers a Dynamic Link Library File
- The Process is polymorphic and can change its structure
- Violates Prevx File Security Settings
- Executes a Process
- Adds a Registry Key (RUN) to auto start Programs on system start up
- The process hooks code into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents
- Modifies Windows Initialization And System Settings Used On Start up
- This problem can be a caused by a backdoor/Trojan amvo.exe
- amvo.exe is bundled with several other worms/files some of them are
- 80avp08.com
- dosocom.com
- usdeiect.com
- xfoolavp.com
- autorun.inf
- Nideiect.com
- u.bat etc..
- These files are stored on the directories i.e. C:\, D:\ etc. and also on C:\windows\system32\amvo.exe
- You wouldn't be able to delete any of these files. Not even in Safe mode because it adds a autorun registry which loads amvo on boot.
- KILL all the processes like AMVO.exe or AVPO.exe
- Type "msconfig" without quote in run and press Enter.
- Go to startup tab and uncheck any entry on amvo.
- Type "cmd" without quote in run
- type "d:" and then press Enter
- type autorun.inf and then press Enter
- a file will open in notepad. this would have the name of the .exe/.bat/.com file in it, which is mounted at the boot time.
- Type "regedit" without quote in run and press Enter.
- Press Ctrl+F and type amvo, do the search again and again and delete all the related entries.
- Press Ctrl+F and type u.bat, do the search again and again and delete all the related entries.
- Press Ctrl+F and type amva, do the search again and again and delete all the related entries. Generally it should be HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\amva
- search for the registry of file name which was entered in autorun.inf and delete all entries.
- Go to regedit and then HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer \Advanced\Folder\Hidden\SHOWALL
- Double click on the entry called CheckedValue and replace the 0 with 1.
- Now Close all the windows and Press Ctrl+E to open the explorer.
- Enable the hidden option from the folder options.
- Delete all the malicious files as mentioned above.
- Your computer is now trojan free.
- Find all the amvo related files and delete them. (some of them are amvo0.dll, amvo1.dll etc.)
Generally this Trojan travels through a USB drive. so better explorer USB drive rather than opening it.
0 comments:
Post a Comment