Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42947
  • Total Topics: 16146
  • Online Today: 4867
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: Malware that slows down your starup - amvo.exe  (Read 3797 times)

0 Members and 1 Guest are viewing this topic.

F3RLs

  • Guest
Malware that slows down your starup - amvo.exe
« on: 14. March 2009., 23:28:25 »
Recently one of kids decided to visit crack-keygen-related websites over internet.
As result the laptop got infected with some worm/malware/spyware called 'amvo.exe'

The symptoms were:
 - Slow or frozen processor at startup
 - Almost unable to use input devices - HID, etc
 - Unable to open Task Manager

The solution I've used:
 1. Boot with Safe Mode
 2. Terminate 'explorer.exe' process with Task Manager and Open Windows Shell (command prompt) only
 2. Search and Delete following files; amvo.exe, amvo0.dll, avpo.exe, kavo.exe, kavo0.dll
 3. Unregister amvo.exe from startup (use msconfig and regedit)
 4. Delete any registry entry with string 'amvo.exe'
 5. Reboot

After that the laptop started up flawlessly. There are a lot of names for this amvo.exe.
Since VirusScan Enterprise 8.5i with latest sdat/dat/patch could not detect it, I suggest
to look for amvo.exe IF your computer is not starting up properly.

Hope everyone get their computer virus-free.

Samker's Computer Forum - SCforum.info

Malware that slows down your starup - amvo.exe
« on: 14. March 2009., 23:28:25 »

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: Malware that slows down your starup - amvo.exe
« Reply #1 on: 14. March 2009., 23:33:15 »

Thank you, for this very useful information's.  :thumbsup:

Maybe you have info. did other AV Companies (Kaspersky, Symantec...) detect this Malware?

 

F3RL

  • SCF Advanced Member
  • ***
  • Posts: 171
  • KARMA: 18
  • Gender: Male
Re: Malware that slows down your starup - amvo.exe
« Reply #2 on: 14. March 2009., 23:40:38 »

Maybe you have info. did other AV Companies (Kaspersky, Symantec...) detect this Malware?


I've used NOD32, BitDefender, Norton AV 2006 and using VSE8.5i P7.
None of those could not detect or de-infect this nasty program.
It's best practice to remove it by yourself.
P.S. I think I posted this without logged in so
my name is 'F3RLs' since it said 'F3RL' is reserved ?!
well? understand ma bad English.

Samker

  • SCF Administrator
  • *****
  • Posts: 7528
  • KARMA: 322
  • Gender: Male
  • Whatever doesn't kill us makes us stronger.
    • SCforum.info - Samker's Computer Forum
Re: Malware that slows down your starup - amvo.exe
« Reply #3 on: 14. March 2009., 23:50:41 »

Ok, my friend. We will watch carefully this infection.  :police:


Quote
P.S. I think I posted this without logged in so
my name is 'F3RLs' since it said 'F3RL' is reserved ?!

That's probably because you "own - register" Forum UserName F3RL and Guest don't have possibility to choose them...

Anyway, for me it's much better to post comments after Log in.



 




haz

  • SCF Advanced Member
  • ***
  • Posts: 117
  • KARMA: 26
  • Gender: Male
Re: Malware that slows down your starup - amvo.exe
« Reply #4 on: 15. March 2009., 16:48:25 »
I've had the same problem in the company before, and these were the steps I made too to overcome the problem, Thanks :)

Samker's Computer Forum - SCforum.info

Re: Malware that slows down your starup - amvo.exe
« Reply #4 on: 15. March 2009., 16:48:25 »

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising