amvo.exe error(might be malicious code)

Status
Not open for further replies.

pulkit1337

Right off the assembly line
a few days ago, i found a file amvo.exe in the startup files of my os(windows xp sp2), so i tried to delete it, but it couldnt find it in the system32 folder.
the path was : c\windows\system32\amvo.exe.

since then, the computer slowed down and i couldnt open the search option, see any hidden files and when i tried to open a local drive from my computer, it would open in a new window.

i got the same results even after booting into safe mode.

i then saved some software installers in g\utilites, and reinstalled windows.
now, it gives me an error :

~link~ERROR

on startup,and i cant access the utilities folder, it says access denied, not accessible.it not accessible even in safe mode.

i am using pentium d 2.8 ghz, 512 mb ram running windows xp pro sp2.
 

gk2k

gkbhat.blogspot.com
You can also do remove it using Xp installation cd.
Boot from the cd and enter the recovery console and select your os
Then cd to system32 folder and then delete amvo.exe file using del command
 

Shloeb

In the zone
Its a virus. Remove it using this method.
1. Go to Start-> run-> type msconfig, go to the startup option and remove the amvo.exe from it

1. Go To Start > Run and type REGEDIT
2. Go to HKEY_CURRENT_USER > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced
3. On the right side, double click the hidden value and give it a value of 1.
4. Same for HKEY_LOCAL_MACHINE > SOFTWARE > Microsoft > Windows > CurrentVersion > Explorer > Advanced > Folder > Hidden > SHOW ALL Change the value of Checked Value to 1.
5. Check if your Folder Option if its working now. If it works! OK you are now ready to delete the Amvo.exe virus now.

Go to your Folder Option and enable the show all the hidden files and you remove the following files if they are exist in the exact location or directory:
c:\autorun.inf
c:\u.bat
c:\amvo.exe
c:\awda2.exe
c:\d.com
c:\mvo.dll
c:\amvo1.dll
c:\windows\system32\ amvo.exe
c:\windows\system32\ awda2.exe
c:\windows\system32\ d.com
c:\windows\system32\ mvo.dll
c:\windows\system32\ amvo1.dll
c:\windows\system32\u.bat


Lastly go to Run and type cmd then type regedit, press Ctrl + F to find the files amvo.exe and delete it. After that, reboot your PC
 

gk2k

gkbhat.blogspot.com
As far as I know amvo.exe virus does not allow you to open regedit, even if it does the change in registry value will be overwritten by amvo.exe virus present in the system.
 
Status
Not open for further replies.
Top Bottom