I caught this from my portable drive when I am doing servicing in my customers office. Seems like this one is quite annoying and even some anti-virus unable to detect it. Luckily my AOL free Kaspersky was able to catch this nasty things without any problem and also using MAVW for the clean up. Anyway, worth checking out the news below and how to removed manually.
Jamboforum - AVPO.EXE is a file recently detected by several antivirus databases. This file is yet to be determined globally as Good or Bad, therefore it is currently classified as Unknown. However if it is malware then it may well be caught by the behaviour protection in databases.
The only way to safeguard against this possible threat is by installing an antivirus (Kaspersky) which has the ability to protect you from all bad files from the instant they are determined.
DEFINITION OF AVPO.EXE
Safety Rating: Uncertain
First seen: Aug 19 2007 (GMT)
Last seen: Aug 19 2007 (GMT)
File Size: 68,727 bytes
How to Manually removed
Thanks to zobl0g.com - Run your windows from Safemode: Press (F8) before your windows startup choose Safemode, then the next step:
Step 1:
- Open up Task Manager (Ctrl-Alt-Del)
- If wscript.exe is running, end it.
- If explorer.exe is running, end it.
- Open up “File | New Task (Run)” in the Task manager
- Run cmd
- Run the following command on all your drives by replacing c:\ with other drives in turn (note: if you have autorun.inf files that you think you need to backup, do so now): del c:\autorun.* /f /a /s /q
- Go to your Windows\System32 directory by typing cd c:\windows\system32
- Type dir /a avp*.*
- If you see any files names avp0.dll or avpo.exe or avp0.exe, use the following commands to delete each of them: attrib -r -s -h avpo.exe and then del avpo.exe
- Use the Task Manager’s Run command to fire up regedit
- Navigate to HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run (as usual, take a backup of your registry before touching it!)
- If there are any entries for avpo.exe, delete them.
- Do a complete search of your registry for ntde1ect.com and delete any entries you find.
- Restart your computer.
Step 2
- Open up registry editor, search and delete all registry keys containing any of the following: avpo.exe and ntde1ect.com2. Restart your computer and boot off a windows XP bootable CD
- Choose the repair option at the initial screen
- Choose your installation and enter administrator password to log in to command console
- Type in the following commandscd \windows\system32, attrib -r -h -s avp*.*, del avp*.*, attrib -r -h -s c:\autorun.inf, del c:\autorun.inf, attrib -r -h -s ntde1ect.com (take note of the “1″ instead of “t” ), del ntde1ect.com
- Restart your computer after this
Comments
Post a Comment
Any SPAM or fake advertising will be remove from the comments