VIRUS REMOVAL [Computer Troubleshooting... [amvo.exe amvo0.dll ampo.exe amvol.dll xfoolavp.com and autorun.inf] virus issues…]

‹‹‹ Previous Post Next Post ›››
January 3, 2008
By Utkarsh

[UPDATE] Download USB FIREWALL to protect your computer from this virus or remove it.

Recently I had a big time trouble with my computer as all the drives failed to open on double clicking and showed me a application selection window instead. After searching through the running processes and other settings I found that the show hidden files options in the folder options was also not working.

With the help of one of my friends [MOHIT] I fixed the issues.

The problem was due to amvo.exe amvo0.dll ampo.exe amvol.dll xfoolavp.com usdeiect.com and autorun.inf present in every drive’s root.

The fix works as follows…

open task manager (if ur task manager doesnt open and shows errors and warnings then use this tool ) and end task the above mentioned processes if u see them in the running process list from the processes pane. Then goto applications pane and click on new task and type in cmd or command. Once at the command prompt type in “cd\” without the quotes to goto the root of the current drive. Then type “del <name.extension> /f /a /s /q”

where <name.extension is the name> of the files above mentioned (this menthod can also be used to force delete any unwanted file ) use this method to delete all above mentioned from the root of every drive.

After this open registry editor by clicking on new task and typing in “regedit” without quotes. Then goto HKCU > software >microsoft >windows >current version > explorer > advanced > then look for the hidden key in the right pane and change the value to 1 from 2.

And to fix the issues with drives not opening or search opening up on double click download this .reg (right click and save target as) file and double click it and add to your registry.

or do this…

copy every under this line paste in notepad save with .reg extension on ur desktop and double click it

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\Directory\shell]

@=”Open”

[HKEY_CLASSES_ROOT\Directory\shell\Explore]

[HKEY_CLASSES_ROOT\Directory\shell\Explore\command]

@=”%SystemRoot%\\Explorer.exe /e,/root,\”%1″

[HKEY_CLASSES_ROOT\Directory\shell\Explore\ddeexec]

@=”[ExploreFolder(\"%l\", %I, %S)]”

“NoActivateHandler”=”"

[HKEY_CLASSES_ROOT\Directory\shell\Explore\ddeexec\application]

@=”Folders”

[HKEY_CLASSES_ROOT\Directory\shell\Explore\ddeexec\topic]

@=”AppProperties”

[HKEY_CLASSES_ROOT\Directory\shell\find]

“SuppressionPolicy”=dword:00000080

[HKEY_CLASSES_ROOT\Directory\shell\find\command]

@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\

00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\

65,00,00,00

[HKEY_CLASSES_ROOT\Directory\shell\find\ddeexec]

@=”[FindFolder(\"%l\", %I)]”

“NoActivateHandler”=”"

[HKEY_CLASSES_ROOT\Directory\shell\find\ddeexec\application]

@=”Folders”

[HKEY_CLASSES_ROOT\Directory\shell\find\ddeexec\topic]

@=”AppProperties”

[HKEY_CLASSES_ROOT\Directory\shell\Open]

“BrowserFlags”=dword:00000010

“ExplorerFlags”=dword:00000012

[HKEY_CLASSES_ROOT\Directory\shell\Open\command]

@=”%SystemRoot%\\Explorer.exe /idlist”

[HKEY_CLASSES_ROOT\Directory\shell\Open\ddeexec]

@=”[ViewFolder(\"%l\", %I, %S)]”

“NoActivateHandler”=”"

[HKEY_CLASSES_ROOT\Directory\shell\Open\ddeexec\application]

@=”Folders”

[HKEY_CLASSES_ROOT\Directory\shell\Open\ddeexec\topic]

@=”AppProperties”

[HKEY_CLASSES_ROOT\Directory\shell\Openddeexec]

[HKEY_CLASSES_ROOT\Directory\shell\Openddeexec\ifexec]

@=”[]”

[HKEY_CLASSES_ROOT\Folder\shell]

@=”open”

[HKEY_CLASSES_ROOT\Folder\shell\explore]

“BrowserFlags”=dword:00000022

“ExplorerFlags”=dword:00000021

[HKEY_CLASSES_ROOT\Folder\shell\explore\command]

@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\

00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\

65,00,20,00,2f,00,65,00,2c,00,2f,00,69,00,64,00,6c,00,69,00,73,00,74,00,2c,\

00,25,00,49,00,2c,00,25,00,4c,00,00,00

[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec]

@=”[ExploreFolder(\"%l\", %I, %S)]”

“NoActivateHandler”=”"

[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec\application]

@=”Folders”

[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec\ifexec]

@=”[]”

[HKEY_CLASSES_ROOT\Folder\shell\explore\ddeexec\topic]

@=”AppProperties”

[HKEY_CLASSES_ROOT\Folder\shell\open]

“BrowserFlags”=dword:00000010

“ExplorerFlags”=dword:00000012

[HKEY_CLASSES_ROOT\Folder\shell\open\command]

@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\

00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\

65,00,20,00,2f,00,69,00,64,00,6c,00,69,00,73,00,74,00,2c,00,25,00,49,00,2c,\

00,25,00,4c,00,00,00

[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec]

@=”[ViewFolder(\"%l\", %I, %S)]”

“NoActivateHandler”=”"

[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec\application]

@=”Folders”

[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec\ifexec]

@=”[]”

[HKEY_CLASSES_ROOT\Folder\shell\open\ddeexec\topic]

@=”AppProperties”

[HKEY_CLASSES_ROOT\Drive\shell]

@=”open_[1]”

[HKEY_CLASSES_ROOT\Drive\shell\find]

“SuppressionPolicy”=dword:00000080

[HKEY_CLASSES_ROOT\Drive\shell\find\command]

@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\

00,5c,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,\

65,00,00,00

[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec]

@=”[FindFolder(\"%l\", %I)]”

“NoActivateHandler”=”"

[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec\application]

@=”Folders”

[HKEY_CLASSES_ROOT\Drive\shell\find\ddeexec\topic]

@=”AppProperties”

[HKEY_CLASSES_ROOT\Drive\shell\open]

[HKEY_CLASSES_ROOT\Drive\shell\open\command]

@=”%SystemRoot%\\Explorer.exe /idlist,%I,%L”

[HKEY_CLASSES_ROOT\Drive\shell\open\ddeexec]

[HKEY_CLASSES_ROOT\Drive\shell\open\ddeexec\topic]

@=”AppProperties”

_______________________________________ dont copy this line only till the above line.

These methods fixed all my issues without reinstalling windows which no i don’t like a all. I am thankful to Google and MOHIT.

find some more about this issue

This is the best explanation and solution

1. here

2. here

3. here

4. here

Popularity: 2% [?]

Tags:


You might also like

Removing a Boot sector Virus
A boot sector  virus is a virus that places its own codes and commands into a computer's DOS boot...
Not able to open drives on hard disk by double click
Sometimes it happens in windows XP that you are not able to open drives on your hard disk. When you double...
Fix for sujin.com.np ie hack
Lately my internet explorer on my desktop had been effected by sujin.com.np and every time i opened up...
Ahsans Computer Virus Trozan Fix
Recently I had big trouble with my computer as ….it was affected by Ahsan virus.. It changes my...

Line Break

Author: Utkarsh (255 Articles)

An MBA grad in Information Technolgy and Computer Networks. Technology enthusiast, blogger, webdesigner and in love with electronics and gadgets a Household Hacker and Audiophile@Mtaram on twitter

No Responses to “ VIRUS REMOVAL [Computer Troubleshooting... [amvo.exe amvo0.dll ampo.exe amvol.dll xfoolavp.com and autorun.inf] virus issues…] ”

  1. sreejith on January 16, 2008 at 5:36 am

    for me the file name was amvo1.dll

  2. Ramana on January 26, 2008 at 5:43 pm

    Visit this site….to remove amvo virus…
    http://www.en.mygeekside.com/?p=18#comment-193

  3. Bhupendra on February 4, 2008 at 5:36 am

    Plese send me above tool

  4. mtaram on February 4, 2008 at 8:23 pm

    Download by clicking the link above….

  5. murali on February 7, 2008 at 3:05 am

    Plese send me Download antivirus files

  6. murali on February 7, 2008 at 3:06 am

    Download antivirus files

  7. anil on February 9, 2008 at 11:11 am

    Thanks Ramana
    Your VB programme is very good i get rid off by it for the virus of amvo.exe
    thanks

  8. Apocalypse on February 9, 2008 at 3:47 pm

    This solution deletes/modifies registry keys/entries added/modified by this malware. Before performing the steps below, make sure you know how to back up the registry and how to restore it if a problem occurs. Refer to this Microsoft article for more information about modifying your computer’s registry.

    1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
    2. In the left panel, double-click the following:
    HKEY_CURRENT_USER>Software>Microsoft>
    Windows>CurrentVersion>Run
    3. In the right panel, locate and delete the entry:
    amva = “%System%\amvo.exe”
    (Note: %System% is the Windows system folder, which is usually C:\Windows\System on Windows 98 and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP and Server 2003.)

    Restoring Modified Registry Entries

    1. Still in Registry Editor, in the left panel, double-click the following:
    HKEY_CURRENT_USER>Software>Microsoft>Windows> CurrentVersion>Explorer>Advanced
    2. In the right panel, locate the entry:
    Hidden = “1″
    3. Right-click on the value name and choose Modify. Change the value data of this entry to:
    2
    4. In the left panel, double-click the following:
    HKEY_CURRENT_USER>Software>Microsoft>Windows> CurrentVersion>Explorer>Advanced
    5. In the right panel, locate the entry:
    ShowSuperHidden = “0″
    6. Right-click on the value name and choose Modify. Change the value data of this entry to:
    1
    7. In the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Windows> CurrentVersion>Explorer>Advanced>Folder>Hidden>SHOWALL
    8. In the right panel, locate the entry:
    CheckedValue = “0″
    9. Right-click on the value name and choose Modify. Change the value data of this entry to:
    1

    Removing Other Malware Key from the Registry

    1. Still in Registry Editor, in the left panel, double-click the following:
    HKEY_LOCAL_MACHINE>SOFTWARE>Classes>CLSID
    2. In the left panel, locate and delete the key:
    MADOWN
    3. Close Registry Editor.

    Deleting Malware-created AUTORUN.INF/s

    1. Right-click Start then click Search… or Find…, depending on the version of Windows you are running.
    2. In the Named input box, type:
    AUTORUN.INF
    3. In the Look In drop-down list, select a drive, then press Enter.
    4. Select the file, then open using Notepad.
    5. Check if the following lines are present in the file:
    [AutoRun]
    ;{Garbage}
    open=xn1i9x.com
    ;{Garbage}
    shell\open\Command=xn1i9x.com
    ;{Garbage}
    shell\open\Default=1
    ;{Garbage}
    shell\explore\Command=xn1i9x.com
    ;{Garbage}
    6. If the lines are present, delete the file.
    7. Repeat steps 3 to 6 for AUTORUN.INF files in the remaining removable drives.
    8. Close Search Results.

    Deleting the Malware File(s)

    1. Right-click Start then click Search… or Find…, depending on the version of Windows you are running.
    2. In the Named input box, type:
    %System%\amvo.exe
    3. In the Look In drop-down list, select My Computer, then press Enter.
    4. Once located, select the file then press SHIFT+DELETE.
    5. Repeat steps 2 to 4 to delete the following file:
    %System%\amvo0.dll
    %Temp%\zhklagpv.dll
    (Note: %Temp% is the Windows Temporary folder, which is usually C:\Windows\Temp or C:\WINNT\Temp.)

  9. Arun Pradeep. K on February 15, 2008 at 6:53 pm

    Thanks for the AMVO virus removal, can any one help me to solve a problem, the problem is, whenever i boot the system disk checking is running even if i shut down the system corrrectly, please help

  10. Prashant on February 21, 2008 at 2:06 am

    Thanks mtaram. Your solution worked!!

  11. Tunde on March 4, 2008 at 9:57 am

    Thanks for the info on the removal of amvo (and it’s friends)!

    God bless you big time!!!

  12. arun on March 4, 2008 at 11:53 am

    plz send this virus remove software site link

  13. andback on March 20, 2008 at 8:48 pm

    Ive written a detailed blog about removing the autorun.inf virus and other issues at http://andback.wordpress.com

    also talks about removing those viruses which even the antivirus cant remove and to revert back to settings prior to infection.

    Hope this helps too.

  14. chirs on March 26, 2008 at 11:24 pm

    The best way to delete autorun.inf and its files associated is to use USB FireWall in this link
    http://www.net-studio.org/application/usb_firewall.php

    It stops too the spreading of virus from USB key or external drive.

  15. Faroque on April 7, 2008 at 5:39 am

    Thanks a lot……..

  16. mtaram on April 7, 2008 at 10:55 am

    you are welcome I am glad this has helped so many ppl… :)

  17. Siliwangi on April 11, 2008 at 8:31 am

    thank`s guys…:D

  18. cmcminh on April 28, 2008 at 11:39 am

    thanks

  19. dileep on May 2, 2008 at 7:00 am

    recently attacked with emv.exe. Its coming in the opening window with some error message. Also yahhomessanger after sign in automatically diconects. how to get rid of this?

  20. andreas04: close to attraction on May 18, 2008 at 12:51 am

    [...] линк 1 , линк 2 , линк 3 [...]

  21. thompson on June 23, 2008 at 11:01 am

    please tell me some proper way to combat against the malicious files that keep retrieving on my desktop even after being removed for quite some time !

  22. solano on June 26, 2008 at 11:24 am

    either use xoftspy.exe or if you don’t have crucial data on your pc just reinstall windows dude !

  23. mtaram on June 27, 2008 at 6:40 am

    ya u can do it but once u reinstall windows and double click on any of the infected drives u are a gonner…..
    I tried it several times. Your Idea is good….
    Thank you

  24. solano on June 27, 2008 at 11:40 am

    glad to help you friend……hope that was helpful

  25. Vijay on June 29, 2008 at 11:23 am

    Thanks a lot for the instructions. I think i removed the amvo malware but I am facing a problem with hidden files. The radio for the show hidden files in the view tab of Folder options in explorer was unchecked for both options (show/hide). I set to Show hidden files but once i click on Apply, it hides all the hiddent files.
    I have to repeat steps from Apocalypse to show the files again! Any idea why this could be happening?
    TIA

  26. Vijay on June 29, 2008 at 11:29 am

    never mind :) I skipped a step. Got it. Thanks again!

  27. mtaram on June 30, 2008 at 2:10 pm

    Glad to know that it helped you…. I am doing my MBA right now it started in june so i dont get time to check comments often.
    Thank u.

  28. james on July 2, 2008 at 10:39 am

    Please send amvo virus removal software

  29. amit on August 6, 2008 at 3:09 pm

    Sir my hidden files are showing but i cannot open my drives after running the registry file. Please help me to open my drives.

  30. Deniz on October 1, 2008 at 11:34 pm
  31. Deniz on October 28, 2008 at 11:39 pm

    That is a response. You dowload and run this program(ComboFix).

    http://www.msproficient.com/2008/about-amvoexe-virus-how-to-clean-amvoexe/

  32. Jaklin on December 22, 2008 at 5:11 pm

    Hi.. this solved my problem related to hidden files. But I cannot open my drives after running reg file. help pls ;(

  33. mtaram on December 23, 2008 at 5:53 am

    please follow the post that is regarding the autrun.inf virus and follow the steps and see if it resolves ur issue.

  34. Jaklin on December 26, 2008 at 6:34 pm

    Hi. 10x for your replay… but it didn’t solve my problem :( I uninstalled the old version of MS office and want to reinstall , but during the installation I’m getting alert about error and the installation interrupts..

  35. mtaram on December 27, 2008 at 11:12 am

    Try installing in safe mode…

  36. Thomson@ Cheap computer on February 7, 2009 at 10:26 am

    Computer virus is surely a great problem you never know when it will attack and spoil your hard work . Thanks for the guidelines .

Leave a Reply

Login with Facebook:
Get Adobe Flash playerPlugin by wpburn.com wordpress themes