Free file hosting, free video sharing

<<< The Web Hosting >>>


Go Back   Noeman GSM > MULTI FORUM > Internet & Computers > Technical Support

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-06-2008, 12:00 PM
Member +
 
Join Date: Feb 2008
Age: 35
Posts: 32
Reputation: 389
alkathiry is just really nicealkathiry is just really nicealkathiry is just really nicealkathiry is just really nice
Default How to remove Win32/NSAnti, d.com virus without any anti-virus tool

How to remove Win32/NSAnti, d.com virus without any anti-virus tool


Trouble:

Recently we received a mail from one of our readers whose computer was infected by Win32/NSAnti virus, this virus mainly causes drive opening problem by double click in windows XP.

If your system is infected by this virus you can’t see hidden files and folders , even after applying the settings to show hidden folders. This setting is reverted back to Don’t show hidden files and folders by the virus.

This happens because virus protects the two hidden ,system files called d.com and autorun,inf which are created by amvo.exe and amvo0.dll , amvo1.dll which resides in system32 folder on the OS drive (hard disk partition on which windows operating system is installed).

Fix:

In order to fix the problems caused by this virus ,you will need to delete all these files created by the virus.

Follow the set of commands to delete these files


1. Open Start>>Run and type cmd and press enter. This will open windows command prompt window. On this window, type as directed in steps further and press enter at the end of each step.

2. type cd\

3. type cd windows\system32

4. type attrib -r -h -s amvo.exe

5. type del amvo.exe

6. type attrib -r -h -s avmo0.dll ,repeat the steps 5 and 6 again to delete avmo1.dll

7. now type d: and press enter for d: drive partition.

8. type attrib -r -h -s autorun.inf

9. type del autorun.inf

10. type attrib -r -h -s d.com

11. type del d.com

Similarly repeat from steps 8 to 11 for all your hard disk partitions to remove the files created by the virus.

Note: Above procedure may seems cumbersome but proves to be of great help to repair your system, if none of your anti-virus tools is able to solve the problem and remove the infections caused by the virus.

Updated (21 Jan 2008):

We have just received some comments by the users who do not find above method useful as they were not able to remove amvo.exe virus by following the above method.

For all those who are facing issues with the above method, can follow the steps given below to remove the virus.

1. First download Trend Micro HijackThis from here

2. Install and run the scan ,you will see an entry like this :

HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe

3. Check the above entry and click on the button which says Fix Checked and click yes on the prompt.

4. Uncheck amvo.exe from msconfig>> startup (type msconfig in run and click on the startup tab) also and restart your system

5. Open my computer and go to folder options >> check the option show hidden files and folders. Also un-check the option Hide protected operating system files (This will give a warning message, confirm by pressing yes button). After this click Ok.

6. Now access all your system drives by typing the drive letters in the address bar (for example c and delete the files like autorun.inf and other file with a name ms18us.exe (sorry but I am not sure about the second file name )

7. Also delete the files amvo.dll and amvo1.dll from windows/system32 folder.

Updated ( 28 Jan 2008)

Note: Looks like that for most of the people both of the above methods are little bit confusing in terms of implementation.

So we would like tell another method to remove amvo and ampo virus by using a vbscript which you can download from [Only Registered users can see links . Click Here To Register...] by clicking here. You can easily remove the virus by double clikcing the script.

PS: But we dont take any responsibilty if this script causes any damage to your system so use it on your own risk.

We hope the new solution for removal of win32/ns anti virus will help.

Give Rep if you think this post is useful
__________________
EL CLASSICO
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 08-19-2008, 09:47 PM
Junior Member
 
Join Date: Aug 2008
Age: 30
Posts: 2
Reputation: 10
silverlightcomputers is on a distinguished road
Default

I have gotten d.com virus on a flash drive. As soon as I try to edit my flash drive it says drive not detected, but I am able to see 3 files on my flash drive 2 hidden (autorun.inf and d.com) 3rd file is an movie file, but i cant see what type, cause there is no info (probably the host).

How do I get rid of these files if I'm not able to edit my drive?
Reply With Quote
  #3 (permalink)  
Old 08-19-2008, 10:31 PM
MariusKane's Avatar
Symbian Contributor
 
Join Date: Jul 2008
Location: Near My Angel
Age: 15
Posts: 2,105
Reputation: 28842
MariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super MemberMariusKane Mega Super Member
Default

format it it. right click on it and click on format
__________________


Ask me about Anything related to Symbian. From Hacking and Cr@cking to Tutorials for Garmin, TomTom and other applications! Just PM me!

Sectiunea Pentru Romani: [Only Registered users can see links . Click Here To Register...] - acolo te putem ajuta in limba noastra
Reply With Quote
  #4 (permalink)  
Old 08-20-2008, 07:47 AM
Junior Member
 
Join Date: Aug 2008
Age: 30
Posts: 2
Reputation: 10
silverlightcomputers is on a distinguished road
Default

In an attempt to format the drive i got this message "windows was unable to complete format".

This is what i know about d.com....it attacks fat32 file systems(luckily I use NTFS on my hdd) it also infects autorun.

I have tried to delete the partition, which needless to say doesn't work. Its seems like it protects itself from being removed, I cant access the drive in any way except with explorer.But i cant execute any actions.

I am all out of ideas and really need some help!
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 02:38 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Copyright © 2004-2008 Noeman . All rights reserved
Free Credit Report | Credit Card | Home Loan | Credit Cards | Credit Cards

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114