Showing posts with label virus removal. Show all posts
Showing posts with label virus removal. Show all posts

Nov 29, 2008

Remove ntde1ect or avpo.exe virus

Ntdetect is a system file, a very important file without which your system won't boot. And virus makers used this name to create a virus to confuse people. The virus is named ntde1ect.com. You can see that only difference is the virus has '1' instead of 't'. This virus is also called the avpo.exe virus. In some parts it leaves this name also.

This virus doesn't allow you to see the hidden files as well as double click will not open the drives. It has the files placed in the root of all the drives.

Now to get rid of this you can follow steps here to get back your settings for hidden files and task manager if its disabled.

--- Then go to task manager and end the process explorer.exe

--- Again restart that process by typing explorer.exe in the File --> New task in the task manager window.

--- If your task manager was not disabled then you can follow the two previous steps and download this file reg_ntde1ect instead of doing things manually as given in the link at the start.

--- Just double click on this .reg file and merge it into your registry. This will bring the folder options and other settings back to normal.

--- Now go to Folder Options --> View then select 'Show the hidden files and folders' and also uncheck the value 'Hide protected operating system files'

--- Now to delete the infected files go to the windows explorer and type the drive letter in the address bar like C: instead of opening the drives by double clicking.

--- Now you can see the ntde1ect.com file and also the autorun.inf files delete these files. Do not delete the ntdetect system file be very careful.

--- Now remove the avpo entry in the startup by going to msconfig from run dialog box.

--- Now go to the windows/system32 folder and search for avpo.exe and avpo0.dll files and delete them.

--- Once again end the process explorer. exe in task manager and restart it as earlier.

--- Restart your system and you are free from the virus.

If you have any difficulties to get rid of it just post here and i will try to help.

Nov 25, 2008

Double Click on Drive Gives Open With Options - Fix

Everyone at some time has experienced the problem where, if we double click on a drive to open it instead of the drive opening, a dialog box with open with options comes up. And you know as soon as this dialog box opens your PC is infected with a virus.

This problem occurs because the virus creates a Autorun.inf file in the root of every drive, which is activated every time you double click the drive. You will not be able to see this file as it is kept as a system file and that's why this file gets left behind on the virus check.

This file is not needed by the system and hence you can delete it. But as it is system file and has hidden and read only attributes you will not be able to delete it. So we first need to clear these attributes and then you can delete these files from all the drives. Here is how you do it..

--- Click on Start menu --> Run and type cmd to open the command prompt.

--- Now type "attrib X:\Autorun.inf -s -r -h" without the quotes, where X is the drive letter you are going to clean.

--- Now you can see this file in explorer and its ready to be deleted.

--- Delete this file and then restart your system or restart explorer.

and your problem is fixed.


Nov 17, 2008

Show hidden files after virus removal

The first a virus does after infecting your system is to disable the show hidden files option in folder options. So that you cannot delete the infected files. So to get rid of the virus from your system, first you need to get the hidden files option back.

Here is how you do it.

First you have to clean your PC to get rid of the virus.
You can download the trial version of the anvtivirus like ESET NOD32 or kaspersky Antivirus.
Install and scan your entire system with any of these. Then you are ready to get the hidden files back to visible, to do this..

--- Go to start menu --> Run

--- Type regedit and press enter

--- Then go to this key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advan ced\Folder\Hidden\SHOWALL"

--- Look for the Dword value on the right pane named CheckedValue and change its value to 1

--- Now check the folder option now.

--- Repeat this once again if the option still doesn't work and close regedit.


For any help post in the comments