This virus is also spreading through autorun of pen drive (AUTORUN.INF )

content of the autorun file
[AutoRun]
open=nideiect.com
;shell\open=Open(&O)
shell\open\Command=nideiect.com
shell\open\Default=1
;shell\explore=Manager(&X)
shell\explore\Command=nideiect.com

This will affect yahoo messenger login

How To remove it manually ?

Do it in safe mode

1, Plug your pen drive and start working.
2, search for autorun.inf and delete the filr if you found in root of your partitions and pendrive
3, search for following file and remove them

xn1i9x.com
n1deiect.com
ntde1ect.com
nudeiect.com
ntdelect.com
nideiect.com
ek.com
d.com
usdeiect.com
80avp08.com
dosocom.com
xfoolavp.com
uxdeiect.com
avpo.exe
amvo.exe
kavo.exe
amvo.exe
amvo0.dll
ampo.exe
amvol.dll
xfoolavp.com

4, open registry and take a backup of registry
5, search for “amvo.exe” and delete all the entry related to that file
6, Open “MSconfig” and remove startup entry of “amvo.exe”
7, update and scan with your antivirus

8,Restart Your PC

0 comments:

Newer Post Older Post Home