after loging into your machine just open Task Manager, go to Processes tab Right click on amvo.exe and click on End Process Tree, click Yes.
After doing this launch again the Task Manager, if this process (amvo.exe) appear again. if not then just follow these steps.
Click On Start Button.
go to Run
type regedit and press enter or Click ok
it will launch Registry Editor, then search whole registry for amvo.exe and note down all the entries of found result with their (Key name, Registry Path, Value).
*CTRL+F then type amvo.exe and press enter
if you have good knowledge of Registry then delete all the entries which contain amvo.exe.
This is the list which contain startup entries
Startup locations
HKCU refers to HKEY_CURRENT_USER
HKLM refers to HKEY_LOCAL_MACHINE
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
(In right-pane, Value named "Run" & "Load")
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
C:\Documents and Settings\{Username}\Start Menu\Programs\Startup
you will also see the path of the amvo.exe (where it is lying in your machine) when you find its entries in search of registry.
once you know the path of it then just go to that path using Explorer then delete it. If you can not see this file on the specified path, it means this Attributes are assigned to System Or Read Only, then just go to command prompt and type this command.
C:\>attrib -a -s -h amvo.exe
where command C:\ refers to the path of amvo.exe
Note: Please perform the procedures in Safe Mode.
i cant open my yahoo messenger, could it be because i have thios dr.watson postmortem debugger on my pc and this amvo.exe that keeps popping in? please help. because im not great when it comes to computer. and i cant remoeve this amvo.exe from my pc and this dr,watson postmortem debugger either.
Posted by vanessa at April 13, 2008, 12:27 ami did all the steps given above ,its getting deleted once and if start my system again the error is appering ,the error as follows amvo.exe application error.please tell me more step to delete this virus.
Posted by prasanna at May 15, 2008, 2:57 pmTo Prasanna:
First of all download the BulletProof FTP Client for Windows software from the http://www.bpftp.com/ ,its free software and then run it it will show you your all hidden files and system file in all drives, Then after u will explore them by right click view explorer then u found the all files like amvo.exe,amvo.dll,amvo0.dll,amvo1.dll,etc.Some file also remove from that software but some r not.So open in safe mode and again choose view explorer from that software.Now u can show that all file into c:\windows\system32\
Delete all that files।and restart ur computer.
Do this for all drives .
Write in address bar of that software like D:, F:, C:, etc.
And you found some file like *.cmd,autorun.inf in all drive, All that file are same in all drive so before delete them u’ll check its remain in the all drive, otherwise by mistake u’ll remove system file, So take care and remove the mentioned file.
still u can’t find them then in bpft software u can edit amvo.dll file by changing its content or by removing all data and rename that file. and again open in safe mode and delete all the file.
Now ur computer is free of virus and follow the below instruction:
Now hidden file problem
1.Click Start > Run and type REGEDIT
2. Click the plus sign next to HKEY_CURRENT_USERthen SOFTWAREthen Microsoftthen Windowsthen CurrentVersionthen Explorerthen Advanced
On the right side, double click the hidden value and give it a value of 1.
3.same for HKEY_LOCAL_MACHINEthen SOFTWAREthen Microsoftthen Windowsthen CurrentVersionthen Explorerthen Advancedthen Folderthen Hiddenthen SHOW ALL
Change the value of Checked Value to 1.
Its really works for meNow i’ve no problem of hidden file.
i, too been affected by this virus…
but the given process is not cool coz i am unable to open task manager….though i can regedit. What happens when i open task manager it just coming…and then it vanishes as if it is flashing… so i could not check actually what process is running in my system.
it copies it self (amvo.exe, amvo01.dll …goes on) in system32 folder ( mine is xp sp2) when i tried to run attrib command ( the -h -s switched) it displays the attribute of the above files cannot be changed…………
stuck at..
tell me a different solution..possibly would help me out..
How Can I remove this virus manually
AdobeRd9.0
Posted by Mihret at June 13, 2008, 6:50 pmAfter editing my registry on “HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer” I can now change the values for example if task manager has been disabled by a virus. It will be easy to track viruses if you can launch your task manager.
Posted by bojo at June 14, 2008, 12:58 pmcan I remove folder.exe and picture.exe from my pc without any antivirus?
And also I’ve a problem with AdobeRd9.0 I want to remove it. How can I do it?
Response: Visit www.eset.com.
Download the trial version of nod 32. it is only a 11mb file, it wont take long.
update it
Scan your PC to get rid of ‘new folder .exe’.
Posted by tsionze at June 17, 2008, 4:17 amwell guy my archicad 11 has failed to launch could it be as a result of amvo.
Posted by kintu j at August 6, 2008, 6:14 pmthanks for your knd informations
Posted by satya at August 21, 2008, 1:29 pmIn here I’ve learned about the kavo.exe virus and learned how to remove it:
Posted by Remove Exe Virus at December 2, 2008, 3:42 pmI know a tool very easy to remove the virus amvo and variants.
The tool name is Combo Fix download here:
All comments are moderated. Your comments will not appear here unless approved by the blog owner. Thank you.
i hope it will works beacuse i so tired of this virus….
Posted by vinux at March 26, 2008, 12:34 pmby the how about “competttt.com” it is a virus because everytime i open my computer it will be pop up