Win32/Virut
Download the
following two files (
rmvirut.exe,
rmvirut.nt)
and run the rmvirut.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmvirut C: D:". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmvirut.nt into the same folder
as rmvirut.exe. After the healing process please
run the AVG Complete Test to make sure your
computer is virus-free.
I-Worm/Luder
Download the
following three files (
rmluder.exe,
rmluder.nt,
rmluder.dos)
and run the rmluder.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmluder C: D:". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmluder.nt and rmluder.dos into the same folder
as rmluder.exe. After the healing process please
run the AVG Complete Test to make sure your
computer is virus-free.
Win32/Delf.2.B
If you have
infected computer connected to a LAN, you need
it to unplug from the LAN, and re-connect again
in the moment when all computers are clean.
-
Download the following file
remdelf.exe.
-
Update AVG and run test of the Windows
System folder to schedule the removal of the
infected DLL/OCX library on computer
restart.
-
Restart computer, so the DLL/OCX file
will be removed.
-
Thereafter run the removal tool with
parameter C:\ to heal the infected files.
You can specify more drives (example:
RemDelf C:\ D:\).
LOP.AH/Backdoor.Generic3.SVX
Download the
following two files (rmbg3svx.exe
and
rmbg3svx.nt)
and run the rmbg3svx.exe file. Then restart your
PC normally and run the AVG Complete Test.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmbg3svx.nt into the same folder as
rmbg3svx.exe. After the healing process is
finished please run the AVG Complete Test to
make sure your computer is virus-free.
Win32/Parite
Download the
following three files (
rmparite.exe,
rmparite.nt,
rmparite.dos)
and run the rmparite.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmparite C: D:". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmparite.nt and rmparite.dos into the same
folder as rmparite.exe. After the healing
process please run the AVG Complete Test to make
sure your computer is virus-free.
Win32/Sality
Download the
following three files (
rmsality.exe,
rmsality.nt,
rmsality.dos)
and run the rmsality.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmsality C: D:". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmsality.nt and rmsality.dos into the same
folder as rmsality.exe. After the healing
process please run the AVG Complete Test to make
sure your computer is virus-free.
Win32/Vampiro
Download the
following three files (
rmvampir.exe,
rmvirus32.nt,
rmvirus.dos)
and run the rmvampir.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmvampir C: D:". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmvirus32.nt and rmvirus.dos into the same
folder as rmvampir.exe. After the healing
process please run the AVG Complete Test to make
sure your computer is virus-free.
Win32/Kriz
Download the
following three files (
rmkriz.exe,
rmvirus32.nt,
rmvirus.dos)
and run the rmkriz.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmkriz C: D:". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the remover requires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmvirus32.nt and rmvirus.dos into the same
folder as rmkriz.exe. After the healing process
please run the AVG Complete Test to make sure
your computer is virus-free.
Win32/Elkern,
variants A, B and C
Download the
following three files (
rmelkern.exe,
rmvirus32.nt,
rmvirus.dos)
and run the rmelkern.exe file.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmelkern C: D: ". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Successful running of the removerrequires
administrator rights. For proper functionality
of the remover it is necessary to save the
rmvirus32.nt and rmvirus.dos into the same
folder as rmelkern.exe. After the healing
process please run the AVG Complete Test to make
sure your computer is virus-free.
Win32/Magistr,
variants A and B
Download the
utility
rmmag.exe
and run it.
You can also specify the disks (or
partitions) to heal as a command parameters,
e.g.: "rmmag C: D: ". If the command is used
without parameters, it heals all disks
(partitions) on computer.
Note:
Remover Successful running of the remover
requires administrator rights. After the healing
process please run the AVG Complete Test to make
sure your computer is virus-free.
I-Worm/Bugbear.C
Download the
remover
rmbugbear.exe
and run it on infected computer. Then restart
your PC normally and run the AVG Complete Test.
If the infected computer is connected to LAN,
it is neccessary to disconnect this computer
from LAN before removing the virus and
re-establish the connection in the moment when
ALL computers in LAN are cleaned.
Exceptions:
If you are using Windows ME or Windows XP
operating systems, there might be a problem in
removing infected files from the _Restore folder
(Windows ME) or System Volume Information folder
(Windows XP). For the correct removal of these
infected files, it is necessary to disable the
system restore function.
I-Worm/Mydoom.F
Download and run
the remover
rmmydoom_f2.exe
on the infected computer.
Downloader.Stubby.A
Download and run
the remover
rmstubby.exe
on the infected computer.
Win32/Valla.2048
Download the
remover
rmvalla.exe.
Restart your computer in
Safe mode
and run the remover.
Note: Default path set in this utility
is to scan C: drive. If you want to change this
value, run the utility as: rmvalla.exe <drive
letter>:\
Win32/Dupator
Download the
remover
rmdptor.exe.
Restart your computer in
Safe mode
and run the remover.
Note: Default path set in this utility
is to scan C: drive. If you want to change this
value, run the utility as: rmvalla.exe <drive
letter>:\
I-Worm/Ganda
Download and run
the remover
rmganda.exe.
Then restart your PC and run the AVG Complete
Test.
Note: Default path set in this utility
is to scan actual drive. If you want to change
this value, run the utility as: rmganda.exe
<drive letter>:\
VBS/Iloveyou
Download and run
the remover
rmlove.exe
on the infected computer.
I-Worm/Lovgate.C
Download and run
the remover
rmlovgte.exe
on the infected computer.
I-Worm/Navidad
Download and run
the remover
rmnavida.com
on the infected computer.
I-Worm/Nimda
If you have
infected computer connected to a LAN, you need
it to unplug from the LAN, and re-connect again
in the moment when all computers are clean. In
any case, check for all available
security patches.
-
Download the remover
rmnimda.exe.
-
Run the utility.
-
Restart the computer.
-
Scan the computer by AVG complete test.
-
Delete all infected files.
-
Repeat until computer is clean.
-
Remove the sharing of disks and the
Guest account from Administrators group.
I-Worm/Pretty_Park
Download and run
the remover
rmppark.exe
on the infected computer.
I-Worm/Sircam.A
Download and run
the remover
rmsircam.com
on the infected computer. Restart the computer,
run AVG and delete all infected files.
I-Worm/Happy99
Download and run
the remover
rmska99.exe
on the infected computer.
W95/Space.1445
Download the
remover
rmspaces.exe.
Restart your computer in
Safe mode
and run the remover.
Note: Default path set in this utility
is to scan C: drive. If you want to change this
value, run the utility as: rmspaces.exe <drive
letter>:\
I-Worm/Verona.B
Download and run
the remover
rmveronb.exe
on the infected computer.
I-Worm/Swen
Download the
remover
rmswen.exe.
Restart your computer in
Safe mode
and run the
remover. Then restart your PC normally and run
the AVG Complete Test.
If the virus file has been removed before the
launching of rmswen.exe (either manually or by
AVG) then please follow these instructions to
recover the system:
-
If you will try to launch any program
you will be given the error message that the
"File *.* is missing".
-
Remember the exact file name and its
location.
-
Rename the rmswen.exe utility exactly to
same name of the "missing" file.
-
Now place the renamed utility into the
C:\WINDOWS folder and restart the PC.
-
After restart please launch a test again
to ensure that the system is now clean.
I-Worm/Mydoom.A
and I-Worm/Mydoom.B
-
Start the
Complete Test for all local hard drives:
In Basic Interface select Tests menu ->
Start Complete Test
In Advanced Interface select Tests menu ->
Test manager -> click on Complete Test item
-> click on Start Test button
-
In case of virus infection select the
button heal/remove.
-
After finishing the Complete test please
restart your PC and repeaet the AVG Complete
test again to check all local hard drives
again (to be sure all infected files has
been removed).
Attention: Users of AVG Anti-Virus
with updated virus databases may continue to
receive false warning messages indicating that
the I-Worm/Mydoom virus was sent from their
email address.
This is because the I-Worm/Mydoom virus changes
the address of the sender of the infected email.
This makes it very difficult to identify the
actual sender of the virus, and therefore to
notify the sender that his computer is infected.
This may result in the virus displaying a
different email address from that of the actual
sender of the infected email. When such an email
is detected by the anti-virus system on the
computer which receives the infected e-mail, a
warning message is often sent concerning the
infection to the address that is indicated as
the sender of the infected message - even
when the email was NOT sent from this address.
I-Worm/Sober.A
-
Run the
Complete Test for all local hard drives ->
Menu Tests -> Test manager -> Complete test
-> Start test
-
In case of virus infection select the
button heal/remove.
-
Some infected file cannot be
healed/removed directly. In some cases
following message will be displayed: "To
finish the healing, it is necessary to
restart the computer" or "File deletion was
scheduled to the next restart of the
computer".
-
After finishing the Complete test please
restart your PC and repeat the AVG Complete
test again to check all local hard drives
again (to be sure all infected files has
been removed).
-
If you find any infected file again,
please restart your computer in Safe mode.
To do it press and hold the F8 key during
the initial Windows boot phase. Repeat all
steps described above in
Safe mode.
Worm/Lovsan
When the timeout
message appears that you will be disconnected in
some time period, please click on START button
-> RUN and type this command here:
SHUTDOWN -a
and click OK then. The timeout will be stopped
then and you will be able to download and
install the security patch to your operating
system.
-
You have to download and install the
security patch to your operating system
first (it repairs a bug in the DCOM RPC).
You can find it on Microsoft internet pages.
-
Run the registry editor (START -> RUN ->
type REGEDIT and click on OK button) and
find this registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Please right click on the name "windows auto
update" and choose REMOVE/DELETE.
-
After this please reboot your computer
to the "Safe mode with command prompt" and
type here these commands:
CD WINDOWS (enter)
CD SYSTEM32 (enter)
DEL MSBLAST.EXE (enter)
-
Then restart your computer and run the
AVG Complete Test to ensure that is your PC
virus free.