Avatod malware

P

Paul

My daughter's Dell Inspiron 1200 laptop was infected with the avatod
malware. I remove most of it but there is 1 piece left behind. What looks
like a popup window appears on the desktop. The desktop icons appear on top
of it, so I'm thinking that the "popup" is really on the background. This
model laptop does not allow wallpaper changes, only theme changes. Theme
changes merely change the background color, but the "popup" is still there.
I don't know what to do to get the background back to normal.
 
M

Mick Murphy

Install Spybot Search & Destroy, and Malwarebytes.
If they find it(scan with one at a time) and can not remove it, redo scan in
Safe Mode
All info below.

http://www.spybot.info/en/index.html

Spybot Search & Destroy 1.6 is a very good, FREE Anti-Spyware Program.
Download, install, update, and immunize your System with it.
Then SCAN with it.
Update it, and scan your System once a fortnight.

http://www.malwarebytes.org/mbam.php

Malwarebytes is as the name says, a Malware Remover!
For the Free version scroll down their page to either download from
Download.com, or Major Geeks.com

Download, install, and update.

Important re: Safe Mode
If you happen to find a problem that you can’t uninstall / delete, reboot
the computer, and go into Safe Mode.
To get into Safe mode, tap F8 right at Power On / Startup, and use UP arrow
key to get to Safe Mode from list of options, then hit ENTER.
RESCAN your computer with your Anti-Virus, Malwarebytes and Spybot S & D
while in Safe Mode.
 
S

sandy58

My daughter's Dell Inspiron 1200 laptop was infected with the avatod
malware. I remove most of it but there is 1 piece left behind.  What looks
like a popup window appears on the desktop.  The desktop icons appear on top
of it, so I'm thinking that the "popup" is really on the background.  This
model laptop does not allow wallpaper changes, only theme changes.  Theme
changes merely change the background color, but the "popup" is still there.
I don't know what to do to get the background back to normal.

VundoFix:http://vundofix.atribune.org/
VirtumundoBegone:http://www.bleepingcomputer.com/malware-removal/
remove-vundo-virtumonde
FixKlez:http://www.capetechsupport.com/download.htm
RogueRemover:http://www.2-software.net/RogueRemover-2147.html
or
http://www.malwarebytes.org/rr-update/rr-free-setup.exe
Place on desktop & use in Safe Mode. (all freebees)
 
N

nass

Paul said:
My daughter's Dell Inspiron 1200 laptop was infected with the avatod
malware. I remove most of it but there is 1 piece left behind. What looks
like a popup window appears on the desktop. The desktop icons appear on top
of it, so I'm thinking that the "popup" is really on the background. This
model laptop does not allow wallpaper changes, only theme changes. Theme
changes merely change the background color, but the "popup" is still there.
I don't know what to do to get the background back to normal.


1... Click start >> Control Panel >> Double Click Network and Internet
Connections >> Double click Internet Options, on the IE Properties window
you will see these Options:
General | Security | Privacy | Content | Connections | Programs
| Advanced .

Click on General Tab (1st Tab on the left) and you will see a Button called
[ Clear History ..] click on it to clear your History caches, then click on
[Delete Files..] to delete Internet Files created over the time, click on [
Delete Cookies...] to delete your cookies left by visiting websites.

= Then try to Disable the Add-Ons on your Browser somehow installed on your
browser, On how to disable the Add-ons follow this:
Click on Programs Tab and then click the Manage Add-Ons Button there Disable
the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
later and see which is the culprit or you can send them here in your next
post) and click [OK] to confirm your Changes.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256

Click on Advanced Tab and scroll down under the browsing option and uncheck
this box:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) and click Apply
then OK to close your IE Properties.

Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

http://onecare.live.com/site/en-gb/default.htm?s_cid=sah
http://onecare.live.com/standard/en-gb/default.htm

Comodo BOClean : Anti-Malware Version 4.27
http://www.comodo.com/boclean/boclean.html

Schedule file rename and delete commands for the next reboot. This can be
useful for cleaning stubborn or in-use malware files.
http://technet.microsoft.com/en-us/sysinternals/bb897556.aspx

Remove these files/folders:
Avatod001.bas
Avatod.exe
Avatod Anti-Spyware 6.0.lnk
Avatod Anti-Spyware 8.0.lnk

Open your Registry Editor and locate this Key then delete the malware from
the run key:
Or you can remove it by using the Autoruns:
http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

[-]HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\=â€
Avatod†= “C:\Documents and Settings\UserName\Application
Data\Avatod\Avatod.exe /MINâ€


download Hijackthis and send me the log.
(http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php)
Send me copy to my address is : to_you_ross(at remove this and repalce with
the obvious)yahoo.co.uk

( _ is underscore)
HTH
nass
 
S

sandy58

My daughter's Dell Inspiron 1200 laptop was infected with the avatod
malware. I remove most of it but there is 1 piece left behind.  What looks
like a popup window appears on the desktop.  The desktop icons appear on top
of it, so I'm thinking that the "popup" is really on the background.  This
model laptop does not allow wallpaper changes, only theme changes.  Theme
changes merely change the background color, but the "popup" is still there.
I don't know what to do to get the background back to normal.

One more.
http://www.2-spyware.com/remove-avatod-antispyware.html
:)
 
S

sandy58

I've never understood 'Safe mode'.  Just what is the purpose of safe mode
and how does it differ from ordinary bootup?

Thanks,

Norm Strong

Safe mode uses minimal drivers so things are easier to remove/move/
change. (for want of a more complicated explanation:)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top