Hello to all,
I am having a dilemma right now. My folks PC in Washington has contracted a Kavo Trojan. I am currently in the process of trying to remove this virus, however it keep coming back. Not surprisingly.
I am in CA right now using logmein(remote desktop) in an attempt to remove this virus/spyware. The virus was first detected by McAfee Antivirus .
I have perform the following:
1. Spyware Search & Destroy 1.4 w/ latest build
2. McAfee Antivirus w/ latest build
3. Lavasoft Adware Removal 1.06 Build w/ latest Update
Even attempted to look for kavo.exe and kavo0.dll files. Apparently, these files will keep spawning if deleted (McAfee deleted). I have disable the startup service kavo.exe in msconfig. However, I get a pop-up error message. Does anyone know of any method or tools that I can use to remove this virus/spyware. Please keep in mind that I am doing this remotely. I am instructing my folks on the phone. I have already scan my computer w/ McAfee in safe mode.
Thank you all for responding.
SOLUTION:
To remove kavo.exe (aka ntdelect.com, TROJ_NSPM.ADB, and TROJ_NSPM.ABT)
Please perform the following:
1. Go to Trend Micro- http://housecall.trendmicro.com/…
and use their housecall scan/removal
2. Go to Registry Edit aka regedit and
search for
"C:\WINDOWS\system32\kavo.exe"
with the value of kavo
Please note the location of the kavo may vary depending on the type of variant you have. The general information insist that it is in
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\”kava” = “%System%\kavo.exe”
I am working on removing all left over "residule" from the virus. As of right now McAfee wasn’t able to detect this virus (i.e. kavo0.dll, kavo.exe in any of my drives)
———————————————————————————
Virus First Reported Date:
Thursday, August 30th, 2007
Category:
EXE Files
Filename:
kavo.exe
Related to:
W32.Gammima.AG
File Directory:
%System%\kavo.e
Share This