How to remove cvlu virus
----start of fwd msg

USA, August 2008. [updated]

HOW TO REMOVE VIRUS CVLU.EXE

I travelled to east Asian countries on summer 2008. I used my flashdrive there on several persons� PCs and the airports� PCs. My flashdrive became infected by cvlu.exe that I was not aware until I used it on my PCs back home. I never got this cvlu.exe virus in the U.S. before. But I have heard that cvlu.exe was born around end of 90s or early millennium and infected many PCs all over the world. It�s disappeared for sometimes because it�s obvious successful raid off. Now it seems to come back from different region of the world. When I used my flashdrive on two towers and a notebook at home then these PCs became infected by cvlu.exe and its autorun, too. My free AVG v8 and free Spybot v1.6 could not detect them. I would replace AVG v8 with something else�.. read the last paragraph.

In my knowledge that this virus did not damage my PCs, but it was annoying. Its message that popped up on the screen repeatedly told that the PC or the programs could not be used or access to Internet because of malfunction Windows socket. This virus has two subprograms: cvlu.exe (its generator) and autorun (its startup program). This virus will always activate the PC�s removable drive over and over with or without media on it. It was very annoying but not damaging. Some people�s notes on the Internet argued that this virus was one of Trojan Horse - Backdoor that could acquire hard drive to setup a �hotel� (huge space) to invite many �criminals� (malware) to create havoc. Trendmicro stated that this virus was a worm-autorun. For my two towers (one WinXP-SP3 and one Win98SE) I used trendmicro�s virus scanner that successfully cleaned my systems from cvlu.exe and its autorun. Many other people used the same treatment successfully. Visit the following trendmicro�s url: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AUTORUN.QX&VSect=Sn

For my notebook PC I used antivirus called PCMAV that successfully disabled cvlu.exe and its autorun. Also many other people used this treatment successfully. Download PCMAV 1.7 from http://pcmav.benbego.com

Pls hold not to download PCMAV�s update called pcmav.vdb until its author confirms that this update file is not a TR/ATRAPS.Gen Trojan. AVIRA detected that pcmav.vdb was a Trojan. It is a real Trojan or not, no clue. AVIRA will keep the file in its quarantine or remove pcmav.vdb on your behalf. I began to wonder that one anti virus author suspected another anti virus author to create a Trojan. Remember, if you have more than one anti virus active in your PC they will conflict each other. Or it may cause your PC gets crashed. It looks like this is an element of anti virus world. �Users or customers beware�.

I uninstalled AVG v8 on my WinXP-SP3 tower & notebook and replaced it with AVIRA that was able to detect and remove TR/Autorun.AGO Trojan such as cvlu.exe, cvlu1.exe, stupid.exe, TR/ATRAPS.Gen Trojan pcmav.vdb and other GEN/PwdZIP viruses including SmithfraudC1.zip, SmithfraudCgeneric.zip, SecondThoughtSTCLoader.zip, and SecondThoughtSTCLoader1.zip. Download free AVIRA from http://www.free-av.com.

Disclaimer: Use this free anti malware carefully (follow its instruction) and at your own risk. This is not an ads of products mentioned above. It is a personal experience for your practical comparison and hints.

PCNET0109

----end of fwd msg


Powered by www.qsl.net