If a shut down timer is active, go to Start, Run, type shutdown
-a and press Enter.
If you do not have shutdown.exe, download it from here.
Stop malware processes
Press Ctrl+Alt+Del, (Windows 2000: Click Task Manager),
go to Processes tab
Find all instances of "avserve.exe",
"avserve2.exe" "12345_up.exe" (where
12345 is a number) and End Task all of them.
Safe mode
Restart to Safe Mode (Restart your computer (if you don't
have "Shut down" in Start Menu, press the Power
button once) and press F8 when Windows begins to load)
Remove files
Go to your Windows directory (such as C:\Windows)
Delete avserve.exe, avserve2.exe (you might not find
both), 12345_up.exe (where 12345 is a number)
Remove registry entry
Open Registry Editor (Start, Run, regedit,
Enter)
Navigate to
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Click on the item "avserve.exe" or
"avserve2.exe" and delete it.You might not find
both of them.
Restore hosts file
Go to Start, Run, type notepad
%systemroot%\system32\drivers\etc\hosts and
press Enter.
You should find many lines such as 127.0.0.1
localhost. Remember to scroll down!
Delete all lines starting with 127.0.0.1 except 127.0.0.1
localhost.
Perform Windows
Update - Download and install all Critical Updates
This page is brought to you by
paultwang
#VirusHelp @ GalaxyNet team
Disclaimer
The above procedures work in most conditions. However, this is
not a guarantee. The resources here are provided "AS
IS". Use them at your own risk. We are not responsible if
something does not work as expected.