How to get rid of W32/MTWB.A.gen!Eldorado virus that picked up by F-prot anti-virus? It keeps coming back after any reboot. We have tried many solutions but without success, how do you delete this nasty virus from your laptop or desktop permanently?

Clearly Understand The W32/MTWB.A.gen!Eldorado Virus

The W32/MTWB.A.gen!Eldorado virus is extremely dangerous and it is well known to cause computers the blue screen that occurs when the system is destroyed and completely crashed. Just like other Trojan viruses, it connects to a remote server and gives access to the hacker without the user being aware. The virus is usually used to just flood a computer with pop up advertisements, although the hackers will have complete access and could also steal personal data from the computer. The rapid delivery of the ads can cause the system to use all of its available memory and the overload can cause the system to crash, damaging the computer.

How do i remove W32/MTWB.A.gen!Eldorado virus manaully? My computer is telling me that “antivirus” has found a whole heap of virus’, W32MTWB.A.gen!Eldorado was identified by F-Prot but cannot be removed. I am running Windows 7 Home Basic.  Have tried running a great deal of programs like: Microsoft Security Essentials, AVG 2013, Malwarebytes, SuperAnti-spyware, and HitmanPro to remove this virus but with  no luck.  F-prot is the only program that even found it and states: failed to quarantine. This virus has the ability to completely disable a computer and make it virtually worthless and completely unusable. It primarily targets the master boot record, and is it part of the Alureon family?  No, but it is a stubborn virus, which has the ability to steal any information that in transmitted through the Internet, such as banking information and usernames and passwords. You need to delete it completely from your system.

To absolutely clean out this virus, you can follow the guide here if you are computer savvy. As the anti-virus won’t be able to help, so manual removal is suggested here as it is a guaranteed complete removal. Contact YooSecurity Online PC Expert to get further help to sort it out.

How Dangerous The Infected Computer Is If The Virus Has Been Downloaded?

Like we said above, once successfully installed on a target computer, the W32/MTWB.A.gen!Eldorado virus modifies the master boot record, that is why you caught the Windows starts itself each time you begin to click the virus, what is the worse the virus will continue to install harmful files that spread and freeze your system. This is a dangerous infection and can actually completely terminate the antivirus software on the computer, which would then never alert the user that there was a potential risk. There are ways to check to see if this virus has hit your computer without using an antivirus program.

This virus slows down your computer and then to successfully crash systems. It occupied so much of the system memory. There are some symptoms of W32/MTWB.A.gen!Eldorado virus that is attacking the computer:

  • Your Internet browsing session is redirected to a security page and a warning will appear stating that you are browsing unsafe pages.
  • The desktop background image has been changed and the home screen icons have been rearranged or resized.
  • While browsing several pop up advertisements are displayed, often times speeding up to the point where it locks the computer and crashes the browsing session.
  • The overall speed of the computer is slowed down and programs take longer than normal to open. The Internet is also slowed down and simple tasks like shutting the computer down are also slowed.
  • Antivirus programs on the computer will be shut off and disabled to prevent detection of the virus.
  • Regularly used programs such as Microsoft Word and Excel will be damaged and unable to open properly.

Steps on How to Get Rid of W32MTWB.A.gen!Eldorado Virus

Step 1: Open Windows Task Manager to end processed related to the Trojan horse. To do that, press Ctrl+Alt+Del keys at the same time or right click on bottom Task Bar and select Start Task Manager.
Windows Task Manager

Step 2: Show hidden files. Go to Folder Options from Control Panel. Under View tab, select Show hidden files and folders and non-select Hide protected operating system files (Recommended) then click OK.
Folder Options

Step 3: Go to Registry Editor. First press Windows+R keys and then type regedit in Run box to search for virus. Delete all the following or those related to the following files and registry entries:
Run+Registry Editor

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AAWTray.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVCare.exe\Debugger svchost.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVENGINE.EXE\Debugger svchost.exe

Video on How to Modify or Change Windows Registry


Up to now you understood this virus will change important settings of your computer performance that will cause a complete crash, but not before potentially stealing all of the data from the computer. There is no anti-virus software can clean out the W32/MTWB.A.gen!Eldorado virus, it is really “smart” that many common users were not able to remove it. The hackers gain access to all of the personal information by controlling the infected computer with this virus. There is no doubt that manual removal of the corrupt files is the best way to remove the W32MTWB.A.gen!Eldorado virus. Please take an action to clean it out.

Note: Still having the same problem after every reboot? If you don’t know how to remove this virus from your computer and don’t want to make thing worse. Contact Online PC Experts 24/7 online in time to get professional help.

Published by Tony Shepherd & last updated on March 12, 2013 5:03 am

Leave a Reply