Do you have pop-ups or your computer infected with trojan or spyware ? Learn how to ask us for help, click here!

How to remove trojans that uses autorun.inf file

These trojans uses autorun.inf file for infects systems. Once infected with autorun.inf trojan your computer will display many popups, Internet Explorer start page can to be change. Also autorun.inf trojan configures itself to run automatically every time, when you start your computer. In addition the autorun.inf trojan creates a files with strange names, some examples:

ampfrb.cmd, hbs.exe, yfog8p.exe, as.bat, phwe.com, o0s.cmd, xa2c.exe, AutoStart.exe, ncyrf.bat, rcukd.cmd, 2u.com, q.com, RavMon.exe, x6.bat, rqq2v.bat, t.com, xp19.com, x0.cmd, yg.cmd, ntde1ect.com, tio8×6.cmd, d6fagcs8.cmd, gbiehbsb.dll, tio8×6.cmd, fooool.exe, 8ng8w.com, x.com, xn1i9x.com, invwft2h.com, selamat_berposa_dari_umt.js, ktnquo.exe, NewVirusRemoval.vbs, kinza.exe, rs.cmd, yssjnngm.cmd, h3.bat, 6fnlpetp.exe, boot.exe, winde32.exe, 6j2j.com, kjibu.com, fun.xls.exe, iqe68o.bat, boot.exe, killVBS.vbs, autorun.pif, lin32.exe, USB.exe, RisinG.exe. f.bat

The trojans may drastically slow the performance of your computer.

Step1: Remove autorun.inf files from all your drives, include any usb/flash drives.

1. Manually:

  • Reboot your PC in Safe mode.

    1. Restart your computer
    2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3. Instead of Windows loading as normal, a menu should appear
    4. Select the first option, to run Windows in Safe Mode.

  • Click Start -> Run.
  • In the type box enter cmd and press Enter.
  • In the command console type del /a:h /f c:\autorun.*
  • Repeat previous step to all drives, make replacing “c” with the appropriate drive letter.

2. Automatically.

  • Download Flash_Disinfector.exe by sUBs from here and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone.
  • Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

Step 2: Remove autorun.inf trojan from the windows registry.

Download and install HijackThis.
Run HijackThis and scan, put a checkmark next to the following items (if exists):

O4 - HKLM\..\Run: [SystemDrive] c:\windows\system32\SVCH0ST.EXE
O4 - HKCU\..\Run: [avp] C:\WINDOWS\system32\avp.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [kxva] C:\WINDOWS\system32\kxvo.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [tava] C:\WINDOWS\system32\tavo.exe
O4 - HKCU\..\Run: [TaskMonitor] C:\WINDOWS\system32\TaskMonitor.exe
O4 - HKCU\..\Run: [Realshade] C:\WINDOWS\system32\realshade.exe
O4 - HKCU\..\Run: [cftmonn] C:\WINDOWS\system32\cftmonn.exe
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - HKCU\..\Run: [kmmsoft] C:\WINDOWS\system32\revo.exe
O4 - HKCU\..\Run: [jvsoft] C:\WINDOWS\system32\j3ewro.exe
O4 - HKCU\..\Run: [ckvo] c:\windows\system32\ckvo.exe

Now close all browser and other windows except for HijackThis, and click “Fix Checked” to have HijackThis fix the entries you checked.

Step 3: Remove autorun.inf trojans files.

Download Avenger from here and unzip to your desktop.
Run Avenger, copy,then paste the following text in Input script Box:

Files to delete:
C:\WINDOWS\system32\avp.exe
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\kxvo.exe
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\tavo.exe
c:\windows\system32\Bitkv0.dll
c:\windows\system32\Bitkv1.dll
c:\windows\system32\kavo0.dll
c:\windows\system32\kavo1.dll
c:\windows\system32\tavo0.dll
c:\windows\system32\tavo1.dll
C:\WINDOWS\system32\SCVVHSOT.exe
C:\WINDOWS\system32\TaskMonitor.exe
C:\WINDOWS\system32\RavMon.exe
C:\WINDOWS\system32\realshade.exe
C:\WINDOWS\system32\cftmonn.exe
C:\WINDOWS\system32\wincab.sys
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\gasretyw0.dll
c:\windows\system32\gasretyw1.dll
c:\windows\system32\kamsoft.exe
c:\windows\system32\vbsdfe1.dll
c:\windows\system32\vbsdfe0.dll
c:\windows\system32\vamsoft.exe
C:\WINDOWS\system32\revo.exe
c:\windows\system32\j3ewro.exe
c:\windows\system32\jwedsfdo0.dll
c:\resycled\boot.com
C:\kjibu.com
C:\6fnlpetp.exe
C:\rcukd.cmd
C:\rqq2v.bat
C:\t.com
C:\xp19.com
C:\x0.cmd
C:\yg.cmd
C:\ntde1ect.com
C:\tio8×6.cmd
C:\d6fagcs8.cmd
C:\gbiehbsb.dll
C:\tio8×6.cmd
C:\fooool.exe
C:\8ng8w.com
C:\x.com
C:\xn1i9x.com
c:\invwft2h.com
c:\AutoRun\AutoStart.exe
c:\AutoRun\autorun.pif
c:\ktnquo.exe
c:\NewVirusRemoval.vbs
c:\kinza.exe
c:\rs.cmd
c:\yssjnngm.cmd
c:\h3.bat
c:\6fnlpetp.exe
c:\boot.exe
C:\6j2j.com
c:\0jbnlnu8.exe
c:\1q8p0y.com
c:\2g.com
c:\39ysi89.com
c:\3jkka91.com
c:\92j11sm.com
c:\a.exe
c:\cjrp8.com
c:\dp.exe
c:\jg6w3yx.com
c:\ntnq.exe
c:\nw0t1l0d.exe
c:\q0rppr.exe
c:\tj8odymw.exe
c:\uh31.exe
c:\vnkucvv.com
c:\xpq63xl.exe
c:\xwpehlv.com
c:\fun.xls.exe
c:\iqe68o.bat
c:\AutoRun\AutoStart.exe
c:\ampfrb.cmd
c:\hbs.exe
c:\yfog8p.exe
c:\as.bat
c:\phwe.com
c:\o0s.cmd
c:\xa2c.exe
c:\killVBS.vbs

Then click on ‘Execute’.
Your computer will be reloaded.

Note: Flash_Disinfector will remove any autorun.inf files, create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don’t delete this folder. It will help protect your drives from future infection.

If you are still having problems with your PC, I would recommend that you follow the instructions - how to use Spyware Removal Forum.

Related articles: Read more: How to disable the autorun feature to prevent malware from spreading, Cannot open C Drive - How to fix it using Flash Disinfector.

Share/Save/Bookmark

May 26, 2008 on 5:24 am | In Trojan, Tutorials - HowTo | |


27 Comments »

RSS feed for comments on this post. TrackBack URI

  1. It is very much pleasing that you have floated free virus removal tools which are very much effective. God may bless you and give more opportinuties to serve the humenity in a more better way. Thanks.

    Comment by Malik Akram — August 14, 2008 #

  2. Iam very great thankful to you fro providing these

    virus removal tools,it is working perfectly for my

    problem,Thanks a lot .

    Comment by adithya — August 17, 2008 #

  3. this is helpful alright but got virus ….detected: virus Heur.Invader (modification) URL: download.bleepingcomputer.com/sUBs/ComboFix.exe//PE_Patch.UPX//327882R2FWJFW/catchme.cfexe//PE_Patch.UPX
    ..

    Comment by wesaxis — August 17, 2008 #

  4. it`s false alert

    Comment by Patrik — August 20, 2008 #

  5. if the problem is just to get rid of autorun.inf worm, do I have to do steps 1 to 4 or can i just do step 1. thanks.

    Comment by Sandy — September 5, 2008 #

  6. If the problem of my pc and flashdrive is the presence of autorun.inf do I still need to do steps 1 to 4 or can I just do steps 1 and 4. Thanks.

    Comment by Sandy — September 5, 2008 #

  7. When I had the autorun.inf worm in the PC system, I could no longer use Yahoo Messenger. Will it help if I uninstall Yahoo MS and download another Yahoo MS? Thanks.

    Comment by Sandy — September 5, 2008 #

  8. Minimum do steps: 1,2 and 4.

    Will it help if I uninstall Yahoo MS and download another Yahoo MS

    Yes, uninstall, donwload a fresh Yahoo MS and install it.

    Comment by Patrik — September 5, 2008 #

  9. it worked well for me buddy. Thnx for the valuble service. I appreciate it.

    Comment by srivenu paturi — September 13, 2008 #

  10. Hi again! My kids classmate used a flashdrive in our PC that has redtube virus. Now each time we used the Explorer we see the pornographic site redtube.com. How can we fix this problem without affecting our files? Thanks.

    Comment by Sandy — September 15, 2008 #

  11. Please try Flash_Disinfector.exe by sUBs(read above, how to use it), if you are still having problems with your PC, I would recommend that you follow these instructions.

    Comment by Patrik — September 15, 2008 #

  12. I have McAfee antivirus and I got the message from it that it had detected and deleted the c:\autorunif trojan (sorry if I typed it’s exact name wrong but u know wat I mean) the problem was that it kept on doing it it kept detecting it and deleting it like every 30 seconds so I looked for a way to delete it and found one before this one and it said to restart the pc I did that and what i was using didn’t work then I did a full scan using McAfee and didn’t find anything. then I tried your step 1 to manually remove it I put the computer in safe mode than start run and typed in del /a:h /f c:\autorun.* and it came back saying that it couldn’t find it I doubt I have gotten rid of it can you help?????????

    Comment by John — November 14, 2008 #

  13. John, yes i can help you. Please follow these instructions.

    Comment by Patrik — November 14, 2008 #

  14. thank uuu verrry much.. it worked a lot for me..

    Comment by dillu — December 9, 2008 #

  15. Iwant to try but i have a problem with avenger…

    http://swandog46.geekstogo.com/avenger2/avenger.zip\\avenger.exe
    detected: Win32:Rootkit-gen [Rtk]

    :-(

    Comment by Gil — December 15, 2008 #

  16. Gil, its false alert. Disable your antivirus and try again.

    Comment by Patrik — December 15, 2008 #

  17. can you help me??? I do not know which file3s I should delete after launching the hijackthis….

    here is the log

    Logfile of Trend Micro HijackThis v2.0.2

    Comment by pichu — December 16, 2008 #

  18. pichu, yes your computer infected with autorun.inf trojan. Please follow these steps. I will help you.

    Comment by Patrik — December 16, 2008 #

  19. How use the avenger it ask for a validate script

    Comment by Mauro — December 24, 2008 #

  20. You should type a text from the step3 and click Execute button. If you need help, follow these steps.

    Comment by Patrik — December 24, 2008 #

  21. when i pluged in the usb in my computer,

    my antivirus AVAST gives alert about virus BV:AutoRun-G [Wrm]
    i gives the antivirus to delete this file but after sometime this alert comes on again and again.

    i don`t know what i have to do……….

    please help me to solve this problem….

    Comment by M Arshad Malik — December 30, 2008 #

  22. M Arshad Malik, please read the instructions above or follow these steps.

    Comment by Patrik — December 30, 2008 #

  23. I Have Remove BV:AutoRun-G [Wrm] By Flash_Disinfector.exe Try it

    Comment by Yuvraj YR — January 5, 2009 #

  24. If You Are Useing Avast !4.8 .Geting Warning Of Autorun.inf Found( BV:AutoRun-G [Wrm])
    For Stop This Message Use ‘Flash_Disinfector.exe’
    http://download.bleepingcomputer.com//sUBs/Flash_Disinfector.exe

    Comment by Yuvraj YR — January 5, 2009 #

  25. Gday,

    the command

    del /a:h /f c:\\autorun.*

    does not work when i type it into run.

    And this is the problem.

    LF to reply

    Comment by Tim — January 6, 2009 #

  26. Tim, you should run command console (Click Start -> Run, type cmd and press Enter) before enter “del /a:h /f c:\autorun.*”.

    Comment by Patrik — January 6, 2009 #

  27. thanks, it worked, appreciate it

    have you got anyidea how to get rid of Vamsoft.exe

    apparantly its very similar to Kamsoft.exe which i waht highjack this picks up

    Comment by Tim — January 7, 2009 #

Leave a comment

XHTML: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 4 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a


MY ANTI SPYWARE Powered by WordPress with Pool theme design by Borja Fernandez.
Entries and comments feeds. Valid XHTML and CSS. ^Top^