Remove autorun.inf manually

so i will tell u how to remove autorun.inf virus which is cause of opening
of your drives in separate window when u click on the drive name in my computer

There is a Trojan/virus (either the Win32/Pacex virus or the Win32/PSW.Agent.NDP trojan) that uses those two files. Here is how you can get rid of them:

1) Open up Task Manager (Ctrl-Alt-Del)
2) If wscript.exe is running, end it.
3) If explorer.exe is running, end it.
4) Open up “File | New Task (Run)” in the Task manager
5) Run cmd
6) Run the following command del #:autorun.* /f/a/s/q with other drives in turn

where # is replaced by drive name e.g-c,d,e etc

Be careful with this command it can delete your all data one by one from your hdd if execute wrongly so place your mouse on x position of cmd prompt windows and if it starts deleting your files close it

or we can do this step by without ending explorer.exe

just hit windows+R it will show you run dialog box now type cmd there,it will give you command prompt

now navigate to #: where # replaced with your different drive name

i am taking the example of c: drive

now write c:del/a/s/q/f and give a space now press tab until you see autorun.inf press enter

now yo done do the rest steps as i said (be careful see clearly autorun.inf before deleting it and don’t delete any ntdelect there it may crash your system)

7) Go to your WindowsSystem32 directory by typing cd c:windowssystem32
8 ) Type dir /a avp*.*
9) If you see any files names avp0.dll or avpo.exe or avp0.exe, use the following commands to delete each of them:

attrib -r -s -h avpo.exe
del avpo.exe

10) Use the Task Manager’s Run command to fire up regedit
11) Navigate to HKEY_CURRENT_USER SOFTWARE Microsoft Windows CurrentVersion Run (as usual, take a backup of your registry before touching it!)
12) If there are any entries for avpo.exe, delete them.
13) Do a complete search of your registry for ntde1ect.com and delete any entries you find.
14) Restart your computer.

Popularity: 21% [?]

Comments

17 Responses to “Remove autorun.inf manually”
  1. From where did you copied this ?

    lol, look at the Header and the body,
    whats avpo.exe doing in the body
    I thought it was removing the autorun.inf

    And more , the virus name was amvo.exe
    not avpo.exe, the file names are
    amv0.dll, amvo1.dll

    More, you can actually disable autorun through
    registry tweak and through GP

    PS: this is my first visit to THL

  2. Bik says:

    Love the advice. Thank you.

  3. Alexwebmaster says:

    Hello webmaster
    I would like to share with you a link to your site
    write me here preonrelt@mail.ru

  4. Abdul Hai says:

    Hello webmaster

    There is simple way to remove Auto play.inf
    ->Goto command prompt type (drive letter):
    ->attrib –s –h –r auto run.inf
    ->Del auto run.inf
    Follow same steps to all the drives
    Follow # as c,d,e,f……. drive letters
    After rename all the drives and then scan with your anti virus.

  5. arbu says:

    u r saying the same thing which i said with a temp solution ,you must have to remove entries from r4egistry and must del tghe two dll file i specified otherwise problem will be problem

  6. dea says:

    hi then, can you help me to show some tips how to prevent viruses, autorun,recycler, etc into my usb drive, i usually have problems from my friend who want to copy data from my computer, and my computer take a long time while loading. and it usually become not responding when i turn on my computer. please can you help me??

  7. arbu says:

    @dea
    use USB disk security for the same

  8. $ says:

    @arbu
    Brother, USB Disc Security is not 100% efficient.Nod 32 can detect better.

  9. simple tarika bhi hai

    just use Combofix(downlaod 1st file)

  10. ▐ ►•▄█•█•█▀█▀█◄▐ says:

    @Navneet Saini

    if we will discuss here about software then what is the need of hackers library

    @$

    +1 for that

  11. Vinay~ says:

    It’s more easy..
    In my computer Goto Tools>Folder Option>View>tick Show Hidden Files & Folder
    & uncheck Hide protected operating system files>Apply>OK

    now Go To all drives & delete Autorun.ini manually…

  12. JIm says:

    @vinay

    lemo if hidden file and superhidden file will be shown then

    the trick poster is not fool that he uses tab button in cmd prompt

    they are not working when u r infected by autorun.inf

  13. winnie says:

    My PC has been infected Win32.autorun.Senna.e and has been infected pendrive, mobile phone.I use AVG, Avast to delete but cannot..This virus can made your folder to be hidden and everything is gone..I use command prompt to delete but just can in pendrive cannot in C: driver because I already go in the system..

  14. ▐ ►•▄█•█•█▀█▀█◄▐wa says:

    @winnie

    there is a tool called malwarebytes google it and scan with that

    i m sure your problem will be solved

  15. smartjani says:

    Remove autorun.inf virus manually.

    1). Go to any folder.In that on the top menu go to Tools–> Folder Options, which will be beside File, Edit, View, Favourites.

    2). A window pops up after you click on folder options.In that window go to View tab and select the option Show hidden files and folders.Now uncheck the option Hide protected Operating system files.Click Ok

    3). Now Open your drives (By right click and select Explore. Don’t double click!) Delete autorun.inf and MS32DLL.dll.vbs or MS32DLL.dll (use Shift+Delete as it deletes files forever.) in all drives include Handy Drive and Floppy disk.

    4). Open folder C:\WINDOWS to delete MS32DLL.dll.vbs or MS32DLL.dll (Use Shift+Delete ) 5). Go to start –> Run –> Regedit and the Registry editor will open

    6). Now navigate in the left pane as follows: HKEY_LOCAL_MACHINE –> Software –> Microsoft –> Windows –> Current Version –> Run .Now delete the entry MS32DLL (Use Delete key on keyboard)

    7). Go to HKEY_CURRENT_USER –> Software –> Microsoft –> Internet Explorer –> Main and delete the entry Window Title “Hacked by Godzilla”

    8). Now open the group policy editor by typing gpedit.msc in Start –> run and pressing enter.

    9). Go to User Configuration –> Administrative Templates –> System. Double Click on entry Turn Off Autoplay then Turn Off Autoplay Properties will display.Do as follows: Select Enabled

    10). Select All drives and Click OK

    11). Now go to start –> Run and type msconfig there and press Enter.A system configuration utility dialogue will open.

    12). Go to startup tab in it and uncheck MS32DLL .Now click Ok and when the system configuration utility asks for restart ,click on exit without restart.

    13). Now go to Tools –> Folder Options on the top menu of some folder again and select the Do not show Hidden files and check Hide operating system files.

    14). Go to your recyclable bin and empty it to prevent any possiblity of MS322DLL.dll.vbs lying there.

    Now restart your PC once and you can now open your hard disk drives by double clicking on them

  16. jimwa says:

    lol @smartjaini

    spammer huh

    the first thing they do is to disable hidden attribute then they remove folder option

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!