 Trojan.AutoRun.A. Removal Help What is Trojan.AutoRun.A?It is a Trojan that drops an AUTORUN.INF file in order to automatically execute it when main hard drives are accessed. In other words, when trying to open C, D, E drives in My Computer they will not open normally, instead a message pops when clicked on the drives saying that Windows cannot find xn1i9x.com. The same issue might happen with other names mentioned below:
n1deiect.com
ntde1ect.com
nudeiect.com
ntdelect.com
nideiect.com
ek.com
d.com
usdeiect.com
80avp08.com
dosocom.com
xfoolavp.com
uxdeiect.com
Trojan also drops malicious files, makes them hidden and disables Windows "Show hidden files and folders" function. Deleting any of these files will remain unrealised because Trojan adds a autorun registry which loads files on boot.
Note that, USB Flash Drives will be affected with Trojan.AutoRun.A as well.
The infected AutoRun.inf file is containing the following information:
[AutoRun]
open=xn1i9x.com
;shell\open=Open(&O)
shell\open\Command=xn1i9x.com
shell\open\Default=1
;shell\explore=Manager(&X)
shell\explore\Command=xn1i9x.com
Possible error messages:
Avpo.exe Application Error
Amvo.exe Application Error
Kavo.exe Application Error
 How to remove Trojan.AutoRun.ATip. Manual spyware removal is a complicated and unadvisable procedure for inexperienced user. Pcindanger is suggesting automated and secure Trojan.AutoRun.A removal: 1. Download "Spyware Doctor". 2. Install program on your computer ( how to install Spyware Doctor?). 3. To perform computer scan press Start Scan button. Wait till scan is over and report is generated. 4. Proceed by pressing Fix Checked button to delete Trojan.AutoRun.A. 5. Need Spyware + Virus protection? Download Spyware Doctor with AntiVirus. Trojan.AutoRun.A EntriesThe following dll files are created: amvo0.dll, gnsmo.dll, amvo1.dll, avp0.dll, taso0.dll, kavo0.dll, kavo1.dll. The following exe files are created: amvo.exe, avpo.exe, avp0.exe, kavo.exe, semo2x.exe. Hijackthis Entries:O4 Entries:
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe Bookmark this page
|