Open cmd window, in this sample the pen drive is G:
G:
attrib -r -s -h autorun.inf
ren \\.\f:\autorun.inf\con. dummy
; edited: Add next line
ren \\.\f:\autorun.inf\nul.protected dummy1
rd autorun.inf /s /q
Use the following instructions to remove Flash Disinfector protection (autorun.inf folder).
Enjoy...
One or more files with the name OLHRWEF.EXE creates, deletes, copies or moves the following files and folders:
- Deletes c:\windows\system32\olhrwef.exe
- Deletes c:\windows\system32\nmdfgds0.dll
- Creates c:\windows\system32\nmdfgds0.dll
- Creates c:\windows\system32\c.exe
- Deletes c:\windows\system32\c.exe
- Deletes c:\oobbyju.ex
- Copies filec:\windows\system32\olhrwef.exe to c:\oobbyju.ex
- Deletes c:\autorun.in
- Creates c:\autorun.in
- Deletes d:\oobbyju.ex
- Copies filec:\windows\system32\olhrwef.exe to d:\oobbyju.ex
- Deletes d:\autorun.in
- Creates d:\autorun.in
- Deletes c:\docume~1\user\locals~1\temp\am1.rar
- Creates c:\docume~1\user\locals~1\temp\am1.rar
- Creates c:\docume~1\user\locals~1\temp\am.exe
- Deletes c:\docume~1\user\locals~1\temp\am.exe
- Deletes c:\windows\temp\scsA1.tmp
- Deletes c:\windows\temp\scsA6.tmp
- Copies filec:\docume~1\user\locals~1\temp\am.exe to c:\windows\system32\olhrwef.exe
- Deletes c:\windows\system32\nmdfgds1.dll
- Creates c:\windows\system32\nmdfgds1.dll
File size 2.60 MB (2,733,056 bytes)
MD5: C9F729D8EA160F7AD1B96F8141E42217
SHA-1: 0C7E9E780BF692AA6283B1033C6ADB722FB2058C
============================================================
Files Created
%AppDataCommonDir%\3d7dad1\LivePCGuard.exe
%AppDataCommonDir%\3d7dad1\SA3d7d.exe
%AppDataCommonDir%\3d7dad1\SAV.ico
%AppDataCommonDir%\3d7dad1\564.mof
%AppDataCommonDir%\3d7dad1\SAVSys
%AppDataCommonDir% = C:\Documents and Settings\All Users\Application Data
Files size 89.5 KB (91,648 bytes)
MD5: 09FE476072CB9FF3D2B5A6DFE3B5B063
SHA-1: 3BEEDF0671011A41C31BA39C21A41D39CF499D71
============================================================
Files Created
%Temp%\herss.exe
%Temp%\cvasds0.dll (0-9)
X:\p3vwxx.exe
X:\autorun.inf
843 KB (863,232 bytes)
MD5: F8417CB6A51DB3800226D04EACE44E0D
SHA-1: 4727E788A42C50B8DE22AB4FF9E0E2D744B444AE
============================================================
File created
%WinDir%\updatevideo.exe
%WinDir%\hide.exe
Hosts midified = blank
Files size 87,552 bytes
MD5: 286C5EFA693B823C6523CD34D6E38C72
SHA-1: 2AEA05BCE93218ED40EF58C1268848CA23A6C421
============================================================
Files Created
%Temp%\xvassdf.exe
%Temp%\4tddfwq0.dll (0-9)
X:\qw6t0mpm.exe
X:\autorun.inf
Files size 89.0 KB (91,136 bytes)
MD5: 5644358BDDB526E022B8FCBD4ECBF88D
SHA-1: 3B28440BB4A62E259AD7493977B8501EE5E46FFD
============================================================
Files Created
%Temp%\herss.exe
%Temp%\cvasds0.dll (0-9)
X:\9qqigqwf.exe
X:\autorun.inf
File size 160 KB (163,840 bytes)
MD5: 505A4F71F3E5678DD3C09A94F2408A69
SHA-1: 43017F8A41FFC7D0EF306B98EF82EBF4977B99B0
============================================================ Files Created / download
%Temp%\Sfb.exe
%Temp%\Sfc.exe
%Temp%\Sfd.exe
%WinDir%\msa.exe
%WinDir%\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
%WinDir%\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
%System%\Sshnas21.dll
%Temp% = C:\Documents and Settings\[UserName]\Local Settings\Temp\
%WinDir% = C:\Windows\
%System% = C:\Windows\System32\
Files size 110 KB (113,152 bytes)
MD5: E34FAB7B93540E77D58D06638CB9BC01
SHA-1: 52DD2A545CE61BF8274A723F9424D47CE78D7E14
============================================================
Files Created
%Temp%\herss.exe
%Temp%\cvasds0.dll (0-9)
X:\ws.exe
X:\autorun.inf
Files size 92.0 KB (94,208 bytes)
MD5: F4BD7CA06FC0F838A41EEFF09DBFF197
SHA-1: 4AE28CC4342115233AD78FD2CC5EE7C764E94EA5
============================================================
Files Created
%Temp%\herss.exe
%Temp%\cvasds0.dll (0-9)
X:\bveijo.exe
X:\autorun.inf
88.5 KB (90,624 bytes)
MD5: B628CA8ADD399A5FFD69AACEF3214BB4
SHA-1: 03E5C5998995FE67AA8C24FB954090615C595E45
============================================================
Files Created
%Temp%\herss.exe
%Temp%\cvasds0.dll (0-9)
X:\9d6tpg.exe
X:\autorun.inf
arking.exe
MD5: 75A6D3A8F00DBC7A9D9939D3BBEC3345
SHA-1: 105CFAC1B1ADE1AC1F4EB2648FF3A92C4FD15B78
============================================================Files Added
%System%\mgking.exe
%System%\arking.exe
%System%\mgking0.dll (0-9)
%System%\arking0.dll (0-9)
X:\cbbw88s.exe
X:\autorun.inf
MD5 : 3ca42dce383f331794569ab634f6ddcb
SHA1 : 700c4bee552b5adb7bc88d34eb0356632ebb7716
============================================================File addeds
%System%\twking.exe
%System%\zaking.exe
%System%\twking0.dll (0-9)
%System%\zaking0.dll (0-9)
X:\wehds63.exe
X:\autorun.inf
MD5 : 41d2fe10bdf82c5fa3fd504b88a46f44
SHA1 : 48a2a97cb1d08dfed03aaabad5e8f3f171090584
============================================================
Files Added
%System%\AEV3szxc10.dll
%System%\AEV3szxc11.dll
%System%\AEV3szxc20.dll
%System%\AEV3zxc.exe
%UserProfile%\Microsoft\FV3smx4pnp.dll
MD5 : ae9525756191032f15db120e642322db
SHA1 : 3a140d223f4d0095c58b19f9a3716857a9997ca3
============================================================Files Added
%System%\FCO0szxc10.dll
%System%\FCO0szxc11.dll
%System%\FCO0szxc20.dll
%System%\FCO0zxc.exe
%UserProfile%\Microsoft\BFV3smx4pnp.dll
MD5 : bc6674796fd2923d4feafa0207698a35
SHA1 : ed56503b0112a8e221906cd18cbe907eb3adbf0a
============================================================
Files Added
%System%\SYO0szxc10.dll
%System%\SYO0szxc11.dll
%System%\SYO0szxc20.dll
%System%\SYO0zxc.exe
%UserProfile%\Microsoft\DriversSystem32.dll
File size 103,184 bytes
MD5: BD95F136DAE1263834D9D00280304565
SHA-1: B31CE0032421774BFF81A1C7D6700465C0CCF29A
============================================================
Files Created
%System%\olhrwef.exe
%System%\nmdfgds0.dll (0-9)
X:\9dlvtiil.exe
X:\autorun.inf
Files size 105,429 bytes
MD5: 3C12DE682D0B835A95252AFE21EF1429
SHA-1: 4D18B6EADF353E34BE2A16F6D0B0F6BE4DB4FB87
============================================================
Files Created
%System%\olhrwef.exe
%System%\nmdfgds0.dll (0-9)
X:\e2.cmd
X:\autorun.inf
File size 120,510 bytes
MD5: 1D5103D7DF40BF58F654099C6E5E6D74
SHA-1: CE2F24D7D24B5E808C456FFF10CF0F92FFB70CBF
============================================================
Files Created
%Temp%\herss.exe
%Temp%\cvasds0.dll (0-9)
X:\nx.exe
X:\autorun.inf
Files size 110,765 bytes
MD5: 90D5C4EF66788980F0A22BCB5362EAC3
SHA-1: 0D84734DC363B82C9545C36D3EAABEABF7EADB61
============================================================
Files Created
%System%\olhrwef.exe
%System%\nmdfgds0.dll (0-9)
X:\nkbd1v.exe
X:\autorun.inf