How to remove olhrwef.exe or the W32/Autorun-AAG worm.
Description:
The W32/Autorun-AAG worm is an infection that spreads through removable media devices such as flash drives, usb drives, and external hard drives. A user becomes infected when they insert an infected device in the computer. Once the device is inserted, your computer will autoplay the device and the infection will now spread to your computer.
During the infection process a file called olhrwef.exe will be created in your C:\Windows folder. This file will automatically start when you login into Windows. It will also create the C:\Windows\System32\nmdfgds0.dll file and add a autorun.inf file to every removable device on your computer. It will then create the follow registry key to start itself automatically:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”cdoosoft” = “%System%\olhrwef.exe”
Manual Removal Instructions for W32/Autorun-AAG
End these processes if they exist:
Learn how to end processes
olhrwef.exe
Delete these files if they exist:
Lean how to remove files
C:\Windows\olhrwef.exe
C:\Windows\System32\nmdfgds0.dll
Autorun.inf from the root of all of your removable media devices
Remove these Registry keys if they exist:
Learn how to remove Windows Registry entries
Warning: Editing the Windows Registry incorrectly can cause problems with your computer that may cause it not to operate correctly. Please edit the Registry only if you know what you are doing.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”cdoosoft”
















March 16th, 2009 at 3:35 pm
I have found cdoosoft in:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\”cdoosoft”=C:\WINDOWS\system32\olhrwef.exe
Thank you
April 28th, 2009 at 1:34 am
Thanks,
Its working Well …Thanks Lol…….
May 31st, 2009 at 4:17 am
thank u
July 11th, 2009 at 5:56 am
thamkYOu…. very much…. i also found the worm in specified location ,,, i deleted it …. thanku once again….
July 30th, 2009 at 12:21 am
I have found olhrwef.exe in user\application data
Thank You
Kind Regards
July 16th, 2010 at 10:58 pm
Awesome!