Manual Removal of W32/AutoIt.QK Worm » regsvr.exe
This Worm Copies its file(s) to Windows folder as hidden files or active non-hidden files.
This worm information updated on September 19, 2009.
Other names of W32/AutoIt.QK Worm:
This worm is also known as Win32/Autoit.AG, Worm.Win32.AutoIt.QK, Worm.Win32.AutoIt.qk, WORM_EMBEDDED.AB.
Download Registry, Taskmanager and Folder Options Repair Tool
W32/AutoIt.QK Worm Manual Removal Instructions
Recommend Removal from Safe Mode:
How to Start in Safe mode:
Restart your Computer, Press F8 Repeatedly, when your Screen turns on, Select Safe mode, press enter.
End the Following Active Process Before Removal
- [ Kill the Process, Use Killbox if your Access Denied ]
- %Windows\System32\regsvr.exe
- %Windows\System32\svchost .exe
- %Windows\regsvr.exe
[ No Exact Information about Files, search above related files in Program files Folder ]
If you have any of these files in running process from task manger, end the process before removal.
Note: if task manager is disabled, Download the following file, Click to Download - Enable Registry.reg[ Right Click - Save Target As/Linked Content As ]
Open it with Regedit.exe [%system32\regedit.exe], then it Confirms Add to registry Yes or No, Confirm Yes, then click Ok.
Click Start, Run,Type regedit,Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor.
- Download this UnHookExec.inf, [ Right Click - Save Target As/Linked Content As ]
- Save it to your Windows desktop.
- Do not run it at this time, download it only.
- After booting into the Safe Mode or VGA Mode
- Right-click the UnHookExec.inf file and click Install. [This is a small file. It does not display any notice or boxes when you run it.]
- Or Download Regfile to enable Registry editor
- Download Registry Enabler [ Right click - Save Target As ]
- Open it with Registry editor
Delete The Entries
HKEY_USERS\S-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXX-XXXX\Software\Microsoft\Windows\CurrentVersion\Run
Delete file entries from right side
Search Registry For W32/AutoIt.QK Worm File Names listed above to remove completely,
Edit Menu - Find, enter Keyword and remove all value that find in search.
Recommended Removal Tools:
Kaspersky Antivirus or Internet Security [Shareware]
Spyware Doctor [Shareware]
AVG Antivirus [Freeware]
Killbox [Freeware]
Written by magakos on October 18th, 2009 with no comments.
Read more articles on svchost.exe and autoit and automatic shutdown and regsvr.exe and W32/AutoIt.AA Trojan and otherSoftware and manual removal and worm removal and Windows.















