Worm.Autorun.BW has a lot of its clones. It is a malicious Trojan infection which secretly gets inside a computer. The virus is spread through spam e mails that have a zip or MS-Office file attached. Bt infact neither its a zip file, nor an MSOffice file, but it is Worm.Autorun.BW malware. once it has infected a computer, it will open ports on your network and allow hackers to access your PC remotely. And when they are connected to your system underground, they will spy and steal your data including personal information. Worm.Autorun.BW add itself for auto startup through autorun.inf file. This thing makes it get launched each time autorun.inf file is used. And that file is used each time you open up any folder (explorer.exe). So in this way, Worm.Autorun.BW keep itself active all the time. Even if you delete its malicious files, it will come again as it keeps a backup of it in .PIF file formate inside windows settings. It is recommended to use a proper anti-malware program to completely sweep Worm.Autorun.BW out of your computer.
What are symptoms of Worm.Autorun.BW and how dangerous it is:
Computer infected with Worm.Autorun.BW?
Need not to worry if your PC is infected. An efficient anti-malware program can fix your PC. If you want to remove it manually, please keep in your mind that manual removal is a complicated thing. Moreover this method dose not ensure 100% removal of malware. The best, easy and simple way to get rid of this virus is to install a proper anti-malware tool.
Worm.Autorun.BW Manual removal instruction:
Please make sure to create backup before getting started.
Stop malicious processes:
Open windows task manager, go to “Processes” tab and stop any Worm.Autorun.BW process which is running. It can be stopped by Right click on it and select “End process”.
Remove Worm.Autorun.BW registry settings:
Open Windows Registry editor by typing REDEDIT into RUN. Find and delete any keys and values related with this malware. (Please use the name of Malware to search for keys related to it)
Below is a list of possibly infected registry keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ’0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ’1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ’0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0
Delete Worm.Autorun.BW files & folders
Go to My Computer, search for malware files. Delete all the files and folders found. (Please use the name of Malware to search for keys related to it).
Possible locations:
%UserProfile%\
%UserProfile%\Application Data\
%UserProfile%\Start Menu\Programs\
Worm.Autorun.BW removal tools
To remove this virus Automatically, We suggest following softwares:

