Solved! Use GPHONE.EXE (Worm Autoit) Removal Guide

I will tell you in this post how to fix the issue manually and how to clean it automatically using a special powerful removal tool. You can download the removal program for free here:

Manual removal instructions:

GPHONE.EXE – Worm Autoit removal

File MD5 Virus Alias
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Worm Autoit
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Trojan Hllw
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Trojan Downloader
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Worm Sohanat
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Worm Autorun
GPHONE.EXE 494bbfb409ff1ff97c002a781f77f7d4 Trojan Agent

GPHONE.EXE size: 8781253 bytes
GPHONE.EXE hash: 494BBFB409FF1FF97C002A781F77F7D4

Created files:

%WinDir%\gphone.exe
%SysDir%\gphone.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: Explorer.exe gphone.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Yahoo Messengger: %WinDir%\System32\gphone.exe

Detected by UnHackMe:

GPHONE.EXE
Default location: %WinDir%\GPHONE.EXE

Dropper information:
MD5: 494bbfb409ff1ff97c002a781f77f7d4
File size: 8781253 bytes