Source: gfxden.blogspot.com
You need to download this little programs.
Simple step on how to prevent and remove autorun spyware/virus manually from removable disk
1. You need to disabled your Autorun/Autoplay
2. Kill the program that process in your system
3. Delete the files and remove in the startup programs
What is Autorun/Autoplay?
Autorun/Autoplay is the ability of many modern computer operating systems to automatically take some action upon the insertion of removable media such as a CD-ROM, DVD-ROM, or flash media. - wikipedia
The disadvantage of Autorun is it can pose a security threat, when the user does not expect or intend to run the software, such as in the case of some viruses and spyware, which take advantage of this feature to propagate. Imagine that the program runs in your computer without your knowledge, so here's how to disable Autorun/Autoplay using Group Policy
Autorun/Autoplay is the ability of many modern computer operating systems to automatically take some action upon the insertion of removable media such as a CD-ROM, DVD-ROM, or flash media. - wikipedia
The disadvantage of Autorun is it can pose a security threat, when the user does not expect or intend to run the software, such as in the case of some viruses and spyware, which take advantage of this feature to propagate. Imagine that the program runs in your computer without your knowledge, so here's how to disable Autorun/Autoplay using Group Policy
1. Click Start button > Run > type gpedit.msc then click OK

2. In Group Policy, expand User Configuration > Administrative Templates > System then double click Turn off Autoplay

3. Select Enabled and All Drives in Turn of Autoplay Properties, click Apply > OK

How to remove autorun spyware/virus in your hard drive or USB drive manually
In order to make a demo, I enabled my Autorun/Autoplay and insert a USB Drive infected with spyware and let the spyware run on my computer system. And now I want to remove it manually, here's how...
1. Show the hidden files and protected operating system files
Open My Computer, in Tools Menu select Folder Options....

In Folder Options, select Show Hidden files and folders and then unchecked Hide protected operating system files > Apply > OK

Go to User Configuration > Administrative Templates > Windows Components > Windows Explorer then select Disabled in the Remove the Folder Options menu item from the Tools menu > Apply > OK
2. Look for autorun.inf
Now open USB Drive, you can see the autorun.inf file and open it ( you also see this file in your Hard disk drive)

Before you open the folder, in your mouse right click the folder and click Properties



3. End the Process
Go to Task Manager or press “Ctrl + Alt + Del” keys, in Processes Tab select the file that you see in the autorun.inf then click End Process. If you get this message

Go to User Configuration > Administrative Templates> System > Ctrl+Alt+Delete options > Remove Task Manager, select Disabled in the Remove Task Manager Option > Apply > OK


For me I use Process Explorer to kill the process


4. Remove the file in the Startup Programs
You can remove it by using Autoruns, check the process programs in the Logon Tab
Click image to enlarge

Root directory (drive C, drive D etc..)
x:\windows
x:\windows\system32
x = where you install the windows
Other case you cannot delete the files because there is a message that the program is running, in this case you can use Unlocker. Unlocker has the ability to delete the file even if it is running.
In the Autoruns, Delete or you can unchecked programs so that it will not run again when the computer restart

Checked also Scheduled Tasks tab, delete the file At1.job (something like that)

This article is an alternative way to remove spyware and virus. If you want to see the full article CLICK HERE!