07 February 2011

Autorun in your USB drive

This virus is very popular among cyber cafes. Whenever you plug in your USB drive, it automatically get infected by this virus. If your computer get infected, some variants will disable Registry Editor (regedit) and disable Folder Options, creating a paralyzed Windows. You need to remove the virus first before you can restore Windows back to normal.

How to repair a computer infected with this virus?

  • Download Flash_Disinfector to your desktop.
  • Open and follow any prompts that may appear.
  • It may ask you to insert your flash drive and/or other removable drives including your mobile phone. Allow the utility to clean up those drives as well.
  • Let it finish scanning before exiting.
  • Restart your computer when done.

How to prevent this from infecting your computer?

  • First of all, do not plug in suspicious USB drive even if you are not sure.
  • Disable autorun for removable drive using either one of these methods:
Method A:

1. Run Notepad and type in:

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"

2. Save as DeAuto.reg (select All files under the filename bar) on Desktop and run the file. Click YES.
3. Autorun should has been disabled now. To test, insert a CD with Autorun.inf such as MS-Office CD.
Note: This method may work on Windows XP and above.

Method B:


1. Download TweakUI from Microsoft. Note: Requires Windows XP with at least SP1.
2. In Control Panel, open TweakUI.
3. Locate + My Computer + Autoplay + Types and uncheck Enable Autoplay for removable drives.
4. Click OK.

    Method C:

    Refer to Microsoft Knowledge Base article 967715 on how to use Group Policy to disable Autorun on newer Windows version and other methods available.

    • You should now can safely insert the infected usb drive for disinfection. Hopefully your current AV can disinfect the virus.
    • If you don't have an Anti-Virus or would like to change to another AV, i recommend Avira Antivir Personal (Free). Download from their website. Warning! You should never install more than one AV. 
    • Once you have installed Avira Antivir Personal, you need to restart the computer.
    • Remember to always scan for removable drives.

    Good luck!

    EUL Level : LEVEL 5

    No comments:

    Post a Comment