What is Autorun.inf

Posted by Admin | 11/12/2008 | | 0 comments »

Autorun.inf viruses are virus that uses the autorun feature of windows to spread itself on computer. This virus make a copy of the autorun.inf file to the root or main directory of all the drives on your PC, internal or external disks, to make the virus runs every time the external disks like pendrives or USB drives were inserted or every time you double-click the drives through the windows explorer.

A lot of this infections were found on Bolivia, Vietnam, Ecuador, Pakistan, Philippines, India,Indonesia, Malaysia, Colombia and Mexico ( base on Google Trends results ). Base on the same source , late of 2007 was peak of this kind of computer virus infections but it also shows that in year 2008 the autorun.inf virus are still prevalent and keep on spreading. Known virus variants of kind are the YahLover ( uses schost.exe and killer.exe ), Bacalid ( uses ctfmon.exe ), IMGKULOT and FAIZAL.JS virus

How to remove autorun.inf here
Post comment here




About autorun.inf
Post comment here

What is Autorun.inf

Ever wonder why your Anti Virus detects a virus in your autorun.inf whenever you insert your removable disk (USB, flash drive, et.) but it can’t disinfect it nor delete it or if you’re having a hard time accessing drives? Tried deleting it manually but you can’t find the file?.Autorun.inf is hidden and it can’t be remove or disinfected by Anti virus. And you try finding the autorun.inf file but failed even if you select to show all files from folder option? more about autorun.inf

Here’s the step it -:
  1. First, boot your system in Safe Mode Command Prompt Only ( pressing F8 before the Windows Logo displays ) ( this mode because all start-up programs are not started on this mode )
  2. Click Start button
  3. Click Run
  4. Type cmd
  5. Change the directory of drive if your pendrive is H directory type H:
  6. Type autorun.inf
  7. Type del autorun.inf
  8. Type atrrib -a -h -r -s autorun.inf
  9. Reboot
If you dont understand try this video tutorial here
Or you can try use Flash Disinfector, download here
Post comment here



Post comment here

The malware in questions redirects all your web requests to the above said URLs, since it does not want you to download any fixes or visit sites to find what the problem is about.

The problem of webpages redirecting to go.google.com, go.yahoo.com or go.msn.com is easily fixable and you do not require to call in tech support or pay for support charges to your computer vendor, follow the simple steps to get rid of the redirect virus.

Step 1 - Disable Your Internet Connection: The most important thing you should do before doing anything else, is disabling your internet connection (If you are infected, use the print option below to print the instructions). The reason is that the virus or trojan transmits information from your PC to an external server, without a Internet connection it becomes practically useless and lowers the threat to your personal information.

Step 2 – Get Your Hands on a Anti-malware Software: The next step is to start the recovery process, so you will need to download a anti-malware software that will scan and remove the virus. Since you turned of your Internet connection (which is also useless since all webpages will redirect to the above said pages) you will need to download the software on some other PC, put it on a portable/flash drive and install it on your PC.

Step 3 – Install Malware and Scan in Safe Mode: Once you have gotten hold of the malware software, it is time to get back to your PC and install the anti-malware, it is advisable to do this in Safe mode with Networking disabled (be sure to get the latest software copy from the website), so that the virus infection is not able to communicate with the Internet. To boot into safe mode, start the PC and press the F8 key, you will see several options, from there choose Safe Mode.

Once you have logged into the PC, install the anti-malware software.

Step 4 – Run a full scan and delete the infections: Once you have installed the software start the anti-malware and run a full PC scan with it, the scan may take sometime. Once the scan has completed it will detect the infections that is causing the redirect problem. Put a tick mark against all the infections and ask the software to clean it up.

Some infections will not be fully cleaned up and will require a reboot, so after the clean process is completed reboot the computer and log in to normal mode once again.

Step 5 – Run a confirmation scan to See if the infections are deleted: With the internet disabled run another scan with the anti-malware just to confirm that all the infections are cleared. Once you have confirmed it you can turn on the Internet once again.

[ Download go.google.com virus removal tool for windows XP | Download go.google.com tool for Windows Vista ]

Post comment here

Normally when a virus infects a windows system which causes a drive opening problem, it automatically creates a file named autorun.inf in the root directory of each drive.

This autorun.inf file is a read only ,hidden and a system file and the folder option is also disabled by the virus. This is deliberately done by the virus in order to protect itself. autorun.inf initiates all the activities that the virus performs when you try to open any drive.

You have to just delete this file and restart your system to correct this problem.

Follow the set of commands below to show and delete the autorun.inf

1. Open Start>>Run and type cmd and press enter. This will open a command prompt window. On this command prompt window type the following steps.

2. type cd\

3. type attrib -r -h -s autorun.inf

4. type del autorun.inf

5. now type d: and press enter for d: drive partition. Now repeat steps 3 and 4. Similarly repeat step 5 for all your hard disk partition.

Restart your system and your trouble will be fixed.

Note: For all those who are not able to correct this problem, after following the above procedure can use a tool called Ravmon Virus Killer, download it from here

Post comment here

Setting up a Web site with your own domain name (www.me.com) is a straightforward process, though finding a name you like may prove difficult. Registration usually gives you exclusive use of a domain name for two years.

Step 1 - Go to an official Internet registrar online. See the More Resources section below for a good suggestion on where to start.

Step 2 - Enter the name or phrase of the domain name you would like to register. Follow the rules regarding name length and format.

Step 3 - Search for the name.

Step 4 - If the name is already taken, enter a new name and search again until you find one that is still available. If you tried .com as a suffix, try .org or .net instead.

Step 5 - Register the domain name.

Step 6 - Pay the filing fee online or through the mail, following the instructions on the Web site.

Post comment here

In most of the cases, even if the virus is been already removed by your anti-virus program, it doesn’t restore the registry back to the original state. Also anti-virus usually does not delete the registry entry created by the virus.

For restoring the registry settings,follow the steps given below

Enable folder option in explorer

1. Go to Start > RUN

2. Type regedit and press enter.

3. Go to HKEY_CURRENT_USER > Software > Microsoft > Windows > CurrentVersion > Policies > Explorer

4. On the right side of the screen, you can see some registry entry names, out of them, right-click on NoFolderOptions and click Modify option.

5. A new small screen pops up, on this screen, sen the value data field as 0 (zero).Press OK.

That’s it but it requires reboot.

If you don’t want to play with the registry yourself ,you can also download the registry file and double click it to add it to the registry.

Post comment here

Problem:

It is due to some kind of virus/ trojan activity which normally disables the task manager.Now due to this problem when ever the user press alt+ctrl+del to launch window task manager it gives an error saying “Task Manager is being disabled by your administrator”.

Solution:

To Enable the Disabled Task Manager on your system

1. Press window key+r to show run prompt

2. Follow the following steps

  1. Enter gpedit.msc in the run prompt and click OK
  2. In the Group Policy settings window
  3. Select User Configuration
  4. Select Administrative Templates
  5. Select System
  6. Select Ctrl+Alt+Delete options
  7. Select Remove Task Manager
  8. Double-click the Remove Task Manager option’.
  9. Set the property of this item as disabled.

For Those who use Windows XP Home Editioncan use the registry to enable Task Manager

1. open start >> run and type regedit

2. Navigate to the following path:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

3. You will find a registry key with name DisableTaskMgr of type: REG_DWORD

4. Double click the key with and set the Value to 0

5. Exit the registry and restart to see the effect

Post comment here