The other side of autorun.inf

September 1, 2007 6:19 am at 6:19 am 11 comments

Yuki Nagato in The melancholy of Suzumiya Haruhi typing 1000wpmAutorun.inf is the primary instruction file associated with the Autorun function. Autorun.inf itself is a simple text-based configuration file that tells the operating system which executable to start, which icon to use, and which additional menu commands to make available. In other words, autorun.inf tells Windows how to deal open the presentation and treat the contents of the CD.

The autorun.inf defines the following:

  • The process or application that will automatically run when a disk is inserted
  • Optionally, one can define the process or application that will run for specific Operating environments.
  • The icon that will represent your application’s CD or DVD when the drive is viewed with My Computer or Explorer.
  • Menu commands displayed when the user right-clicks the CD-ROM icon from My Computer or Explorer.

read more about autorun.inf here

Autorun is intended as a convenience feature: software distributed on a disc can automatically start an installer when the disc is inserted. However, autorun can pose a security threat, when the user does not expect or intend to run the software.
For instance, an attacker with brief and casual physical access to a computer can surreptitiously insert a disc and cause software to run. Alternately, malicious software can be distributed with a disc that the user doesn’t expect to contain software at all — such as an audio compact disc. Even music CD’s from well known name-brand labels have not always been safe. – wikipedia

It’s always been a hassle for us students who are using computers with a lot of malicious software. Some of these software are really getting into my nerve. (Ravmone.exe, Vundo, imgKulot, RECYCLER, more..) These malicious softwares use the power of autorun.inf to be able to gain access of the PC and propagate their selves by sticking their files to the system folders. But usually they reside on USB Flash Drives and infect other PC’s. And recently I’ve been experimenting some ways on getting rid of it. Here are some steps in deleting these malicious softwares.

Precautions:

  • Do not enter directly to your USB Flash Drive. Use [right click] -> open or explore
  • Make sure there are no running malicious software in the background
  • Be sure to have a cmd.exe on your USB. You can copy the cmd.exe from you X:windows\system32\ folder and put it to your Flash drive

General Steps in removing these softwares:

  • run cmd.exe
  • type in dir /a
  • if you can find the autorun.inf delete it by typing del autorun.inf /a /f
  • But before you can do this you must first know what are the accompanying files of the malicious software that is in your USB
  • Then delete the files that are not yours that you believe to be malicious using
    del <filename> /a /f
  • But this files can’t be deleted if its running on your system. Be sure to kill the process before trying to delete it.
  • If you can encounter some malicious programs who uses directory such as RECYCLER. First download the eraser portable from the net. [link to download]
  • Use the Eraser Portable to delete the directory and its subdirectories. (proceed to help if you need some help in using the program)

If you need more help on removing these softwares please feel free to to contact me at boting_231@yahoo.com .

How would a car function if it were designed like a computer? Occasionally, executing a maneuver would cause your car to stop and fail and you would have to re-install the engine, and the airbag system would say, “Are you sure?” before going off. (Katie Hafner)

Entry filed under: Blogging, Internet, IT, Journals, Technology, Viruses. Tags: .

Learn on your own Power up your USB with PortableApps

11 Comments Add your own

  • 1. Hanakurosu  |  September 5, 2007 7:21 pm at 7:21 pm

    Whats up man, I just recently viewed your blog and it states that how boring it is to live in the Philippines (Regarding the weather out there), anyway… I just got this damned annoying virus in my USB pen drive – (I just got this from my friends machine, where I copied files from him…) My anti virus which is BitDefender detects this fuckin; malware “autorun.inf” I tried several things on directly erasing it from the pen drive itself but unfortunately, it keeps on regenerating… (that’s the most annoying part here.) anyway hope you can assist me on my problem. thank you in advance ~

    PS. just email me here – its Hanakurosu123@yahoo.com
    (BTW I’m Singaporean and I’m planning on going there in manila for a vacation hehe lol)

  • 2. boting231  |  September 6, 2007 1:57 am at 1:57 am

    I’ll do everything in my power to help you. hihih.. I just finished writing my reply. :D

  • 3. Ozzy  |  October 2, 2007 9:21 am at 9:21 am

    Boting, unsaon na dayun pag-run sa cmd.exe na naa sa akong flash drive? DIli man unta i-open or explore kay mu-activate ang virus. So unsaon man pagrun sa comand-line?

  • 4. boting  |  October 5, 2007 2:32 am at 2:32 am

    Run> cmd
    cmd>
    x:>dir /a

    ingana lng :p

  • 5. zerofreeze  |  January 31, 2008 7:30 pm at 7:30 pm

    Dude, searching for the files accompanying the malicious software is quite difficult to know specially if you are not a geek in computers (unless you can find the INFO.EXE file). Your removal procedure is good but please remember that there are versions of this worm virus that you nor your antivirus can delete the said autorun.inf file. If I may suggest, download a copy of this tool: PRT (Perlovga Removal Tool).

    Download site: http://www.softpedia.com/get/Security/Security-Related/PRT-Perlovga-Removal-Tool.shtml

    Good luck in your programming career….

  • 6. oscar  |  March 11, 2008 7:04 am at 7:04 am

    i really can’t remove the virus…

  • 7. andback  |  March 20, 2008 8:39 pm at 8:39 pm

    Ive written blog about removing the autorun.inf virus http://andback.wordpress.com

    also talks about removing those viruses which even the antivirus cant remove.

    Hope that helps.

  • 8. Niko  |  March 23, 2008 8:55 am at 8:55 am

    Hi Friends,

    One way to delete Autorun.inf:
    1) Click on Start
    2) Click on Run
    3) Type cmd
    Now you will see dos prompt
    4) go to root dir say c:
    5) Type command: attrib -r -h -s autorun.inf
    6) Now type command: del autorun.inf

    Now you are safe.

    Anothe way to clean your hard drive as well as USB drive, just go to the lnk below:

    http://www.raymond.cc/blog/archives/2008/01/28/double-click-c-drive-at-my-computer-and-not-opening-fix/

    Regards,
    Niko

  • 9. M.Gunasekaran  |  July 4, 2008 7:56 am at 7:56 am

    drive is open , then click to AUTO expore
    plese reson.

  • 10. ламинат  |  August 24, 2008 7:39 pm at 7:39 pm

    9eThank’s for greate post.3l I compleatly disagree with last post . udq
    паркет 1f

  • 11. Mixon  |  June 5, 2011 1:19 pm at 1:19 pm

    РемонтМикс – Мы предлагаем недорогой и качественный ремонт квартир в Петербурге, а также ремонт офисов, домов, комнат, кухни, ванны. Ремонт магазинов

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Trackback this post  |  Subscribe to the comments via RSS Feed


who? me?

Talking about things in the web, my boring life, computer programming, animes, etc... anything you wanna think of.. its here. Oh yeah btw, I'm boting. (malapit kong yun ahh. :D)

 

September 2007
M T W T F S S
« Aug   Oct »
 12
3456789
10111213141516
17181920212223
24252627282930

a

Visitors

Blog Stats

  • 3,110 hits

Flickr Photos

watch your back

altar

baby samantha

Jaamans

More Photos

Corks


Follow

Get every new post delivered to your Inbox.