The other side of autorun.inf
September 1, 2007 6:19 am at 6:19 am 11 comments
Autorun.inf is the primary instruction file associated with the Autorun function. Autorun.inf itself is a simple text-based configuration file that tells the operating system which executable to start, which icon to use, and which additional menu commands to make available. In other words, autorun.inf tells Windows how to deal open the presentation and treat the contents of the CD.
The autorun.inf defines the following:
- The process or application that will automatically run when a disk is inserted
- Optionally, one can define the process or application that will run for specific Operating environments.
- The icon that will represent your application’s CD or DVD when the drive is viewed with My Computer or Explorer.
- Menu commands displayed when the user right-clicks the CD-ROM icon from My Computer or Explorer.
read more about autorun.inf here
Autorun is intended as a convenience feature: software distributed on a disc can automatically start an installer when the disc is inserted. However, autorun can pose a security threat, when the user does not expect or intend to run the software.
For instance, an attacker with brief and casual physical access to a computer can surreptitiously insert a disc and cause software to run. Alternately, malicious software can be distributed with a disc that the user doesn’t expect to contain software at all — such as an audio compact disc. Even music CD’s from well known name-brand labels have not always been safe. – wikipedia
It’s always been a hassle for us students who are using computers with a lot of malicious software. Some of these software are really getting into my nerve. (Ravmone.exe, Vundo, imgKulot, RECYCLER, more..) These malicious softwares use the power of autorun.inf to be able to gain access of the PC and propagate their selves by sticking their files to the system folders. But usually they reside on USB Flash Drives and infect other PC’s. And recently I’ve been experimenting some ways on getting rid of it. Here are some steps in deleting these malicious softwares.
Precautions:
- Do not enter directly to your USB Flash Drive. Use [right click] -> open or explore
- Make sure there are no running malicious software in the background
- Be sure to have a cmd.exe on your USB. You can copy the cmd.exe from you X:windows\system32\ folder and put it to your Flash drive
General Steps in removing these softwares:
- run cmd.exe
- type in dir /a
- if you can find the autorun.inf delete it by typing del autorun.inf /a /f
- But before you can do this you must first know what are the accompanying files of the malicious software that is in your USB
- Then delete the files that are not yours that you believe to be malicious using
del <filename> /a /f - But this files can’t be deleted if its running on your system. Be sure to kill the process before trying to delete it.
- If you can encounter some malicious programs who uses directory such as RECYCLER. First download the eraser portable from the net. [link to download]
- Use the Eraser Portable to delete the directory and its subdirectories. (proceed to help if you need some help in using the program)
If you need more help on removing these softwares please feel free to to contact me at boting_231@yahoo.com .
How would a car function if it were designed like a computer? Occasionally, executing a maneuver would cause your car to stop and fail and you would have to re-install the engine, and the airbag system would say, “Are you sure?” before going off. (Katie Hafner)
Entry filed under: Blogging, Internet, IT, Journals, Technology, Viruses. Tags: .










1.
Hanakurosu | September 5, 2007 7:21 pm at 7:21 pm
Whats up man, I just recently viewed your blog and it states that how boring it is to live in the Philippines (Regarding the weather out there), anyway… I just got this damned annoying virus in my USB pen drive – (I just got this from my friends machine, where I copied files from him…) My anti virus which is BitDefender detects this fuckin; malware “autorun.inf” I tried several things on directly erasing it from the pen drive itself but unfortunately, it keeps on regenerating… (that’s the most annoying part here.) anyway hope you can assist me on my problem. thank you in advance ~
PS. just email me here – its Hanakurosu123@yahoo.com
(BTW I’m Singaporean and I’m planning on going there in manila for a vacation hehe lol)
2.
boting231 | September 6, 2007 1:57 am at 1:57 am
I’ll do everything in my power to help you. hihih.. I just finished writing my reply.
3.
Ozzy | October 2, 2007 9:21 am at 9:21 am
Boting, unsaon na dayun pag-run sa cmd.exe na naa sa akong flash drive? DIli man unta i-open or explore kay mu-activate ang virus. So unsaon man pagrun sa comand-line?
4.
boting | October 5, 2007 2:32 am at 2:32 am
Run> cmd
cmd>
x:>dir /a
ingana lng :p
5.
zerofreeze | January 31, 2008 7:30 pm at 7:30 pm
Dude, searching for the files accompanying the malicious software is quite difficult to know specially if you are not a geek in computers (unless you can find the INFO.EXE file). Your removal procedure is good but please remember that there are versions of this worm virus that you nor your antivirus can delete the said autorun.inf file. If I may suggest, download a copy of this tool: PRT (Perlovga Removal Tool).
Download site: http://www.softpedia.com/get/Security/Security-Related/PRT-Perlovga-Removal-Tool.shtml
Good luck in your programming career….
6.
oscar | March 11, 2008 7:04 am at 7:04 am
i really can’t remove the virus…
7.
andback | March 20, 2008 8:39 pm at 8:39 pm
Ive written blog about removing the autorun.inf virus http://andback.wordpress.com
also talks about removing those viruses which even the antivirus cant remove.
Hope that helps.
8.
Niko | March 23, 2008 8:55 am at 8:55 am
Hi Friends,
One way to delete Autorun.inf:
1) Click on Start
2) Click on Run
3) Type cmd
Now you will see dos prompt
4) go to root dir say c:
5) Type command: attrib -r -h -s autorun.inf
6) Now type command: del autorun.inf
Now you are safe.
Anothe way to clean your hard drive as well as USB drive, just go to the lnk below:
http://www.raymond.cc/blog/archives/2008/01/28/double-click-c-drive-at-my-computer-and-not-opening-fix/
Regards,
Niko
9.
M.Gunasekaran | July 4, 2008 7:56 am at 7:56 am
drive is open , then click to AUTO expore
plese reson.
10.
ламинат | August 24, 2008 7:39 pm at 7:39 pm
9eThank’s for greate post.3l I compleatly disagree with last post . udq
паркет 1f
11.
Mixon | June 5, 2011 1:19 pm at 1:19 pm
РемонтМикс – Мы предлагаем недорогой и качественный ремонт квартир в Петербурге, а также ремонт офисов, домов, комнат, кухни, ванны. Ремонт магазинов