Removing the FlashDrive autorun.inf VirusDesai Kalpesh 1 of 6
Removing the FlashDrive autorun.inf Virus
Some of the symptoms of an infected computer:
Hidden files cannot be viewed. Changing options in Tools/Folder Options has no effect.Changing registry values has no effect. No restriction removal tools likeRRTetc are able to fixthe problem.
Regedit cannot be found
when you try to invoke it from the RUN box.
Task Manager has been disabled
cannot enter a particular drive
ie when you click on your drive letters(C, D, E etc) inMy Computer nothing happens.
Computer has become slow and there is noticeable delay in characters to appear on screenwhen you press in keyboard. The
left and right strafing keys in Counter Strike 1.6 dontwork
. They work on CS: Condition Zero tho.Virus Removal Strategy that works for me:
Full System scan
A full system scan using any of the following Antiviruses/antispyware tools usually do thetrick.1.
Eset Smart Security Business Edition
.2.DOS mode virus scan using the antivirus tools in
Identifying the Virus manually
Most of the time a virus gets detected but the antivirus software is unable to remove it. This is because either the virus is currently running on your system as one of the processesor is being protected by the Operating System Itself. So before doing the virus scan you have to take a few precautions:1.DownloadProcessXPif you Task Manager is disabled.2.DownloadHijackThis from TendMicro
Both of these tools are helpful in revealing and killing hidden processes running on your system or those which have recently make changes. If you find something like:1.monit.exe- runs under explorer.exe, keylogger app, creates problems with Counter Strike2.scvhost.exeor 713xRMTmon.exe- not to be confused with svchost.exe, an important windows
process.3.wscript.exe- a harmless process which can be made to execute harmful VBScripts likemswin32.dll.vbs 4.amvo.exeor amva.exe
5.autorun.inf - Its actually a harmless file.more info. But can be used to invoke a virus when you
click a folder/drive which has this file.Its best to kill/terminate them by Right Click/
End Process Tree
. Also a good practice is toEndProcessTree
Explorer.exe as well. And starting the antivirus executable fromTaskManager/File/Run. And then run a system scan. Explorer can be started again fromTaskManager/File/Run/ Type
[enter].Several antivirus support forums help out people who submit their HijackThis log files.Viruses usually invoke at startup. So its a good idea to check the startup list byStartMenu/Run/
/Startup where you should find something suspicious Uncheck them(only if suspicious ones!)likescvhost.exe. Uncheck them(only if suspicious ones!).Restart your PC. Do system scan.So how do you findout which process is malicious? Google them. If your data is important toyou and you really want to remove the virus without formatting, you have to do this bit. Whenyou familiar with which System processes you should be able to isolate the culprit by justseeing the list.