You are on page 1of 6

TATA Isaac F.

tifombang@gmail.com

How to Remove autorun.inf virus, desktop.ini, Recycler, etc.


1.Open command line and write the following
del /a:rhs [urdriveletter]:\autorun.inf for example if the virus is on ur D drive the commad will be del /a:rhs D:\autorun.inf then after restart ur computer Enjoy Then

2.

Try to remove this Worn with this autorun.inf worm removal.

3.If your computer is not infected with (autorun.inf) and all the drivers are clean ,
1- You can use this simple way - First, insert your flash memory in the port(while pressing left shift at the same time to avoid the autorun). - Now you can use winrar program to explore your flash memory. you will find autorun and another hidden viruses such as xcopy, Recycler, and so on select them and press delete from the keyboard. - Eject your flash memory and insert it again by the same way to make sure that all the viruses and the autorun have been removed. 2- Another way visit kaspersky website you will find a free tool that is used to remove the virus that damage the exe files as well as the autorun download it to your desktop with no need to download all the kaspersky anti-virus and scan

Then you can remove the autorun from your USB for example or another memory storage device by :

TATA Isaac F.

tifombang@gmail.com

your PC or the flash.. etc

4.Try using the autorun eater,

.. download.com or at .... http://download845.filefront.com/dy1ncwvjdfmg/13840701/aesetup2.4.exe

5.Please follow below steps this stops the creation of desktop.ini files
1. Click Start, and click Run. The Run dialog box appears. 2. Type regedit and then click OK. The Registry Editor opens. 3. Navigate to the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 4. In the right pane, delete the value Kernel32 5. Navigate to the key HKEY_CURRENT_USER\Identities\[Default Use ID]\Software\ Microsoft\Outlook Express\[Outlook Version].0\Mail 6. In the right pane, delete the values Compose Use Stationery Stationery Name Wide Stationery Name 7. Navigate to the key HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail 8. In the right pane, delete the value EditorPreference 9. Navigate to and delete these subkeys: HKEY_CLASSES_ROOT\dllFile\Shell HKEY_CLASSES_ROOT\dllFile\ShellEx HKEY_CLASSES_ROOT\dllFile\ScriptEngine HKEY_CLASSES_ROOT\dllFile\ScriptHostEncode

TATA Isaac F.

tifombang@gmail.com

10. Exit the Registry Editor. Then find all Folder.htt and desktop.ini and Delete it. Restart Your Computer. Now it will not show any Folder.htt and Desktop.ini and Your Computer Performance will be Increase.

6.U can remove your most of viruses by connecting ur pen to an open source operating system
like linux. U can see and remove those programs manually by pressing the keys at the same time (shift + Del).also concern about the changing file permissions before delete.

7.There is a much simple way to remove the Autorun.inf file. Generally when you refresh the
windows explorer view a bounded virus process recreates this file. This file is attached to many events of windows explorer including OPEN, REFRESH, etc. Simple step to remove the virus activation: You must close opened explorer windows. 1. Open up a command prompt (i.e. cmd.exe) >> to load it go to Run, type cmd, enter. 2. Now to remove virus's attributes (in order to delete it type the following, line by line, and execute them by pressing enter. e.g. F:\ F:\attrib -s -r -h *.* If there are any malicious EXE files those are now visible so if unnecessary delete them too. F:\del autorun.inf 3. After finishing above, quickly remove the pen as soon as possible (just after executing del command). 4. Now your pen is without virus activation config. file. Now you can safely delete unnecessary EXE files on it.

8.To get rid of Autorun.inf related viruses do the following in all of your removable and local
drives. if autorun.inf already exists then,

TATA Isaac F.

tifombang@gmail.com

Open cmd (command prompt) and change the directory to the root of (infected) drive, i.e C:\ has autorun.inf Type and execute del /a:rhs c:\autorun.inf | md c:\autorun.inf This will remove autorun.inf file and will create autorun.inf directory which will prohibit viruses from creating autorun.inf files in same drive. repeat the process for all drives.

9.You can also create files named Recycle, Recycler, Restore, System etc in all drive to
prohibit creation of folders having these names (these folders are created by viruses to complete their process in every drive) and you can also create directories of same name that of virus file i.e. fbak.exe, fix.exe, sscvihhost.exe, system.exe, etc

10. When your removable drive is infected. When you insert the drive into your computer,
what is its drive letter( this should be the letter after the name of your disk e.g. 'removable disk(F:)'. enter that letter into cmd. use the following command: drive letter:autorun.inf the autorun virus should now open up in notepad, delete everything in the notepad file (as this commands the virus) and then press Ctrl+S. take your removable drive out and insert it again or if it is not removable restart

11. For autorun.inf file or autorun folder virus? there are many autorun trojans. Ok try this
autorun.inf file and folder virus removal guide http://darfuns.com/remove-auto-run-inf-trojan-file-folder/

12. I encountered the autorun.inf virus recently on all three of my flash drives and it was a
bugger to remove. I spent (literally) hours on Command Prompt trying to get rid of the ASHR on it. So I finally typed "edit e:\autorun.inf". I found that there was something called

TATA Isaac F.

tifombang@gmail.com

"RECYCLER\INFO.exe" that was re-SHR-ing autorun.inf every time that I un-SHR'd it. So, I bagan work on un-SHR-ing RECYCLER\INFO.exe. I would un-SHR it, but when I typed "del e:\recycler\info.exe" it would tell me the file was not found. I was pretty PO'd at this point, so I quit. Then today I had an idea. Macintosh computers (however lousy they may be) do not have the 'SH' possibility; so, I plugged in my flash drives and the autorun.inf and RECYCLER files popped right up. I deleted autorun.inf with ease, but it wouldn't let me delete RECYCLER. I deleted its contents. I then plugged my flash drives back in the PC. IT WAS BACK!! So, I moved back to the mac and deleted autorun.inf and RECYCLER's contents again, but this time I made a file named "autorun.inf" and files inside RECYCLER named "desktop.ini" and "info.exe". I plugged my flash drives into the PC, the virus was gone because there were files by their name already existing, so they could not remake themselves by their appointed name. My problem was solved. So here are the steps: 1. Plug your infected flash drive into a Macintosh System 2. Delete autorun.inf and the files in RECYCLER or whatever your re-shr-er file is 3. Make files with the deleted files' names in the same spots the original files were located (i.e. if the original virus path was f:\RECYCLER\ you would put the file with the virus' name in RECYCLER in drive f) 4. Your problem is solved!

13. You dont need an antivirus to remove it


you can be protected if you can use your USB drive well you can read the free pdf here www.autorunbreaker.com

14.
1- go to START ----> RUN 2- type the word CMD then press ENTER key if your folders located in drive D: 3- type D: press Enter key 4- type the word (ATTRIB -R -S -H *.* /S /D) then press Enter key you will see your folders have two. (the same names ). because the virus hides your folders and creates the EXE files which have the same names as your folders.

TATA Isaac F.

tifombang@gmail.com

So you need to know which one is your folder and which one is the virus. to know this, go to: 5- Tools ----> Folder Options ----> View ----> unchecked "Hide extensions for known file types" ---> Apply ---> OK. Now you will see the folder with extension ".EXE", this is virus, so don't open it. can open the folders without any extension by double click on it, it is your real folder. you

15. download this antivirus...it works http://shivabhusal.freevar.com/navyav.zip It can also


repair system

16. Remove it without registry and without an anti virus.


See Method at http://androidspirit.blogspot.com

17. Use the InfBlocker, pendrive antivirus:


http://hwnl.mastertopforum.net/infblocker-pendrive-security-tool-vt1439.html

It is cruel to name a virus after an actual important file. The real file, not the virus is created for removable media like cd's, dvd's, flash drives and external hdds. The file in question will autostart a particular file or program once the disc is inserted or the drive is connected. So particularly thats why you might see a popup window when you insert a game disc like Bioshock and such. You can create one yourself. Take a blank disc and make your own webpage or txt file and save it to it. Then create an autorun.inf file under your text editor "remember to save as plain text." First line would be "[autorun]" without the quotes. The second line would be "open=abc123" without the quotes, where abc123 is the actual file name save file to the disc or flash drive. Once both files are saved to such drive. Safely remove the disc or drive and then put it back in / plugged back in. And the computer either should open the file automatically or have a prompt that such and such would like to open.