Prevent Autorun.inf file in USB Drives From Automatically Executing Virus

by renjith on April 26, 2008 · 4 comments

in Trojans and Mobile Viruses

Nowadays the major cause of my system getting infected with virus is from the USB drives.When the USB drives are plugged into a computer previously infected with a virus then these viruses are automatically copied to the drives along with autorun.inf file.The virus  infects all executable files in my flash drive, then creates a hidden autorun.inf file at the roof of the pendrive.

Usb sandisk VirusThe autorun.inf file is useful only when an installer can automatically start the installation of the setup program when a disc is inserted.Turning off the autoplay also doesn’t prevent the autorun file from executing.

Raymond has found out a registry hack which will allow you to to globally block autorun.inf from automatically executing.Open notepad and copy the code below and save it as AutorunHack.reg file instead of .txt file.

REGEDIT4
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionIniFileMappingAutorun.inf]
@="@SYS:DoesNotExist"

                    Autorun Prompt Windows

Open this AutorunHack.reg file  and click Yes if you’re asked “Are you sure you want to add the information in AutoRunHack.reg to the registry?”.Next time you insert a USB drive into your system then Windows will not execute the information in any autorun.inf file that may be present.

Related: Recover deleted files from corrupt USB Drives

Be Sociable, Share!

Related posts:

  1. Crossplatform virus – the latest proof of concept
  2. Orkut banned by a virus!! (Removal included)
  3. Recover deleted files from corrupt USB thumb drives,Memory cards and Hard disks
  4. Bypass or Prevent Keyloggers from logging Keyboard inputs
  5. Linux OS less than 50mb for Pen drives

{ 4 comments… read them below or add one }

Anonymous October 28, 2008 at 7:01 pm

damn good work dude

Reply

Anonymous February 20, 2009 at 9:12 am

yeah
good one

Reply

Bob March 15, 2010 at 10:25 pm

Hi. When I click 'Yes" to access the registry it says I can't access the registry.

Reply

Anonymous October 4, 2010 at 10:42 pm

hi.. pls do a search on how you would remove a certain virus named tbpoixx.exe, tbpoix.exe and x.exe.. they are all diff. viruses and they came with the autorun.inf virus.. it makes all of my files in the pendrive hidden, making it not accessible even though you can view your hidden folders..

Reply

Leave a Comment

Previous post:

Next post: