Web.Net Internet Cafe
Not a member?

If you aren't a member yet, it only takes a couple of minutes to register! Members get these benefits and more!

* Start new topics and reply to others
* Subscribe to topics and forums to get automatic updates
* Get your own profile and make new friends
* Customize your experience here
* Download Software & Games
* Download your online games addys
* Dowmloads E-Books, photoshops & Progamming Tutorials
Register Now!

Web.Net Internet Cafe

WEB.NET CHAT SITE
 
HomePortalRegisterLog in
Similar topics
    DONATE via Paypal
    Poll
    Top posters
    kyleksido
     
    bLake
     
    webnetrhung
     
    jkblaze15
     
    chaddy_sumaga
     
    estoryahee
     
    kathir_anitha
     
    mjerard
     
    trotskiii
     
    coolseng
     
    Navigation
     Portal
     Index
     Memberlist
     Profile
     FAQ
     Search
    SOPA & PIPA
    Thu 26 Jan - 15:44 by
    1,000,000 Likes to Stop SOPA and PIPA.Anti PIPA and SOPA Anti PIPA and SOPA

    PAYAG BA KAYONG I-SHUTDOWN ANG FACEBOOK? AT IBA PANG SITE PARA LANG SA RESOLUTION NA ITO!!!?







    Right now, there are two pieces of …


    [ Full reading ]
    Comments: 0
    Computer Shop Complete Set-up Package
    Sun 30 Jan - 7:12 by
    Computer Shop Complete Set-up
    Package


    We Accept Computer Shop Set-up.

    Package include:
    - Networking
    - Operating System intallation
    - MS Office 2007 & 2010
    - 100's OF Games TO BE SELECTED (Lan & Online)
    - Timer Server (Cafe Manila, HANDY CAFE TIMER) OR COIN OPERATED SYSTEM
    - Deepfreeze (optional)
    - Anti-Virus

    Just Visit Web.Net Internet Cafe Located at Rizal cor. Delicona st. Tandag, Surigao …


    [ Full reading ]
    Comments: 0
    Coin Operated PC Timer
    Tue 25 Jan - 16:43 by
    COIN OPERATED TIMER FOR YOUR INTERNET SHOP PC'S







    1.) Digital time indicator which disables
    the monitor, keyboard or mouse when timer runs out.
    2.) Compact design
    3.) Last one minute alarm function


    [ Full reading ]
    Comments: 0
    SERVICES OFFERED
    Thu 23 Dec - 1:57 by webnetrhung
    Internet (Chatting & Web Surfing)
    LAN Games & Online Games
    Encoding
    Printing
    Layouting
    Invitation Cards
    Photo Editing
    CD & DVD Burning
    Audio & Video Remix
    ID Lamination
    PVC ID
    Games Installation (PC, PSP, MP3, MP4)
    Software Installation
    Hardware Installation
    Network Installation
    Computer Repair Hardware, Software & Troubleshooting



    +
    ----
    -

    [center]WEB.NET INTERNET
    CAFE

    NOW Accept....


    Software …


    [ Full reading ]
    Comments: 0
    WEBNET Internet Cafe Services Offered
    Mon 20 Dec - 9:42 by














    Comments: 0

    Share | 
     

     Removing AUTORUN.INF virus manually

    Go down 
    AuthorMessage




    Join date : 1970-01-01

    PostSubject: Removing AUTORUN.INF virus manually   Wed 9 Feb - 14:24

    Introduction

    AUTORUN.INF Viruses are virus that uses the Autorun feature of Windows to spread itself on computers. This virus makes a copy of the autorun.inf file to the root or main directory of all the drives on your PC, internal and / or external disks, to make the virus runs every time the external disks like pendrives or USB drives were inserted or every time you double-click the drives through the Windows Explorer.

    A lot of this infections were found on Bolivia,Viet Nam, Ecuador, Pakistan, Philippines, India, Indonesia, Malaysia, Colombia and Mexico (this list of countries were based on the Google Trends results for the AUTORUN.INF VIRUS keyword search: [You must be registered and logged in to see this link.] Based on the same source, late of 2007 was the peak of this kind of computer virus infections but it also shows that in year 2008 the autorun.inf virus are still prevalent and keep on spreading. That’s why I decided to write an article about this autorun.inf virus.

    Known virus variants of this kind are the YahLover (which uses scvhost.exe and killer.exe), Bacalid (which uses ctfmon.exe), IMGKULOT and FAIZAL.JS virus.
    Prevention of Autorun.INF Virus

    I still believe that prevention is better than cure so I have prepared here several points on how to prevent this kind of infection.

    1. First method is you can disable the AUTORUN feature of Windows by applying a registry modification on the Windows’ Registry Editor. To do this:

    * Download: DISABLE-AUTORUN.REG and save this file on your computer.
    * After downloading the file, open the folder where you download it and double-click the file. You will be confirmed by Registry Editor if you want to proceed, just click Yes button to continue. (If a different message was seen such as “Registry Editing has been disabled by your administrator.”, possibly your PC is infected already by a virus that prevents registry access. To correct this read the section on Removing Autorun.INF virus.)
    * Restart your computer to apply these changes.

    2. Another method is to create an AUTORUN.INF folder on the root directories (main directory usually represented by backslash symbol \ ) . You can do this via Windows Explorer or Command Prompt but I will recommend the method via Command Prompt.

    * To run command prompt, click Start then Run or press the key combination: Winkey + R
    * Type CMD then press enter. This will open the black and white environment.
    * On the prompt, type MD C:\AUTORUN.INF then press enter key.
    * Repeat this procedure to other hard drives and USB drives. Just replace the C letter from the command with the appropriate drive letter of each storage device.
    * If this fails, maybe your computer is infected already by the virus so read the next section for the solution of this problem.

    Removing AUTORUN.INF virus manually

    Manual removal procedure of the autorun.inf virus will vary depending on the attachment of the virus on the system. Actually this kind of infection is very easy to remove. Simple DOS commands can easily remove this kind of infection.

    The following are just generic instructions and some of the steps might not be applicable to some virus infections that uses autorun.inf.

    1. First, boot your system in Safe Mode Command Prompt Only. This can be done by restarting your computer and pressing F8 before the Windows Logo displays. It is important that you start the computer in this mode because all start-up programs are not started on this mode.

    2. When you see the black and white environment, type the following commands (commands in BOLD). This commands will be used for analysis of the infection only:

    * CD \ – This change the current folder to the main directory of drive C
    * DIR /AH – Displays all files that are hidden. Usually virus hides their files by changing its attributes to Hidden and System attributes. If you find a file: AUTORUN.INF, it confirms the infection of the virus.
    * TYPE AUTORUN.INF – This shows the content of the file autorun.inf. From the picture below you will see that the name of the virus is SAMPLE-VIRUS.EXE, which the name will usually comes with the line Open or Explore or Shell line of the autorun.inf. This shows that the virus carrier is the file SAMPLE-VIRUS.EXE
    Safemode Command Prompt Only

    Command Prompt window after dir/ah and type autorun.inf

    3. To remove the infection based on the analysis above type the following command:

    * ATTRIB -H -R -S C:\AUTORUN.INF – unhides the hidden file autorun.inf
    * DEL C:\AUTORUN.INF
    * Repeat this step to other drives by replacing C:\ with other letters

    4. To make sure that the carrier will not run during start-up, you need to make sure that it is disabled. Do this using the MSCONFIG tool of windows.

    * On the same Safemode Command Prompt Mode, type MSCONFIG
    * This will run the System Configuration Utility.
    * As shown below, uncheck the suspected file. This will disable it from start-up and will not run again. To see other places where programs were place to run on start-up, see my previous posts: How to Determine the Windows Startup Programs?

    System Configuration Utility

    System Configuration Utility window

    Note: This manual removal is only recommended when your installed anti-virus is not working due to the said autorun.inf virus infection. My advice is that when the virus is already removed manually, try reinstalling or installing an antivirus and update your virus definition file and scan your system to ensure a virus-free PC.

    If these steps specified here does not work for you, use TrendMicro Hijackthis (this is free and downloadable). Use it to analyze the system and produce a file called HIJACKTHIS.LOG. Send hijackthis.log produced to my email address so that I could analyze it and suggest an appropriate solution for it.

    Related posts:
    Back to top Go down
     
    Removing AUTORUN.INF virus manually
    Back to top 
    Page 1 of 1
     Similar topics
    -
    » Removing Vray watermark

    Permissions in this forum:You cannot reply to topics in this forum
    Web.Net Internet Cafe :: PC Tips & Tricks :: Tutorials-
    Jump to: