Worms spreads by creating a copy of itself and starts by autorun.inf files. It is essential to remove the malicious and autorun.inf files not only from computers but also from the source, and that is the USB Drive. PreciseSecurity have created a procedure to delete the malicious files on infected drives.
Method 1: Manual Removal Method
PROCEDURE:
1. While the computer is still off;
2. Plugin the USB Drive
3. Insert the Windows XP CD-ROM into the CD-ROM drive. It must be the bootable XP Installer
4. Start the computer from the CD-ROM drive. It will start Windows Setup screen
5. When the “Welcome to Setup” prompt appears.Press “R” to start the Recovery Console
6. If asked “Which Window installation would you like to logon to” select the number. Type“1",Hit Enter, if only one installation of Windows is present
7. Enter the administrator password, press Enter
8. It will bring you to command prompt, C:\Windows>
9. Proceed with the following command:- Type d: (This is the drive letter of USB. It can be e: or f: defending on how many hard disk or cd drive is installed)- Type attrib -h -r -s autorun.inf- Type “edit autorun.inf” it will open DOS Editor and display contents as follows
==========================
[autorun]
open=file.exe
shell\Open\Command=file.exe
shell\open\Default=1
shell\Explore\Command=file.exe
shell\Autoplay\command=file.exe
==========================
Take note on the file that it called to open (in above example it is file.exe)
10. Exit DOS Editor and return to command prompt, D:\>
11. Delete the file that was called to open on DOS Editor- Type del /f /a file.exe
12. Delete autorun.inf file- Type del /f /a autorun.inf
13. Exit Recovery Console by typing exit.
Method 2:
Remove Autorun virus - Microsoft patch KB971029
Microsoft has fixed a problem that prevents users from selectively disabling AutoRun features in an effort to stop the Conficker worm from spreading.
Microsoft said it recommends all customers to install the update, which affects all supported Windows versions.
Download links
The following files are available for download from the Microsoft Download Center:
Update for Windows Server 2008 (KB971029)
Windows6.0-KB971029-x86.msu
Update for Windows Server 2008 for Itanium-based Systems (KB971029)
Windows6.0-KB971029-x64.msu
Update for Windows Vista (KB971029)
Windows6.0-KB971029-x86.msu
Update for Windows Vista for x64-based Systems (KB971029)
Windows6.0-KB971029-x64.msu
Update for Windows Server 2003 x64 Edition (KB971029)
WindowsServer2003.WindowsXP-KB971029-x64-ENU.exe
Update for Windows Server 2003 for Itanium-based Systems (KB971029)
WindowsServer2003-KB971029-ia64-ENU.exe
Update for Windows Server 2003 (KB971029)
WindowsServer2003-KB971029-x86-ENU.exe
Update for Windows XP (KB971029)
WindowsXP-KB971029-x86-ENU.exe
Related Articles
1.how to remove sysdate.exe
2.How to remove I Love You Virus
3.How to Remove csrcs.exe or csrsc.exe Virus
4.How to remove regsvr.exe
5.Drives are not opening by double click. What to do ?
6.Signs of Intenet browser hijacker infection
7.Spyware threats and removal instructions
8.How to remove Autorun.inf
9. How to enable task manager
1. While the computer is still off;
2. Plugin the USB Drive
3. Insert the Windows XP CD-ROM into the CD-ROM drive. It must be the bootable XP Installer
4. Start the computer from the CD-ROM drive. It will start Windows Setup screen
5. When the “Welcome to Setup” prompt appears.Press “R” to start the Recovery Console
6. If asked “Which Window installation would you like to logon to” select the number. Type“1",Hit Enter, if only one installation of Windows is present
7. Enter the administrator password, press Enter
8. It will bring you to command prompt, C:\Windows>
9. Proceed with the following command:- Type d: (This is the drive letter of USB. It can be e: or f: defending on how many hard disk or cd drive is installed)- Type attrib -h -r -s autorun.inf- Type “edit autorun.inf” it will open DOS Editor and display contents as follows
==========================
[autorun]
open=file.exe
shell\Open\Command=file.exe
shell\open\Default=1
shell\Explore\Command=file.exe
shell\Autoplay\command=file.exe
==========================
Take note on the file that it called to open (in above example it is file.exe)
10. Exit DOS Editor and return to command prompt, D:\>
11. Delete the file that was called to open on DOS Editor- Type del /f /a file.exe
12. Delete autorun.inf file- Type del /f /a autorun.inf
13. Exit Recovery Console by typing exit.
Method 2:
Remove Autorun virus - Microsoft patch KB971029
Microsoft has fixed a problem that prevents users from selectively disabling AutoRun features in an effort to stop the Conficker worm from spreading.
Microsoft said it recommends all customers to install the update, which affects all supported Windows versions.
Download links
The following files are available for download from the Microsoft Download Center:
Update for Windows Server 2008 (KB971029)
Windows6.0-KB971029-x86.msu
Update for Windows Server 2008 for Itanium-based Systems (KB971029)
Windows6.0-KB971029-x64.msu
Update for Windows Vista (KB971029)
Windows6.0-KB971029-x86.msu
Update for Windows Vista for x64-based Systems (KB971029)
Windows6.0-KB971029-x64.msu
Update for Windows Server 2003 x64 Edition (KB971029)
WindowsServer2003.WindowsXP-KB971029-x64-ENU.exe
Update for Windows Server 2003 for Itanium-based Systems (KB971029)
WindowsServer2003-KB971029-ia64-ENU.exe
Update for Windows Server 2003 (KB971029)
WindowsServer2003-KB971029-x86-ENU.exe
Update for Windows XP (KB971029)
WindowsXP-KB971029-x86-ENU.exe
Related Articles
1.how to remove sysdate.exe
2.How to remove I Love You Virus
3.How to Remove csrcs.exe or csrsc.exe Virus
4.How to remove regsvr.exe
5.Drives are not opening by double click. What to do ?
6.Signs of Intenet browser hijacker infection
7.Spyware threats and removal instructions
8.How to remove Autorun.inf
9. How to enable task manager
No comments:
Post a Comment