The process for disabling Windows Autorun:-
- Go to Start Menu and click Run...
- Open the Group Policy Editor by typing gpedit.msc at the run prompt and hit enter.
- In the Group Policy Editor that opens up, choose Local Computer Policy -> Computer Configuration -> Administrative Templates -> System. In the right pane find a setting named "Turn off Autoplay" and double click it.
- In the "Turn off Autoplay Properties" dialog box, select Enabled(for disabling autoplay) and "For all drives" from the drop-down menu. And, then click apply and OK.
- Autoplay is now disabled. Close the Group Policy Editor.
This will prevent the malware from running automatically and help you keep your system clean. Generally most antivirus softwares are capable of handling such threats but they may not prevent a new virus from running. So to be on the safer side use this tip. Also I should recommend that you always access your removable drives from the address bar rather than double-clicking them to open or using right-click options because some malwares come with autorun.ini which has code to link the executable to the default Open command or Explore command of the Explorer. To access your removable drive from the address bar, just enter the drive letter of your removable drive and a colon and press enter(e.g., "F:" or "G:").
Usually these worms are hidden and have system attribute so you will not be able to see these files unless the "Show hidden files and folders" is selected and "Hide protected operating system files" is unchecked in the Folder Options dialog box under the View tab. If you see any suspicious file or folder in the root of the removable drive which you have not created or saved in the drive, remove these files immediately. You can also scan the files with your antivirus software.
These malwares if executed may create a copy of the executables in the "[System Drive]2:\Windows", "[System Drive]:\Windows\System32" folders and in the roots of all the drives, and also in any other attached removable drive. They also create autorun entries for the executables so they can automatically start each time windows is started. Most of the viruses try to disable the task manager or the registry editor so that it is dificult to remove the malware from the memory.
I will also write a post which describes how to remove such malwares from the active memory and your computer if it is infected.
2 comments:
I didn't know much about blogs but i surely do know about ARNAB,he is a very genuine guy and a true friend and simply "A Genius".
I don't have words to explain his blog,
its really marvelous.I liked the posts and the tags,they are really very helpful.
Keep Up The Good Work Dude
@Sid: Thanks for your support. I will definitely try to help you more often. If you have any queries regarding computer problems, you may post them here.
Post a Comment
Please comment if you like my posts and suggest improvements if you disliked. You can also post your queries if you have any, and I will try to answer it.