Upload
dm-may-up-ko-cho-nguoi-ta-tai-thi-up-lam-chi-do-xau-xa
View
13
Download
3
Embed Size (px)
DESCRIPTION
Autorun Virus
Citation preview
So called autorun viruses were developed to infect external devices, such as infecting a victims PC while opening a flash drive in Windows Explorer
So called autorun viruses were developed to infect external devices, such as infecting a victims PC while opening a flash drive in Windows Explorer. An autorun viruse exploits the Autorun.inf file in the Windows OS which is used to launch and auto play programs and files that are stored in removable disks such as Memory sticks, DVDs, CD ROMs, USB Devices and much more. The autorun virus uses this feature to destroy files.
If your USB Drive is infected with autorun.inf virus, whenever you insert the USB stick virus files start to execute and infect your PC, it further replicates itself onto the PC by creating a number of copies of autorun.inf and .exe files on all drives of your PC.
If infected, the malwarecovertly directs the user to malicious websites. It might also install a key logger on to your PC that can capture your web site activity, login credentials usernames, passwords, account numbers, credit card details and other personal and sensitive information.
An autorun virus must be removed from a PC for it to be safe to use.
Instructions to remove autorun.inf virus from the USB drive:
Insert the USB drive onto your computer, dialogue box appears, click cancel
Type the USB drive letter on to the command prompt
Type dir/w/a and press enter, which will show up a list of the files in your flash drive. If you find Ravmon.exe, New Folder.exe, ntdelect.com, kavo.exe, svchost.exe, autorun.inf, remove these files
If the virus name is autorun.inf, type F:\del autorun.inf and enter to delete the same.
After all the above steps, perform an antivirus scan on the USB stick, just to verify whether all the viruses are removed
How to Delete autorun.inf on hard drive of a PC
Start the PC in safe mode
Open the command prompt
You will come across all these files mentioned below, go ahead and delete all these files.
%System%\config\csrss.exe
%WinDir%\media\arona.exe
%System%\logon.bat
%System%\config\autorun.inf
C:\autorun.inf
D:\autorun.inf
E:\ autorun.inf
F:\autorun.inf
autorun.inf files in all drives.
Open the registry editor to delete the parameters that are mentioned below
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableTaskMgr = 1
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
NoFolderOptions = 1
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
Worms = %System%\logon.bat
Restart your computer
This manual method to remove autorun virus can be implemented only for some simple type of autorun viruses. If you find the autorun virus even after the manual removal, it means that your PC has got infected with a mutant of autorun virus, which cannot be removed manually. There are autorun virus remover tools available that can help to remove and solve other variants of autorun virus.
Comodo Internet Security Software offers the best security solution with the defense + technology and auto sandbox technology which is found as the best defensive mechanism protecting the PC by fighting against malware and viruses in an isolated environment.
C gi l "virus autorun" c pht trin ly nhim cc thit b bn ngoi, chng hn nh nhim PC ca nn nhn trong khi m mt a flash trong Windows Explorer.An viruse autorun khai thc cc tp tin Autorun.inf trong cc h iu hnh Windows c s dng khi ng v cc chng trnh chi t ng v tp tin c lu tr trong a di ng nh Th nh, DVD, CD ROM, thit b USB v nhiu hn na.Cc virus autorun s dng tnh nng ny ph hy cc file.
Nu a USB ca bn b nhim virus autorun.inf, bt c khi no bn chn virus USB file bt u thc hin v ly nhim my tnh ca bn, n tip tc sao chp chnh n vo my tnh bng cch to ra mt s lng bn sao ca autorun.inf v cc file .exe trntt c cc a ca my tnh ca bn.
Nu b nhim, cc malwarecovertly hng ngi dng n cc trang web c hi.N cng c th ci t mt logger phm trn my tnh ca bn c th nm bt hot ng ca trang web ca bn, thng tin ng nhp tn ngi dng, mt khu, s ti khon, thng tin th tn dng v thng tin c nhn v nhy cm khc.
Mt loi virus autorun phi c ly ra t mt my tnh cho n c an ton s dng.
Hng dn loi b virus autorun.inf t a USB:
Chn a USB vo my tnh ca bn, hp thoi xut hin, nhp hy
Nhp cc k t a USB vo du nhc lnh
Loi dir / w / a v nhn Enter, m s hin th mt danh sch cc tp tin trong a flash ca bn.Nu bn tm thy Ravmon.exe, New Folder.exe, ntdelect.com, kavo.exe, svchost.exe, autorun.inf, loi b nhng tp tin ny
Nu tn ca virus l autorun.inf, loi F: \\ autorun.inf del v Enter xa cng.
Sau khi tt c cc bc trn, thc hin mt qut chng virus trn USB, ch xc minh xem tt c cc virus c loi b
Lm th no Xa autorun.inf trn cng ca mt my tnh
Khi ng my tnh trong ch an ton
M du nhc lnh
Bn s i qua tt c nhng tp tin c cp di y, i trc v xa tt c nhng tp tin ny.
% System% \\ config \\ csrss.exe
% WinDir% \\ media \\ arona.exe
% System% \\ logon.bat
% System% \\ config \\ autorun.inf
C: \\ autorun.inf
D: \\ autorun.inf
E: \\ autorun.inf
F: \\ autorun.inf
file autorun.inf trong cc a.
M trnh son tho registry xa cc thng s c cp di y
[HKCU \\ Software \\ Microsoft \\ Windows \\ CurrentVersion \\ Policies \\ System]
DisableTaskMgr = 1
[HKCU \\ Software \\ Microsoft \\ Windows \\ CurrentVersion \\ Policies \\ Explorer]
NoFolderOptions = 1
[HKLM \\ SOFTWARE \\ Microsoft \\ Windows \\ CurrentVersion \\ RunOnce]
"Worms" = "% System% \\ logon.bat"
Khi ng li my tnh ca bn
Phng php th cng ny loi b virus autorun c th c thc hin ch dnh cho mt s kiu n gin ca virus autorun.Nu bn tm thy virus autorun ngay c sau khi vic loi b dn s dng, n c ngha rng my tnh ca bn c nhim vi mt t bin ca virus autorun, m khng th c g b bng tay.C nhng cng c vi rt autorun remover c sn m c th gip loi b v gii quyt cc bin th khc ca virus autorun.
Comodo Internet Software Security cung cp gii php bo mt tt nht vi vic bo v + cng ngh v cng ngh sandbox t ng c tm thy nh l c ch phng th tt nht bo v my tnh bng cch chin u chng li phn mm c hi v vi rt trong mt mi trng b c lp.