自动运行病毒的手动清除办法

2014/10/15

Those so-called “Autorun virus” is used to infect an external device, such as in Windows Explorer to open the flash drive will lead to the victim’s computer infected by the virus. Autorun viruses use to open within the Windows operating system and automatically run the program and stored on a removable disk, such as a memory stick, DVD discs, CD and USB devices and other documents Autorun.inf file. The advantage of this feature to automatically run the virus destroy files.

If your U disk is autorun.inf virus infection, as long as you insert U disk, the file that the virus will begin to infect your computer. It also copies more autorun.inf and executable (.exe) file on the computer within your computer all the drives.

Once infected, malware hidden to direct users to a malicious Web site. It may be safe keylogger on your computer to capture activity on your site, the login cohabitation user name, password, account number, credit card information and other personal and sensitive information.

For security, you must clear the computer automatically run the virus.

Remove autorun.inf virus descriptions from the USB drive:

“The U disk into your computer, click Cancel when the dialog box appears

“Open a command prompt, enter U disk drive

“Input dir / w / a and press Enter, which will show you all the files U disk. If you find Ravmon.exe, New Folder.exe, ntdelect.com, kavo.exe, svchost.exe, autorun.inf, please delete these files

“If the virus name is autorun.inf, type F: \ del autorun.inf, and then press Enter to delete

“Once all of the above steps, run anti-virus software to scan your U disk, determine whether all viruses have been removed

How to delete autorun.inf computer’s hard drive

“Start the computer in Safe Mode

“Open a command prompt

“You’ll see the file shown below, please delete these files:

%System%\config\csrss.exe
%WinDir%\media\arona.exe
%System%\logon.bat
%System%\config\autorun.inf
C:\autorun.inf
D:\autorun.inf
E:\ autorun.inf
F:\autorun.inf
(出现在所有驱动器的autorun.inf 文件)

Open the Registry Editor to remove the following parameters

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
DisableTaskMgr = 1
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
NoFolderOptions = 1
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
“Worms” = “%System%\logon.bat”

“Restart the computer

The above method is used to remove some of the simple types of autorun virus. If you find that after clearing, autorun virus still exists, then this means that your computer is infected with a mutant virus that can not be used manually deleted. There autorun virus removal tool on the market that can help you eliminate and solve other problems autorun virus variants.

Comodo Internet Security software provides you with the best security solutions, and its defense + technology and automatic sandbox technology is recognized as the best defense mechanism to protect against malware and viruses in an isolated environment to protect your computer.

Write a comment

Name
Comment