The article describes the procedure to remove an Autorun.inf virus from a computer. The methods compiled here are simple and correct to date. However, it is recommended that these be followed carefully to avoid problems. Since it is a difficult and time-consuming procedure, you can also go to an expert virus removal helpdesk. It will save you a great deal of time and money.

Autorun.inf virus is a dangerous program that exploits Autorun.inf, a common file of Windows operating system to run on removable media and other drives viz. C: on your computer. It can be quite difficult to deal with this virus as it is capable of re-running after removal. Keeping this in mind, we have designed a comprehensive guide that will help you get rid of this virus for good. See below for more information.

Instructions:

Click the Start button and search for Run. Type ‘cmd’ in the empty box and press the OK button. The command prompt window will open. Type ‘del/a:rhs [drive letter]: autorun.inf’ (without quotes or brackets and as is) and press Enter. For example, it is drive C: that you want to run this command for. Type ‘del /a:rhs c:autorun.inf’ and press Enter to continue. You need to repeat the command for all partitions on the drive, viz. D: or E: etc. When done, exit Command Prompt and restart your computer.

If this method does not work for you and the virus still exists on your computer, please exercise this method. navigate to C: drive> windows> System32> and Setting. Look for the csrss.exe, arona.exe, logon.bat, and autorun.inf files. Select and delete them all one by one. Go to Windows (the directory) again and then to the media folder, locate and delete the arona.exe file. Search through all drives viz. C:, D:, E: etc. for the autorun.inf file and delete it. When you’re done, close all windows.

Open Registry Editor. Go to To runtype ‘regedit’ in the opened box and punch Get into. If you are prompted for an administrator password, you must enter it to continue with Registry Editor. When you are in the utility, make a backup copy of the registry before proceeding with the registry modification. A registry is the heart of an operating system. Incorrect registry changes can lead to a permanent system crash or other serious problems on your computer. Since modifying the registry is a delicate and cumbersome process, we recommend that you seek the help of a professional virus removal support service.

You can create a system restore point or use the built-in Import and Export feature to back up and restore your registry if necessary. When you’re done, navigate to HKEY_CURRENT_USER > Software > Microsoft > Windows > Current Version > Policies > System > DisableTaskMgr=1. Change the last numeric value to 0 of the thread. navigate to HKEY_CURRENT_USER > Software > Microsoft > Windows > Current Version > Policies > Explorer > NoFolderOptions=1 and do the same.

navigate to HKEY_CURRENT_USER > Software > Microsoft > Internet Explorer > Mail > Windows > Hacked by Godzilla. Delete the last entry in the thread. navigate to HKEY_LOCAL_MACHINE > Software > Microsoft > Windows > Current Version > Run > MS32DLL. Delete the last entry in the thread. navigate to HKEY_LOCAL_MACHINE > Software > Microsoft > Windows > Current Version > RunOnce > Worms = Systemlogon.bat. Similarly, delete the last entry. Exit Registry Editor and restart your computer.

Go to Run again, type ‘msconfig’ and hit Enter. Highlight the Startup tab and remove the check mark from the button next to MS32DLL. Press the OK button and choose to exit the window without rebooting. Go to Recycle Bin and delete all virus files from there. Open your security program viz. antivirus or anti-spyware and update it with the latest virus and malware definitions. When upgrading, run a full scan (recommended) and not a custom one. It will take some time, so wait until it’s done. Ask the program to remove all the infections it found during the scan.

Whether it’s an extraction flash drive or a CD, etc. that has autorun.inf virus, exercise this method. Insert the media into your computer’s port while holding down and continuously pressing the left Shift key. It will prevent the virus from running on its own. Find the location of the removable drive and explore it with WinRAR. There you will see all the hidden virus files including autorun.inf, xcopy, kavo, new folder, ravmon, recycler, ms32dll.dll, ms32dll.vbs and svchost among others. Select each one and press the Delete key.

As soon as you finish deleting all those files, remove the media from the port. Reinsert it into the port and repeat the procedure to ensure that all virus files have been removed from your computer. This method will only work if other drives, viz. C: or D: etc on your computer are virus free except for the external flash drive or CD which has the virus. If you can’t see all the hidden files and folders on the drive, click the Tools tab and go to Folder Options. Highlight the View tab, find Show hidden files and folders, and select it. Press the Apply button and then OK to close the Folder Options window. Thereafter, you should also run a full system scan from your antivirus or antispyware program to ensure that no traces of the virus remain on your computer.

Additional tips:

You will need administrator privileges to perform some of the tasks mentioned above. If you cannot follow these instructions on your computer, restart it in Safe Mode with Networking. Don’t forget to empty the Recycle Bin after deleting all files, as the virus may try to run from there again.

Apart from being cumbersome and time consuming, virus removal is also a risky process as it involves scanning system roots for virus files and removing them. Since it is not possible for you to be well-versed in the nature and mechanism of a virus due to lack of knowledge and time, you may feel stuck at times, especially while working on an important official or unofficial job. Online virus removal support is the best and most reliable way to save yourself from such hassles.

The article is associated with ‘How to remove Autorun.inf virus from a computer’ available at vtechsquad.com.

Leave a Reply

Your email address will not be published. Required fields are marked *