Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editorials

November 28th, 2007, 09:05 GMT · By

Worm Infections Via Windows AutoRun

SHARE:

Adjust text size:

USB Plug
Enlarge picture
As useful as it may seem, AutoRun can get you in a lot of trouble. It is helpful when a new disc is inserted or you plug in a flash drive, automatically launching installers, but this can pose a serious risk for your computer's security. If you do not know in advance what data is stored on a disc or on a USB key, chances are your computer may get infected.

Here's how it all works. In both Vista and XP AutoPlay it is enabled by default. The moment you insert a disc, AutoPlay will automatically prompt you for an action. But, if it has an autorun.inf file at the root, Windows will execute all the commands included in that file. This file generally contains instructions for launching an installer, splash screen or another file of some sort.

The same happens with USB flashdrives. The moment they are plugged into a computer, AutoPlay will kick in, displaying the options for the device and Windows will look at the root for an autorun.inf and will automatically execute the commands
included. AutoPlay can be disabled with not too much fuss in Vista. Going into the "Properties" window of the drive and choosing "AutoPlay", you can customize the actions to be taken when a disc is inserted. Taking no action will still run the contents of the autorun.inf file, and turning it off will not prevent Windows from executing the commands included in the AutRun.inf file located at the root. It will only stop displaying the automatic menus, but the commands in AutoRun.inf will still be obeyed.

The trouble is that the little file containing a set of commands can be the trampoline for any kind of malware stored somewhere on the USB key. The worst part is that the nasties can be launched without your knowledge and multiply to any other drive available on your computer.

Luckily, there is one solution for disabling the running of an autorun.inf file without too much effort. The downside is that, when inserting game discs, the installation screen will no longer appear automatically and you will have to give it a manual jump start. But hey, at least no malware will make its way inconspicuously to your computer (AutoRun files can also be executed when accessing removable media).

Here's what you have to do: paste the following in Notepad and save it under any name you want, but with .REG extension. Once this is done, all you have to do is add it to the registry by double-clicking on it.

REGEDIT4
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrentVersionIniFileMappingAutorun.inf]
@="@SYS:DoesNotExist"


It involves adding a new key to the registry, telling the operating system how to handle autorun.inf files. The principle is simple: the OS is told not to use the values inside the file, but instead to go to an inexistent location in the registry, in order to find the values that will be used. As the value is inexistent, the system will treat autorun.inf as if it would be completely empty, so nothing will be executed behind your back.

As I said before, all software on an inserted disc will have to be launched manually. That's an inconvenience I would gladly take, in order to keep my computer as malware-free as possible. However, if you want to reverse the operation and enable AutoRun again, all there is to do is deleting the key from the registry. Everything will get back to normal and AutoRun will be executed each time.

I know the solution is not quite a comfortable one, as deleting the entry in the registry requires a system reboot, but system administrators will be able to reduce worm infection risk. Plus, a manual launch of an executable never hurt anyone; it eliminates the automation of the process, but you will see in time that it is not that bad.


14,351 hits · 3 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:

READER COMMENTS:


Comment #1 by: Chetan Umarje on 30 Jan 2008, 16:10 UTC reply to this comment

You can selectively stop USB sticks and memory cards doing the 'Autorun' (and retain the CD-ROM autorun)

A novice editing the registry can easily make mistakes and cause more damage. Here is a decent way to do the same thing for Windows XP.

Go to http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx
Keep looking at the right side pane and scroll down till you notice the TweakUI.exe file
Download and install it. (Restart not needed)
Launch it. (Start >> All Programs >> Powertoys for Windows XP >> TweakUI)
On the Left side, expand the My Computer Node >> Expand the AutoPlay node >> and choose the Types node
On the right side >> deselect the box for Enable Autoplay for removable drives
You may also deselect the box for Enable Autoplay for CD and DVD drives for added protection.
Apply >> OK and exit.

Prevention is better than cure


Comment #2 by: Budi on 29 Mar 2008, 11:32 UTC reply to this comment

The (even) easier one is by typing "gpedit.msc" at the run command.
Then go to(double click) Computer Configuration->Administrative Templates->System->Turn Off Autoplay
Select "Enable" and choose on the menu pulldown for "All drives".
Press "Apply" then "ok". Close Gpedit and you're done disabling all kind of autorun.inf on all drives (including UFD, FDD, ODD, HDD, etc.).

{unless of course you run it explicitly}


Comment #3 by: Utkarhsa on 30 Jan 2010, 08:24 UTC reply to this comment

I have been Getting a problem That my autorun is disabled nor i can enable it.My kasprsky works fine and it is not showing any problem.I can't get autorun tab.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM