i thought only that when i created a directory autorun.inf the resun i cant find the autorun.inf but wen i delete the directory still the ca alerted me of that virus… Repeat this procedure to other hard drives and USB drives. Should I perform the 1st method as well? http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html Click on where it says "download now", no where else or you will download the wrong program. have a peek here

i've removed the autorun.inf and have made AUTORUN.INF dir in all my drives. i dont know the virus but b4 starting up my computer theres an message box and it's a different language so i dont really know d virus. At the time of deletion of the autorun.inf virus, I immediately hit the enter button to execute the command on the command prompt. just removed AVg as this ouucpy too much storage space on my pc. . .

can anyone tell me how to do it?? Reply josaragoca January 21, 2009 hello, yesterday i have a problem in my home computer. it's shutting the computer automaticaly. Let me know if there are still some issues.

It will produce a log file, attach it to your email & send it to me at admin @ bleuken . If you accept cookies from this site, you will only be shown this dialog once!You can press escape or click on the X to close this box. Just to give you a headstart: go ahead and get the latest version of malwarebyte and do a quick scan. Download the HijackThis installer from here.

My advice is that when the virus is already removed manually, try reinstalling or installing an antivirus and update your virus definition file and scan your system to ensure a virus-free Reply nicholas_b105 October 14, 2008 sir is there anyway to find out if the autorun.inf was actually removed from the drives? Reply vishnu yeroor February 16, 2009 iam running avg but not removed new trojan and auto run Reply bleuken February 15, 2009 thanks tigerman, just corrected the DISABLE-AUTORUN.REG 404 problem. THANKS KAMY Reply bleuken August 17, 2008 try removing runexe.bat from your system (del c:\windows\system32\runexe.bat).

Please keep updating until it says you have the latest version. I am having trouble with my pc. I'm all clean now, thankyouverymuch! Reply bleuken January 21, 2009 @josaragoca, try other free antivirus like avira or avast then let me know if the infection was eliminated.

I had a problem of that on my mobile phone and my usb drive. It will ask you if you're sure before it starts. This commands will be used for analysis of the infection only: CD \ - This change the current folder to the main directory of drive C DIR /AH - Displays all Reply bleuken August 21, 2008 @KAMY download Hijackthis then run it (use Google to find it).

I'm just in panic mode right here. http://softsystechnologies.com/hijackthis-log/hijackthis-log-from-rdp.html That seems to be the most common way this worm spreds.*** polonus: Hi CharleyO & webkohli,Here is how to kill it: 1. i cant open it cuz its hidden.. infected po yung pc ko ng INF/autorun.gen trojan,..

and edits the registry. I thought that there might be some hidden "thing" running in the memory that was recreating the file and folder. try to install it (uninstall AVG first). http://softsystechnologies.com/hijackthis-log/hijackthis-log-worm-win32-netsky-fake-spyware-alert-i-think.html How can I perform the 2nd method with the external hardisk?

The installer will place a shortcut on your desktop and launch HijackThis. It is a good tool also for recovering deleted files or formatted disk. My hardisk is partitioned into drive c and d.

Post the logfile that HijackThis produces along with the Malwarebytes Anti-Malware log johnb35, Jan 11, 2011 #2 Thanatos Active Member Messages: 2,031 well the virus isnt on my computer NOW,

P.S. With regards to the creation of autorun.inf folder, i found it effective and tried it for several times. Thank you very much for your response and for the article. Reply Laur March 18, 2009 I don't know if anyone said this already but TotalCommander can see the autorun.inf, system and hidden files.

tnx… Reply bleuken November 6, 2008 @harbans, yes but the problem is some anti-virus programs block this kind of script because most of the scripts made for this purpose are considered I gather theres a virus in there of some sort but its also got my downloads, which i cant get to. If an update is found, it will download and install the latest version. this contact form pag inerase ko po ba yan, maccra yung pc ko??

Reply bleuken May 12, 2009 koolkat, Disable-autorun.reg is not a virus. .REG is not an executable file but a registry file (windows xp) that can be embedded to the registry. Invision Power Board © 2001-2017 Invision Power Services, Inc. Reply kemboi October 18, 2008 Hi. Reply Leon March 25, 2009 i had infected autorun.inf inside my hard disk, i tried many ways online including attrib -s -h -r autorun.inf, del autorun.inf, find out the file to

This stops the bug from functioning. Reply bleuken November 7, 2008 @dyrone, viruses that uses autorun.inf evolve overtime and buis.exe is another strain. Use it to analyze the system and produce a file called HIJACKTHIS.LOG. Open Notepad, and save as all files.

Reply bleuken February 17, 2009 to be sure, i recommend that you should. my computer is opening programs by itself. That may cause it to stall** webkohli: Hello everybody,Thanks for your cooperation. I suggest that you remove the virus first.

I'm new here and i was really amaze reading this "autorun.inf" article. Mabuhay ka kapwa ko Pinoy! Reply bleuken December 26, 2008 Glad to hear that! 🙂 Reply VeryDesperate December 25, 2008 My autorun.inf has an m.exe… please tell me how to delete it.. And maybe make that file autorun by editing autoexec.bat?

Did you receive my email? Hope this helps. Share this post Link to post Share on other sites miekiemoes    Forum Deity Moderators 8,338 posts Location: Belgium ID: 3   Posted March 30, 2009 Hi,It's a bad idea to Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exeO4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe"

try to read this post, I have listed several tools here that you can use: http://www.bleuken.com/2008/11/20/free-tools-virus-worm-malware/ Reply ravishankar January 26, 2009 Yes, I have tried to remove it from safe mode Reply gL3nnX September 9, 2008 astig ah! Jump to content Resolved Malware Removal Logs Existing user? If you do, just ZIP it.