Creating NoDriveTypeAutoRun value.

Disable USB Drive Autorun

Windows provided Autorun features for quick software response to inserted media or connected drives. The moment USB is inserted; Autorun begins reading from it whether it contains music, video or executable file. Autorun commands are typically kept on a file called autorun.inf. These commands provide an automatic start for applications and media files. Most software manufacturers are utilizing this function to start the installation of their program right after the media is inserted. Since it is a general functionality, there is a risk that the feature is utilized in a malicious approach.

AutoPlay Function

AutoPlay Function in Windows 7

In this age of Internet and USB devices, Autorun is being misuse by computer thefts and hackers. A Trojan called Downloader.Agent effectively exploited this function to harm countless computers globally. That is one reason why most users wanted this feature disabled. Another basis why people wish to halt this action is for security reason, possibly to avoid execution of codes without their consent.

Below is a guide to help you disable Autorun function for USB and other devices. Please note that removing Autorun.inf from any device can resolve certain issues.

Disable Autorun in Windows XP, Windows Vista and Windows 7 without Group Policy

Group Policy is probably the simplest way to disable the Autorun feature. However, Group Policy is not available in some versions of Windows particularly on Home Edition. This is the reason why disabling Autorun using the registry is on top of the list. You must have an administrative privilege to execute this.

1. Click on Start > Run. Alternatively, you can use [Windows Key]+[R] on your keyboard.

2. Type regedit in the box. Click OK or press Enter on keyboard.

3. When User Account Control prompts if you want the allow the program to make changes on computer, click Yes.

4. Locate the registry entry:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion
\policies\Explorer\NoDriveTypeAutorun

5. Double-click on NoDriveTypeAutoRun.

6. In the Value data box, type 0×4 to disable Autorun on removable drives including USB. Refer to the list below to disable specific drives.

 

If the value “NoDriveTypeAutoRun” is not present:

There is a chance that the value NoDriveTypeAutoRun do not exists. Follow these steps to add the value in the registry.

1. Navigate to the following entry:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\

2. On right pane, right-click then New > DWORD (32-bit) Value. Name the value NoDriveTypeAutoRun.

No Autorun

Creating NoDriveTypeAutoRun value.

3. After creating the value. Double-click on it. In the Value data box, type 0×4 to disable Autorun on removable drives including USB. Refer to the list below to disable specific drives.

4. Exit registry editor and restart the computer.

List of Settings for NoDriveTypeAutoRun
0×1 or 0×80 – Disables AutoRun on drives of unknown type 
0×4 – Disables AutoRun on removable drives 
0×8 – Disables AutoRun on fixed drives 
0×10 – Disables AutoRun on network drives 
0×20 – Disables AutoRun on CD-ROM drives 
0×40 – Disables AutoRun on RAM disks 
0xFF – Disables AutoRun on all kinds of drives 

 

How to Disable Autorun with Group Policy:

Please take note that Group Policy is not available on some versions of Windows. To access this feature, you must login with Administrative account.

1. Click on Start > Run. Alternatively, you can use [Windows Key]+[R] on your keyboard.

2. Type Gpedit.msc in the box. Click OK or press Enter on keyboard.

3. It will prompt for Administrator password. Please continue by providing the password and click on Continue.

4. Local Group Policy Editor will open.

5. Go to Computer Configuration, click on Administrative Templates, click on Windows Components and then click on Autoplay Policies.

6. Click Enabled.

7. Select specific drive on Turn off Autoplay to disable Autorun on that drive.

Autorun Group Policy

Two methods to disable Autorun

8. Another method is to set Default behavior for Autorun. Click Enabled and select Do not execute any autorun command. This will generally disable Autorun command on all drives.

8. Restart the computer.

Remove W32.USB Worm (Heap41a)

Remove W32.USB Worm (Heap41a)

W32.USB Worm or Heap41a attempts to periodically copy itself to removable drives and USB keys. The worm also tries to create a hidden file Autorun.inf on removable drive. Additionally, W32.USB will drop its own malicious file called MicrosoftPowerPoint.exe to any detected removable drive. It will monitor Internet browser activities and display the following messages: More

SUPERAntiSpyware

SUPERAntiSpyware

SUPERAntiSpyware free edition is security software that detects not just spyware. This program is also capable of eliminating adware, malware, virus and Trojan. SUPERAntiSpyware features exceptional techniques to delete threats that other software fails to remove. SUPERAntiSpyware will remove ALL the Spyware, NOT just the easy ones!  More

Managing Add-ons in Internet Explorer

Unable to Find mswbar.dll – MyWebSearch

My Web Search or sometimes called as MyWebSearch Tool Bar is an adware program that that brings excessive advertisements on the compromised computer. MyWebSearch also monitors victims Internet browsing habits and serve pop-up advertisements based on the gathered data. It also hijacks Internet search and point users to unknown web sites. MyWebSearch also modified Internet Explorer settings and modifies the default homepage. A Toolbar is integrated to the same web browser even without proper authorization from user.  

mywebsearch

Most people who got contaminated with this adware thought that they have successfully removed it through simple add/remove program of Windows. This method is insufficient to totally take out all files and system components created by MyWebSearch. For this reason, incomplete removal will cause an error “Unable to Find mswbar.dll.”

Mswbar.dll is a major component of MyWebSearch. Some security programs will automatically quarantine or remove this file from the system leaving other components behind. Thus, it give an error messages every time you start your computer: More

Clean Windows Hosts File

Clean Windows Hosts File

All Windows installation consists of a single file to manually map IP addresses to host names. This Windows Hosts file is loaded each time Windows start. By default, Windows hosts file contains only one mapping and that is the localhost. Any address mapped to 127.0.0.1 will redirect connection back to your local machine. This is useful for blocking unwanted services from reaching the Internet. Editing the HOSTS file will provide positive results for user, but it is relatively damaging when Trojan alters it for malicious purpose. More

Online Virus Scanner

Online Virus Scanner

Free Online Virus Scanner is an effective solution to scan and remove common virus and malware threats from your computer without the need to install separate antivirus software. All it requires are launcher, Java or Active-x components. Using free online virus scanner might not help protect your system from viruses, but at least you can remove existing infection. You can also analyze which of the below scanner has the higher detection ratio. As the saying goes, not all antivirus are created equal. More

Scan Effectively with Anti-Virus

Scan Effectively with Anti-Virus

Computer virus can slip into your computer in various methods. Typically, the distribution process utilizes Internet services like malicious web sites, spam emails and instant messaging application. Local propagation of the infection is another issue. Once it gets inside the computer, it has a tendency to spread through local area network and USB removal drives or most commonly known as autorun worm. More

Portbale virus scanner by SuperAntispyware

Standard Virus and Malware Removal Procedure

Launching your antivirus application and scanning the computer in normal way is sometimes insufficient to do the job. It is very important you are knowledgeable to have skills in running virus scan with different methods. More

W32.Sohanad sends messages containing links.

W32.Sohanad.Vbs – thecoolpics.net and thecoolpics.com Removal Tool

W32.Sohanad is a worm that specifically spreads on instant messaging application. W32.Sohanad will detect running process that belongs to instant messenger. If it sense that the program is running, it instantly send a message to remote users included in the contact list of victim. The message will contain malicious URL that redirect browser to a contaminated web site. This method will extend the infection to people who visited the web site. More