first things first, lets get our tools ready. This is
Autorun Virus Removal 101. I'll try to make this as simple as i can so you'll be able to remove at least most of the autorun viruses out there.
-make sure you have the latest updates for your antivirus.
-download:
Killbox Utility
- make sure your Explorer is set to view all hidden files. (Open My Computer > Folder Options> View> remove the check in the two "Hide" entries and also click on "Show hidden files and folders". (Read my previous post)
- turn off Xp autoplay feature (if you haven't done it yet, read my post above)and reboot <
to hopefully disable the autorun file from launching more copies
ok, now your pretty much ready to kick this thing in the balls...
-In IE Tools> Internet Options> delete all cookies, urls, and temporary internet files. (some viruses launches from the internet using your browser start page. set your start page to "about:blank".
-Right click Start > Explore
Navigate to your C drive. you should find a file named
autorun.inf, rename it to
autorun.txt. some viruses hide their autorun lanchers in Windows>System32, look for
autorun.ini.
-Open the *.txt file
-Note the files used to launch or run the virus (like xmss.exe, document.exe, *.vbs, *.bat, *.ico, etc).
these are usually hidden files.
-Using the search feature, find these files and delete them.
Remember to include "hidden files", otherwise search may not find them. DO NOT DELETE normal windows files! list them from another good pc so you'll be familiar with them.
-If Windows says "file is in use", note or copy the location of the file and paste it on Killbox. Click on the Red button with an X on it to kill and delete the file.
-Move on to the next file in your autorun list and do the same steps till you got them all. do another search sweep to make sure none of them came back.
-do a full system scan with your antivirus. delete any files in its quarantine folder.
-open regedit (Start> Run> type Regedit> press enter) and delete any entries regarding the files in your autorun list. Start the search from "My Computer" in the left hand panel. Make sure it is a rougue entry!!! baka ibang entry ma-delete mo. double check before pressing delete and yes. ^^
-reboot pc.
-check your other drives and partitions for any of the same hidden files and delete them (they should go away without any fuss now).
done! hopefully...