Hello!
Let's first know how a virus generally attacks from the pen drive. Whenever we plug an external media onto our PC or laptop it autoplays itself you can see the dialog boxes asking you to chose an option on hw to play the external media. When a device is infected with virus it contains a file with the name autorun.inf which contains some text like
[autorun]
open=some file name
shell/execute...
and so on.
What basicall happens is that when your system autoplays the device it reads this autorun file and commands written under it get executed by the explorer and hence infects your system.
Another method is that when you double click the device icon the virus gets executed, main reason remains same as above.
Now the basic idea is clear on how the system gets infected from external medias.
How to protect ?
First of all disable autoplay on all media for all kind of files. Basically it is nothng but just modifying some registries so that none of your medias get autoplayed (Relax no side-effects to your normal working). You can do so by using softwares like Tune up utilities or will get the registry file for same on this site after some time (I apologise for the same right now).
After you have done the same, None of your external drives will now autorun. Next is that do not open the drive by double clicking it, rather follow a different procedure. Open Windows Explorer (win + E) and chose the drive icon from left pane by a single click. Make the settings to show all hidden system files, so that you are able to view hidden scripts and executables. Also arrange the icons by type and view them in groups so that you can view any discrepancies (like executable virus file with icon that of a folder, spreading now a days like mustard seeds! Sorry inappropriate sentence!!). Now delete any unwanted and unsure files from there by carefully single clicking them and follow the same in other inner folders or you can automate them using search options and searchong for *.bat, *.exe, *.com and deleting any suspicious files.
In Nutshell
Disable autplay on all kinds of external media (one time change)
Open the Explorer (Win+E)
Tools->Folder Options->View->Show hidden files and shoe system protected files
Arrange icons by type and show them in groups
Delete suspicious files from there and from any subdirectory
Open folders by single clicking folder from left pane only.
Good use of above thing!!
Create a file named autorun.inf in root directory of any drive i.e. its location should be X:\autorun.inf with following text
[autorun]
open="address of any file, which is in same drive address without the drive letter"
icon="same address"
for example dcb\abc.ico if absolute address is X:\dcb\abc.ico
now save the file and right click and select install from the context menu of the file.
Remove your media and reinsert it (restart if doing in hard disc). See the drive icon
Make any person think different of yours.
Post your doubts and comments regarding the same. I would be happy to clear your doubts.
Ring me at +91-9899024447 or mail me at mailto:atdurgeshindia@gmail.com
Corprova | Saroj Hydraulics | AlphaNumeric | durgeshindia
0 responses:
Post a Comment