View Single Post
Staro 24.09.2007., 22:32   #9
borgy
kenova
 
borgy's Avatar
 
Datum registracije: Sep 2003
Lokacija: München / Dubrovnik
Postovi: 919
Look under HKEY_CURRENT_USER\Microsoft\Windows\CurrentVersion\Policies\Explorer for a REG_BINARY value named NoDriveTypeAutoRun. It should be set to 5F 00 00 00. If not, my guess is that the worm has enabled AutoRun for your hard drives, which is normally disabled. Editing the value to contain 5F 00 00 00 may solve the problem.

You may also wish to examine the root directory of each of your hard drives for a file named AUTORUN.INF, which may be hidden. If such a file exists, delete it.

The above actions should stop your system from treating your hard drive as if it were a CDROM or other removable media when you double-click its icon.

You should also either look for a removal tool for this worm, or check out this page at Trend Micro's website, which has instructions for removing most (if not all) of its crap man
borgy je offline   Reply With Quote