This tutorial describes the procedure to remove autorun.inf and boot.com virus. This virus is commonly called as resycled/boot.com virus, which could damage the system files and may steal important information from the system. This can be removed by any malware / spyware remover like Malewarebytes.
To remove it using Malewarebytes :
To remove this virus manually:
To remove it using Malewarebytes :
- Reboot the system.
- On startup, press F8 before windows starts loading.
- From the menu, choose the option to boot the system in Safe Mode.
- Once the system boots up, run Malwarebytes and perform a scan.
To remove this virus manually:
- Open the Task manager by Shift + Ctrl + Esc keys
- Select the "Processes" tab. In the list of processes, select "explorer.exe" and press the button "End Process" to kill the process.
- Right click "My computer", select "Properties". In the "System Properties" window, select "System Restore" tab.
- Select "Turn off System Restore on all drives" and Press "OK".
- Open command prompt by pressing Windows + r keys, type "cmd", press "OK".
- Type the following commands one by one and press "Enter".c:cd\attrib -s -h -r autorun.infdel autorun.inf.* /s /q /fcd resycledattrib -s -h -r boot.comdel boot.com /s /q /fcd \rmdir c:\resycled /s /qexit7. Press Windows + e keys to open the explorer.
- Open the folder "C:\windows\prefetch " and delete all the files in this folder. Close the explorer window.
- Go to "System Properties" window and deselect "Turn off System Restore on all drives" to enable system restore.
- Open Registry Editor, by pressing Windows + r keys, type "regedit", press "OK".
- Search for the string "resycled\boot.com" by pressing Ctrl+F.
- If you find any occurance of this string, delete the occurances.
- Close the Registry Editor and reboot the system. The virus is cleared now.
No comments:
Post a Comment