How to remove autorun.inf and boot.com virus on your PC

This tutorial describes the procedure to remove autorun.inf and boot.com virus. This virus is commonly called as resycled/boot.com virus, which could damage the system files and may steal important information from the system. This can be removed by any malware / spyware remover like Malewarebytes.


To remove it using Malewarebytes :

  1. Reboot the system.
  2. On startup, press F8 before windows starts loading.
  3. From the menu, choose the option to boot the system in Safe Mode.
  4. Once the system boots up, run Malwarebytes and perform a scan.






To remove this virus manually: 

  1. Open the Task manager by Shift + Ctrl + Esc keys
  2. Select the "Processes" tab. In the list of processes, select "explorer.exe" and press the button "End Process" to kill the process.
  3. Right click "My computer", select "Properties". In the "System Properties" window, select "System Restore" tab.
  4. Select "Turn off System Restore on all drives" and Press "OK".
  5. Open command prompt by pressing Windows + r keys, type "cmd", press "OK".
  6. Type the following commands one by one and press "Enter".c:cd\attrib -s -h -r autorun.infdel autorun.inf.* /s /q /fcd resycledattrib -s -h -r boot.comdel boot.com /s /q /fcd \rmdir c:\resycled /s /qexit7. Press Windows + e keys to open the explorer.
  7. Open the folder "C:\windows\prefetch " and delete all the files in this folder. Close the explorer window.
  8. Go to "System Properties" window and deselect "Turn off System Restore on all drives" to enable system restore.
  9. Open Registry Editor, by pressing Windows + r keys, type "regedit", press "OK".
  10. Search for the string "resycled\boot.com" by pressing Ctrl+F.
  11. If you find any occurance of this string, delete the occurances.
  12. Close the Registry Editor and reboot the system. The virus is cleared now.




Share/Bookmark

.......................................Fileshare.......................................

Related Posts



No comments: