How to Completely Block and Disable Autorun.inf Files in Windows 7, Vista, and XP
Information
When a CD/DVD disc is inserted or a USB drive is connected to your system, Windows looks in the root directory of the new disc or drive for a file named autorun.inf. If found, Windows executes the instructions (keys) in that file.
AutoPlay will no longer support the AutoRun functionality for non-optical removable media. In other words, AutoPlay will still work for CD/DVDs but it will no longer work for USB drives. For example, if an infected USB drive is inserted on a machine then the AutoRun task will not be displayed. This will block the increasing social engineer threat highlighted in the SIR. The dialogs below highlight the difference that users will see after this change. Before the change, the malware is leveraging AutoRun (box in red) to confuse the user. After the change, AutoRun will no longer work, so the AutoPlay options are safe.
A dialog change was done to clarify that the program being executed is running from external media.
By default in Windows 7, Vista, and XP now, the only [Autorun] keys available for USB/removable drives are below. The rest of the keys are ignored.
label - This key is responsible for displaying a custom name (label) for a CD/DVD or USB drive in Computer when a CD/DVD is inserted or a USB drive is connected.
icon - This key is responsible for displaying a custom icon for a CD/DVD or USB drive in Computer when a CD/DVD is inserted or a USB drive is connected.
This tutorial will allow you to completely block and disable all keys in autorun.inf files from being able to execute from any location and on any drive. This will affect all users on your Windows 7, Vista, or XP computer.
You must be logged in as an administrator to be able to apply this tutorial.
Note
If autorun.inf files are set to be blocked below, then the installation startup process of software from any autorunning installation CD/DVD will no longer be automatic. It will be necessary to view the CD/DVD's autorun.inf file, and then execute the appropriate EXE install file manually.
EXAMPLE: Autorun.inf Files Unblocked and Blocked NOTE:This example is with the icon key.
Here's How:
1. To Completely Block and Disable Autorun.inf Files
A) Click on the Download button below to download the file below.
Block_Autorun.inf_Files.reg
B) Go to step 3.
2. To Unblock Autorun.inf Files Back to Default NOTE:This is the default setting to allow the icon and label keys to work again for autorun.inf files.
A) Click on the Download button below to download the file below.
Unblock_Autorun.inf_Files.reg
3.Save the .reg file to the desktop.
4. Right click on the downloaded .reg file, and click on Merge.
5. Click on Run, Yes (UAC-Windows 7) or Continue (UAC-Vista), Yes, and OK when prompted.
6.Restart the computer to fully apply.
7. When done, you can delete the downloaded .reg file if you like.
Some malware that infect USB flashdrives include an Autorun.inf file that makes the flashdrive's icon go wrong as well as help run or initialize the malware to do its thing. Will blocking Autorun.inf files prevent this from happening as well??
System Manufacturer/Model Number Custom Built OS Windows 7 Ultimate 32 Bit, Windows Developer Preview, Linux Mint 9 Gnome 32 Bit CPU Intel Pentium Dual CPU E2180@2GHz Motherboard Elitegroup 671T-M3 Graphics Card NVIDIA GeForce 7200 GS Monitor(s) Displays AOC TFT1560 15" LCD Monitor Screen Resolution 1024x768
"It is important to note that this applies to any autorun.inf in any location and on any drive."
"This workaround have the drawback is that installation of software from an autorunning install CD or DVD is no longer automatic. It will be necessary to view the CD's autorun.inf file and then execute the appropriate install program manually."