Is Your Computer Infected with the Autorun.in Virus? Here’s How to Delete It

Aviva Zacks
Posted: January 13, 2019

Autorun.in is a virus that is usually spread through infected external devices like USB drives. Once an infected USB disk is introduced to your system, the virus can destroy your computer, self-executing files, destroying important documents, and replicating itself so that it is hard to remove.

How To Know If You Have Been Infected

Here’s the crazy thing about Autorun.in: although the virus’s main tactic is to automatically launch programs, you might not even know if it’s on your system. The program can both automatically launch programs and then dictate what actions they will automatically take.

So, a new browser window may automatically open that instantly downloads a piece of malware which automatically installs itself. This could happen in a few seconds and repeat itself until your system is nearly unusable.

If you notice a series of suspicious programs automatically launching or important documents mysteriously vanishing, then you should take immediate action.

Step 1: Follow The Manual Method

You should begin by ensuring that all traces of Autorun.in have been safely deleted from your system. It requires knowing some basic Windows command line prompts.

  • Boot your computer in Safe Mode and select the “open a command prompt” action. The safe mode option should appear towards the bottom or top of your BIOS/UEFI screen, which appears immediately after turning the computer on.
  • Delete all of the following files:
  • %System%\config\csrss.exe
  • %WinDir%\media\arona.exe
  • %System%\logon.bat
  • %System%\config\autorun.inf
  • C:\autorun.inf
  • D:\autorun.inf
  • E:\ autorun.inf
  • F:\autorun.inf
  • inf files in all drives.

Next, open the Windows Registry Editor and delete the following parameters:

  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
  • DisableTaskMgr = 1
  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
  • NoFolderOptions = 1
  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
  • “Worms” = “%System%\logon.bat”
  • To finish, reboot your computer

Step 2: Install An Antivirus Solution and Scan

While the manual method will hopefully be enough to remove the virus, there’s a strong chance that Autorun.in has introduced secondary payloads (viruses or pieces of malware) that the above method will not delete.

Your best course of action is to install a reliable antivirus solution to immediately conduct a full system scan. This will root out any other malware that hackers may have introduced.

Here are the very best tools for the job:

Norton

Norton has a phenomenal award-winning virus scanning engine. Its advanced SONAR real-time protection and automatic scanning of external drives will give Autorun.in zero chance of overtaking a system.

See Norton Deals >>>

BullGuard

The Bullguard Premium Protection platform features a real-time vulnerability scanner and advanced antivirus detection. It can block Autorun.in and secondary payloads it may have downloaded.

See Bullguard Deals >>>

Avira

Avira deserves an honorable mention for its virus detection features—although I think that Norton and Bullguard are slightly better choices. Its award-winning malware protection will detect viruses, trojans, and worms and its smart artificial intelligence (AI) and deep learning backed algorithms will protect against the latest threats.

See Avira Deals >>>

What Can You Do Next?

To avoid a second encounter with the virus, you should:

Disable the Windows Autorun & Autoplay Configuration:

  • Click the ‘Start’ symbol
  • Type Gpedit.msc into the search box and click on ‘ENTER’
  • Under “Computer Configuration,” expand “Administrative Templates,” “Windows Components,” and then choose “Autoplay Policies.”
  • Under the “Details” pane, double click “Turn Off Autoplay.”
  • Restart the system.

Never Insert an Untrusted USB Drive into Your System:

For obvious reasons, inserting unknown USB drives is a very risky business. Having proper antivirus protection should help avoid the chance that an autolauncher will cause an infection, but ideally, you should never introduce unknown external devices to your system in the first place.

About the Author

Aviva Zacks
Aviva Zacks

Aviva Zacks is a content manager, writer, editor, and really good baker. When she's not working, she enjoys reading on her porch swing with a cup of decaf.