cleaning Win32/AutoRun.Agent.BE
So yeah, I got my first worm in quite a while, the awesome and overall cute Win32/AutoRun.Agent.BE. But I also got a piece of wisdom from cleaning it – make sure you never download any software from sources you aren’t 100% sure of. That includes torrent trackers, dc++, any other p2p interface, random [free] download websites and so on.
As I said, my PC, the mighty Shoarec, has caught a nasty case of Win32/AutoRun.Agent.BE and I had a bit of trouble cleaning it. Google adviced me to different methods to get rid of it but none actually worked so now I will post here the best way to get rid of it without much headache. For me it went pretty much like this: nod32 detected the worm as soon as it was in my system but didn’t manage to actually get me rid of it.
This is how I cleaned it, step by step:
#1: Downloaded and installed the Malwarebytes’ Anti-Malware software. It’s free for scanning and cleaning, you can get it from here. It’ll detect the worm and delete some of its parts.
#2: If you check in [My Computer] at this point you will still notice that the drive’s default action is Autoplay instead of Open. You shouldn’t double click the drive or use the autoplay option at any time! That’s definitely not good. Now you need to get those pesky “autorun.inf” files out in the open, to do that you will type in Run “attrib c:\autorun.inf -r -h -s”, it’will remove the attributes for the autorun.inf file found in the root C:\ drive. Replace C: with D:, E: etc. to remove the attributes for the file on all of your drives..
#3: Delete C:\autorun.inf, D:\autorun.inf and so on.
#4: Reboot.
#5: Run MBAM again to make sure the worm is gone.
There you go, now the worm is gone and your drives should again behave properly.
PS: Have a happy New Year. I will.
Thanks,
The management.