On GameSpot: What are the Best Games of 2009?
BNET Business Network:
BNET
TechRepublic
ZDNet

April 28th, 2009

Windows AutoRun gets a makeover to combat malware

Posted by Ryan Naraine @ 1:12 pm

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Complex Attacks, Data theft, Exploit code, Hackers, Malware, Microsoft, Spam and Phishing, Spyware and Adware, Viruses and Worms, Windows Vista, Zero-day attacks

Tags: Change, Malware, USB Flash Drive, Windows AutoRun, Microsoft Windows, Cyberthreats, Spyware, Adware & Malware, Flash Memory, Viruses And Worms, Operating Systems

In direct response to Conficker and an increased wave of malware attacks targeting the dangerous Windows AutoRun mechanism, Microsoft today announced significant changes to the way the operating system operates when USB drives are used.

[ Roel Schouwenberg: Is there no end to the AutoRun madness? ]

The changes, detailed on Redmond’s Security Research & Defense blog, have been built into Windows 7 will be back-ported to Windows Vista and Windows XP in the near future.

Here’s a breakdown of the changes in Windows 7:

  • AutoPlay will no longer support the AutoRun functionality for non optical removable media. In other words, AutoPlay will still work for CD/DVDs but it will no longer work for USB drives. For example, if an infected USB drive is inserted on a machine then the AutoRun task will not be displayed. This will block the increasing social engineer threat highlighted in the SIR. The dialogs below highlight the difference that users will see after this change. Before the change, the malware is leveraging AutoRun to confuse the user. After the change, AutoRun will no longer work, so the AutoPlay options are safe.
  • A dialog change was done to clarify that the program being executed is running from external media.

There are images on the SR&D blog explaining the changes.

ALSO SEE:

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 33 Talkback(s)
Agreed!
Autorun in any form is just a bad idea. (Read the rest)
Posted by: jbaviera@... Posted on: 05/01/09 You are currently: a Guest | | Terms of Use
Finally!  kd5auq | 04/28/09
This doesn't work like 'leaving the keys in the car'  Lerianis | 04/28/09
Even dumb (almost bankrupt) Detroit makes it a hassle ....  kd5auq | 04/29/09
Personally, I want autorun to work even for USB drives  Lerianis | 04/28/09
AutoRun vs AutoPlay  CobraA1 | 04/28/09
Windows again detects the virus but will not remove it  BALTHOR | 04/28/09
Not the job of an OS.  CobraA1 | 04/28/09
True, removal is the area of an antivirus  Lerianis | 04/29/09
Yeah but if you had...  hasta la Vista, bah-bie | 04/30/09
And if Linux was...  D2 Ultima | 04/30/09
Try having a bash fork bomb script autorun on your system  alaniane@... | 04/30/09
RE: Windows again detects the virus but will not remove it  dsljay | 04/28/09
Antivirus.  magallanes | 04/29/09
Power  pranavb99@... | 04/29/09
politics?  martin@... | 04/29/09
MS's usual wait, and half-do something.  kcredden2 | 04/28/09
Get real  Lerianis | 04/29/09
the HD is still read-write  dgrainge | 04/29/09
Re: Get Real  tmsbrdrs | 04/29/09
RE: Windows AutoRun gets a makeover to combat malware  Steve KTG | 04/28/09
RE: Windows AutoRun gets a makeover to combat malware  kurtkr | 04/29/09
Misquote of MS article  Larry Huisingh | 04/29/09
RE: Windows AutoRun gets a makeover to combat malware  wilwad | 04/29/09
RE: Windows AutoRun gets a makeover to combat malware  Daiv_Skinner | 04/29/09
RE: Windows AutoRun gets a makeover to combat malware  shadow3865 | 04/29/09
what about networked drives?  mikeymike76@... | 04/29/09
there is no autorun on networked drives as such.  dgrainge | 04/29/09
Make it Manual  travellingpolander | 04/29/09
RE: Windows AutoRun gets a makeover to combat malware  RanRicky | 04/29/09
How will this break modified Windows XP/Vista?  grail@... | 04/29/09
true  dgrainge | 04/29/09
Agreed!  jbaviera@... | 05/01/09
RE: Windows AutoRun gets a makeover to combat malware  cybernick2@... | 04/30/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here