Sunday, April 15, 2007

PFW.exe in flash drive pfw.pif and autorun.inf - virus

PFW.pif was a hidden file I first saw in a pen drive (also variously called flash drive to thumb drive to thumbnail drive)

Anyway the hidden file is labelled as an MSDOS shortcut but it is a trojan or worm or virus or whatever.

How does PFW .pif spread ?
It has an autorun.inf file also in the root folder of the pen drive.

How do you remove it ...

If you have AVG free edition 7.5 installed and have the latest virus definitions, it is more than enough.

I'm not sure about Norton but if it is not updated, I guarantee that it will NOT catch this virus.

Manually remove the virus if you can !
Follow these steps
  1. Press Ctrl-Alt-Del . Task Manager opens. Choose Processes. Select PFW.exe . And click End Task
  2. Right click and Open Pen Drive (Autoplay will run the virus - Don't double click)
  3. Delete Pfw.pif and autorun.inf from the pen drive
  4. In My Computer, click Tools> Folder options> View - Show hidden and system files
  5. Delete C:\windows\system32\pfw.exe (it's a hidden file)
  6. Registry (Type regedit in Start >Run) Go to > HKCU>Sofrware>Microsoft>Windows>Current version>Explorer>Mountpoints2>(crazy names)
    1. Make backup of registry (right click Mount Points 2 and export file)
    2. Delete the names in mountpionts2 which are just a string of letters and numbers (not all of them are harmful, but this is easier) Don't delete C, D,E etc
    3. All finished. pfw.pif / pfw.exe is gone from your computer. Delete the virus from all the pen drives.
    4. Or to be careful , delete only the subkeys Shell which have Autoplay as default value (I'll explain this in detail later)
    5. http://www.johndasfundas.blogspot.com

No comments:

How to get N95 Masks in India - कैसे पाएं मास्क? Yellow, White, Blue or Black ?

कैसे पाएं मास्क? पीला, सफेद, नीला या काला? There are many colors of masks available in India of different colors. What is the difference ? W...