cancel
Showing results for 
Search instead for 
Did you mean: 
Reply
nightoil
Paper Tape
Posts: 10
Location: London UK
4,973 Views
Message 1 of 8

AUTORUN.INF repeatedly trying to run for no apparent reason

I got this Thinkpad X201s direct from Lenovo last November.

Since then, my Avira antivirus software has been blocking Q:\AUTORUN.INF several times a day.

Why would Q:\AUTORUN.INF be trying to run from the recovery partition during normal use of the computer?

Is it likely to have been hijacked by malware?

Curiously, Q:\AUTORUN.INF seems to go mad whenever any potential threat to it is running,

i.e. when Windows Defender is running or paticularly when AUTORUN.INF removal software is downloaded.

If I click on it in Windows Explorer, Avira blocks it but it does open as a Notepad document with an "Access is denied" warning and an empty Notepad window behind it.

Repeated Avira system scans and Windows Defender scans find nothing abnormal.

Can anyone help?

Retired Moderator
Retired Moderator
Posts: 2,933
Location: US
4,964 Views
Message 2 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Is Avira only blocking the file or is also giving you an option to remove it? It might be a false alarm.Try using Malwarebytes or Microsoft security essentials ..
nightoil
Paper Tape
Posts: 10
Location: London UK
4,960 Views
Message 3 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Dear Vijay

Thanks for your prompt reply.

No, Avira is only blocking it, not offering to remove it.

By false alarm, do you mean that Avira only thinks Q:\AUTORUN.INF is trying to run but isn't

or that it is trying to run and that Avira is blocking it by mistake.

Question remains for me why Q:\AUTORUN.INF should be trying to run at all during normal use.

Can you say whether the Q recovery partition does normally contain an AUTORUN.INF? If not, could I not simply delete Q:\AUTORUN.INF myself.

Meanwhile, I will try Malwarebytes and/or Microsoft security essentials, as you suggest.

Thanks again

nightoil

Retired Guru
Posts: 2,090
Location: USA
4,953 Views
Message 4 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Can you access the Q partition?
Open autorun in notepad if you can and post contents.
(Might be something to do with recovery backups?)
nightoil
Paper Tape
Posts: 10
Location: London UK
4,945 Views
Message 5 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Yes, folders/files in Q partition are "hidden" but can be seen by checking "Show hidden files" in Folder Options.

Opening Q:\AUTORUN.INF in Notepad causes Avira to block it

but Notepad does open with an "Access is denied" warning and with the Notepad window empty behind it.

Yes, seems to be to do with recovering the OS in the event of total failure.

But why does Q:\AUTORUN.INF run at all during normal use?

Have downloaded Malwarebytes.

Quick scan of full system and a full scan of the Q partition both yield nothing.

Retired Guru
Posts: 2,090
Location: USA
4,896 Views
Message 6 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Still there?
Try to temporarily disable Avira and see if you can view file.

Personally recommend Avast for free AV myself...
Community Moderator Community Moderator
Community Moderator
Posts: 2,913
Location: US
4,888 Views
Message 7 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Hello,

 

Perhaps it is a false positive alarm.  Have you tried uploading the AUTORUN.INF file to a site which runs files against multiple anti-malware scanning engines like VirusTotal to see what is reported back?  That should help give you an idea of whether the file is infected. You can also submit it your anti-virus vendor's researchers for examination. 

 

Regards,

 

Aryeh Goretsky

 



I am a volunteer and neither a Lenovo nor a Microsoft employee.

L380 YogaP50 (20EN-*)S230u (3347-4HU)T23 (2648-LU7)T42 (2378-R4U)T43p (2678-H7U)T61p (6459-CTO)W510 (4318-CTO)W530 (2441-4R3)W530 (2441-4R3)X100e (3508-CTO)X120e (0596-CTO)X220 (4286-CTO)X250 (20CM-*)Yoga 370

de.gif Deutsche Community es.gif Comunidad en Español ru.gif Русскоязычное Сообщество pt.gif Communidade Portugues
nightoil
Paper Tape
Posts: 10
Location: London UK
4,871 Views
Message 8 of 8

Re: AUTORUN.INF repeatedly trying to run for no apparent reason

Dear Guru

Thanks for your interest!

I turned off Avira, as you suggested, and clicked on Q:\AUTORUN.INF, which then opened in notepad thus:

[AutoRun]

open=LenovoQDrive.exe

icon=qdrive.ico

i.e. it looks totally innocuous and as it should do.

I've also repeatedly run full system scans by Avira, Windows Defender, Microsoft Security Essentials and Malwarebytes, all of which report clean.

So it would seem that Avira has just been being hyper-cautious, which is fine by me.

I think I'll probably now just make a set of recovery discs, delete Partition Q and free up the space for my own use and leave it at that, unless anyone else thinks otherwise.

Anyway, thanks very much for your (and Aryeh Goretsky's and Vijay Saradhi's) help.

Regards

nightoil

Top Kudoed Authors