Re: What features does Autorun provide?




Hello Robear,

Thank you for the helpful advice. I tried following the instructions in
KB967715 (which Belarc Advisor tells me is installed). The instructions for
my OS (XP-Pro) tell me to use the Group Policy Editor but I am unable to
locate the System (folder?) in Administrative Templates. That folder(?) has
only a Windows Components folder.

I found the NoDriveTypeAutoRun entry in the registry but I wasn't sure what
value to set it to. It is currently set to 91 (Hex) (145 decimal). I still
want to be able to use a flashdrive as well as play CDs and DVDs. I don't
mind (in fact I prefer) clicking on an option to tell it to run but I am not
certain if I will lose that functionality by changing that registry entry.

Thanks again for your help.

Fraser


"PA Bear [MS MVP]" wrote:

AutoRun and AutoPlay, while related, are NOT the same function.

What features (beside automatic execution of autorun.inf) will I give up
when I disable autorun (WinXP)?

For one, you will give up the convenience of a hijackware-infested USB key
(re)infecting your computer as soon as you plug it in (or a
hijackware-infested
attachment or compromised link infecting your computer as soon as you open
it).

Conficker Worm: Help Protect Windows from Conficker:
http://technet.microsoft.com/en-us/security/dd452420.aspx

Steve Riley on Security : Autorun: good for you?:
http://blogs.technet.com/steriley/archive/2007/09/22/autorun-good-for-you.aspx

Steve Riley on Security : More on Autorun:
http://blogs.technet.com/steriley/archive/2007/10/30/more-on-autorun.aspx

Microsoft Malware Protection Center : Windows Addresses the Changing AutoRun
Threat Environment:
http://blogs.technet.com/mmpc/archive/2009/04/28/windows-addresses-the-changing-autorun-threat-environment.aspx

Microsoft Security Advisory (967940): Update for Windows Autorun:
http://www.microsoft.com/technet/security/advisory/967940.mspx

How to disable the Autorun functionality in Windows (2K; XP; 2003):
http://support.microsoft.com/kb/967715
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Client - since 2002


Fraser wrote:
What features (beside automatic execution of autorun.inf) will I give up
when I disable autorun (WinXP)? It seems to be widely recommended that
this
feature be disabled for security purposes. There also seems to be a lot of
conflicting information about exactly what autorun does and why it should
be
disabled.

For instance, some sources say that autorun and autoplay are equivalent
while others say disabling the former will not affect the latter. Only one
of those two statements can be true. I understand (and agree) that
disabling the automatic execution of autorun.inf is desired. What about
the
popup menu that lets me choose to view files with Windows Explorer? Will
that be disabled as well? I do not wish to lose that menu.

Any clarification would be most appreciated.

Cheers,
Fraser


.



Relevant Pages

  • Re: SSL 2.0
    ... this is the classic tradeoff between compatibility and security. ... by default from Windows 2000 Server to Windows 2003 Server. ... may look at the instructions for disabling SSL3 and SSL3.5 and say ...
    (microsoft.public.inetserver.iis.security)
  • Re: Autorunning disks Very Bad Idea.
    ... The typical user does not know how to turn off autorun, ... computer should be designed with at least a sensible attitude to security. ... autorun ON even if the user has turned it off, directly in the registry. ... it is virtually impossible to do anything to Windows which will ensure ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Lock down Win2K Box on a LAN?
    ... Disabling unneeded services is always a good thing. ... Security Analyzer to help determine unneeded services and review information ... in the Windows 2000 Security Hardening Guide for more specifics on services. ...
    (microsoft.public.win2000.security)
  • Re: security
    ... 10 Immutable Laws of Security. ... Uninstall/disable Windows Messenger Windows Messenger in XP ... Click Start, go to Settings, Control Panel, Administrative Tools, and click ... You could consider disabling all Security Settings in IE and use IE only ...
    (microsoft.public.windowsxp.general)
  • Re: SP3 & no internet access
    ... If you don't want to use ZA Security Suite, uninstall it. ... AVG 8 via Add/Remove Programs and make sure the Windows Firewall is ... Error message after you install a Windows Internet Explorer 7 update from ... you may need to uninstall it instead of disabling it. ...
    (microsoft.public.windowsupdate)