AutoRun neutered in Windows 7
By Stuart Turton
Posted on 30 Apr 2009 at 11:52
Microsoft is taking the hatchet to aspects of AutoRun in Windows 7, as it reacts to new attacks by hackers.
Autoplay is the dialog box that pops up when you connect removable media, such as flash drives to your computer. Autorun options are those which appear in the dialog box allowing you to install a program or browse files.
Autorun is typically used to start an installation program running when you first insert a CD or DVD.
However, in recent times it has become the plaything of hackers, most prominently in the spread of the Conficker worm. Conficker spread through USB drives by creating an extra AutoRun option that when clicked would automatically install the malware.
During the latter half of 2008, Microsoft claims that AutoRun abusing malware accounted for 18% of infections, the biggest single malware category.
To stop this behaviour, Microsoft will modify Autoplay in the first Release Candidate of Windows 7 so that AutoRun options don't appear when most removable media is connected.
"Windows will no longer display the AutoRun task in the AutoPlay dialog for devices that are not removable optical media (CD/DVD) because there is no way to identify the origin of these entries," says Arik Cohen, a program manager on the Windows 7 team, on the Engineering Windows 7 blog.
"With these changes, if you insert a USB flash drive that has photos and has been infected by malware, you can be confident that the tasks displayed are all from software already on your computer."
Microsoft says it will also roll out the modifications across XP and Vista in due course, though no timeframe has been given.
From around the web
advertisement
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Why virtualisation hasn't slowed the growth of data
- How to make Google AdWords work for your business
- The curse of sloppily written software
- Paying for your crimes with Bitcoin
- Behind the scenes: tech support for Formula 1
- The security risk of fat fingers
- Why Windows Phone 7 isn't quite ready for business
- When will Microsoft stop fiddling with Windows 8?
- Flash down the pan?
- Metro Style apps vs desktop applications
advertisement
