INF:AutoRun-BL[WRM] blocked.

So apparently I’m so used to being skeptical about other’s USB sticks that I was completely oblivious to SD cards, someone plugged it in and it was instantly blocked and chested Autorun.inf twice(one as Autorun and the other autorun), once from the SD card I think and apparently a second time within the avast chest? I don’t have the warning message up any more which said the origin (Update message came up since wireless at Uni was passworded thus failed to update.) Typically it happened shortly before I got a critical warning from adobe reader/flash player which only increases my worry.

Is this normal for avast to be wary of this file or should I do all the preliminary scans anyway(I’ll do a bootscan/malwarebytes scan this weekend anyway, more of the other tools as well).

recomended to install MCShield USB protector. http://mcshield.net

I don't have the warning message up any more which said the origin
if you have not rebooted since it happend, right click avast tray icon....show last popup click pin in top right corner, take screenshot and attach

if you want a malware check

follow instructions and attach logs (not copy and paste) http://forum.avast.com/index.php?topic=53253.0

run in order listed
AdwCleaner / Malwarebytes / OTL / aswMBR

when done, removal experts will be notified and help you
when finish, all tools used will be removed

Thanks for the USB tip, Window’s Update has to reset my computer so no luck there. And no aswMBR log since it said it ins’t compatible with windows 8 which sadly is what i’m using. That said should I go ahead and do a full system/boot scan with avast now?

That said should I go ahead and do a full system/boot scan with avast now?
No .... now you relax and wait for a removal expert to check the logs

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

.

--------------- Next ----------------

Check USB storage devices / removable drives

Download MCShield from one of the following links:

MyCity - Official download link
Softpedija - Mirror download link

[*] Double click MCShield-Setup to install the application.
[*] Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
[*] Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.

When all scanning is done, you need to attach a logreport that MCShield has created.

Start → All Programs → MCShield → Logs

Attach here → AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.

Ok while it’s doing that, I noticed AdwCleaner found a few things, should I go ahead and just clean those? I wasn’t 100% sure if I should have done so without being told to do so. And as for the McSheild scan it wasn’t my SD card that triggered this so I can’t scan that particularly (I’ll let him know next time I see him) I should still scan my other USB Drives even if they haven’t been used here in awhile now just in case right?

I recommended to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity - Official download link
Softpedija - Mirror download link

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.

Woah, Farbar worked faster than I thought.

System is clean, any problems?

I should still scan my other USB Drives even if they haven't been used here in awhile now just in case right?
yepp do that and as argus say...attach the log her
And as for the McSheild scan it wasn't my SD card that triggered this so I can't scan that particularly (I'll let him know next time I see him)
advice him to install MCShield ;)

and if he need to checck his computer for infections, send him here and follow the same guide as you did

I have two external backups to scan so I’ll do that tomorrow or Saturday when I have a longer stretch of time and attach the logs then.

Nope, none so far, thanks.

Will do!

Please download TFC by OldTimer to your desktop

[*]Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
[*]It will close all programs when run, so make sure you have saved all your work before you begin.
[*]Click the Start button to begin the process. Depending on how often you clean temp
files, execution time should be anywhere from a few seconds to a minute
or two. Let it run uninterrupted to completion.
[*]Once it’s finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

.

Please download DelFix by “Xplode” to your Desktop.

Run the tool and check the following boxes below;

[] Remove disinfection tools
[
] Create registry backup
[*] Purge System Restore

Now click on “Run” button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt

I don’t need DelFix log report.

And ran both, though if it did unsure if MCSheild created any logs(or where they be if it did, my drives were clean but my external had an autorun.inf there too renamed. Anything else I should do?

but my external had an autorun.inf there too renamed. Anything else I should do?

Autorun.inf.vir —> remove.

And ran both, though if it did unsure if MCSheild created any logs(or where they be if it did,
Start > all programs > MCShield > Logs

Yeah this is going to sound stupid but doesn’t seem like when I open the control center to be anywhere that indicates logs just general, scanner, update, quarantine, whitelist stats and about tabs, and I don’t think the autorun.inf had was “autorun.inf.vir” it just labeled it suspicious and renamed the file apparently, I believe that log had temp in the filename too. Nothing’s in the quarantine or anything either. (unless they all autorun files should be treated to be viruses). I didn’t happen to download the wrong version or something did I?

And ran both, though if it did unsure if MCSheild created any logs(or where they be if it did,

%AllUsersProfile%\MCShield\AllScans.txt

you are looking at the wrong Place…

start button in Your lower left corner of computer screen…then continue

Okay got it, not Window’s 8’s first time making me feel this stupid but here’s the log.