Forum Home
Press F1
 
Thread ID: 89689 2008-05-08 12:39:00 Why do discs still autoplay? utopian201 (6245) Press F1
Post ID Timestamp Content User
667384 2008-05-08 12:39:00 Hi
I've set the drive as shown in the screen shot:
img131.imagevenue.com

So as you can see, I've chosen "ask me what to do"

But whenever I insert a CD, it still autoplays. I've also tried choosing "Take no option", but still it autoplays. Why doesn't this dialog work?
utopian201 (6245)
667385 2008-05-08 13:51:00 What OS? Win XP, Vista?

What sort of CD's does this happen with?
stu161204 (123)
667386 2008-05-08 22:34:00 This happens with XP Pro, it has SP2.
These are just ordinary data discs.
utopian201 (6245)
667387 2008-05-08 22:54:00 Run this (www.microsoft.com)

And see if it finds anything wrong, then it'll fix it
Speedy Gonzales (78)
667388 2008-05-09 00:00:00 You could also set 'Mixed content' instead of 'Music Files' in the Autoplay window and see if that works for you. Terry Porritt (14)
667389 2008-05-09 00:40:00 Run this (www.microsoft.com)

And see if it finds anything wrong, then it'll fix it

Thanks, I'll give that a go
utopian201 (6245)
667390 2008-05-09 05:00:00 Start/Run
Type in gpedit.msc
Go to User Configuration/Administrative Templates/System
Double click on Turn off Autoplay
Select Enabled and Turn off Autoplay/All Drives.
Reboot.
Neil McC (178)
667391 2008-05-10 04:19:00 Hi
Speedy: that little autorun fix was quite useful. How did you come to know about it?
It says:
AutoFix [V5.2.3790.67]
Time [2008-05-10 15:08:03]
Microsoft Windows Version [5.1 (Service Pack 2) <2600>]

Test [The Shell Hardware Detection service is running.] - Instance [N/A]:
Result [AutoStart Setting]: OK
Result [The Shell Hardware Detection service is running.]: OK

Test [Policies] - Instance [W:\, Drive Type: 0]:
Result [HKCU\...\Policies!NoDrives]: OK {Absent}
Result [HKCU\...\Policies!NoDriveAutorun]: OK {Absent}
Result [HKCU\...\Policies!NoDriveTypeAutorun]: OK {Present}
Result [HKLM\...\Policies!NoDrives]: OK {Absent}
Result [HKLM\...\Policies!NoDriveAutorun]: OK {Absent}
Result [HKLM\...\Policies!NoDriveTypeAutorun]: OK {Absent}
Result [Driver level policies]: OK {
HKLM\...\Services\!Autorun (Absent) <Allows>
HKLM\...\Services\\Parameters!Autorun (Absent) <Allows>
HKLM\System\CCS\Enum\...!AlwaysEnable (Absent) <Not set>
HKLM\System\CCS\Enum\...!AlwaysDisable (Absent) <Not set> }

Test [Drive Notification] - Instance [W:\, Drive Type: 0]:
Result [Legacy Notification]: OK
Result [AutoPlay V2 Notification]: Problems {
Service (Silent)
Shell (Deaf) }
>> Repair << [Autoplay V2 Event]
Step: No steps to take.
Result: This AutoPlay setting cannot be fixed. Either the device is malfunctioning, or the wizard cannot determine the problem.

>> Required action: The wizard found problems but cannot fix them -> None

I dont think the drive is malfunctioning, because it says the same for my dvd writer as well. Do you think it could be indicative of malware or something similar? If I plug in an infected usb stick, it auoplays and I'm screwed.

spybot search and destroy doesn't find anything and there doesn't seem to be anything wrong with my hijack this log. do you concur?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:25:12 p.m., on 10/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
D:\Norton Internet Security\IAMAPP.EXE
D:\NORTON~1\navapw32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
D:\KMaestro\KMaestro.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Norton AntiVirus\navapsvc.exe
D:\Norton Internet Security\NISUM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
D:\Norton Internet Security\SymProxySvc.exe
D:\UPHClean\uphclean.exe
D:\Norton Internet Security\NISSERV.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\CNAC4RPK.EXE
D:\Firefox\firefox.exe
D:\utorrent.exe
C:\WINDOWS\Explorer.EXE
D:\Programs\windows updates\AutoFix.exe
D:\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 127.0.0.1:8080
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\FLASHGET\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Norton AntiVirus\NavShExt.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\FLASHGET\getflash.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [iamapp] D:\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] D:\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BtcMaestro] D:\KMaestro\KMaestro.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - D:\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\FLASHGET\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - www.update.microsoft.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{48866084-9EA2-4C2F-95E2-E4299D264B06}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Ad-Aware 2007\aawservice.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - D:\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - D:\Norton Internet Security\NISUM.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - D:\Norton Internet Security\SymProxySvc.exe

--
End of file - 4845 bytes
utopian201 (6245)
667392 2008-05-10 04:27:00 I've used this program myself a few times and it did fix something once.

The only entry that doesnt have to be there is this

04 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

Disable Nortons, then run autofix again, (or see if autoplay works), see if it makes any diff.
Speedy Gonzales (78)
1