Benefits of disabling autorun?

    I just downloaded the xp update needed to disable autorun and used fix it for microsoft that automatically disables autorun. What are the actual benefits of disabling autorun, does it really provide more protection from viruses and malware?
    Plenty of benefits, almost all malware outside of the internet comes from autorun enabled devices.
    For me, it would cripple a useful function. I have several USB hard drives and I use autorun.inf to have the drive open automatically to a specific directory. These drives do not get connected to any computer but my own.

    Policies and procedures in place prevent USB exploits:

    • My flash drive is not the CD emulating type that will execute autorun.inf, so that if it were to become infected with a USB exploit while connected to another computer, it would not run when connected back to my computer.

    • Holding down the SHIFT key bypasses autorun when a CD ROM or USB device with autorun.inf is connected.

    • Navigating to the drive via Windows Explorer prevents any double-clicking from executing autorun.inf

    • Default-Deny security prevents non-white listed executables from running

    Having said that... if one has any doubts, it best to apply the fix, expecially on computers with multiple users.

    Nonetheless, there is one caveat to this "fix" that I've asked about in various places and never have received a clarification. From the KB article which describes how autorun is disabled on USB media:

    Update to the AutoPlay functionality in Windows
    Here is the statement I question:
    I assume this is because Windows cannot distinguish between a true CD and emulated CD device.

    This is quite troubling, it seems to me, for if a user connects one of these types of USB drives that happens to be infected with a USB autorun.inf virus, won't the exploit automatically run?

    I haven't used XP in so long that I forget, but does it not have the option to turn on/off auto run manually for each type of media?

    Even before security concerns, I always disabled autorun manually for everything.

    I find it annoying more than useful...
