Infected By Nar.vbs And VBS/AutoRun.S Worm

how can i recover them? it is work great!!!! …………. The registry was scanned ( '49' files ). got the exact same problem as Oneil two post above mine… the download website seems to be down… where else can i download flash_disinfector from??.. his comment is here

But the update from Exterminate It, removed it. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: JULIE-44049AC7A Version information: BUILD.DAT : Nasty little problems, but kills everyone…. jyoti Says: November 23, 2009 at 2:31 pm | Reply hey xperience…… I used this fd… but I still hav AUTORUN.INF folder in my C and D drives is this fine..? http://www.bleepingcomputer.com/forums/t/184788/infected-by-narvbs-and-vbsautoruns-worm/

Additionally it attempts to place an Autorun.inf file on the root of the volume so that it is executed the next time the volume is mounted. In addition to this, VBS autorun worms may perform other activities. I was running no antivirus or spyware removal software, so I got eset NOD32 and it found nar.vbs on both of my drives and supposedly 'quarantined' it. usb-flash-drive virus file-recovery share|improve this question edited Sep 19 '15 at 11:10 asked Sep 15 '15 at 8:28 user568458 949102952 1 I've got a feeling that the "fake drive" was

the capacity is 4gigabyte and is made from China.. pourquoi? Marlwarebytes finished the full scan and found nothing. that will clean the thumbdrive that we'll deal with after you're cleanLet's start with Mbam and get an idea of what's going on----------------Please download Malwarebytes Anti-Malware and save it to your

si oui c'est bon, sinon ben je trouve ca louche... I have 2 HDs... I keep getting the message: "cannot copy flash_disinfector[1]:Access is denied.The source file may be in use. Donnez votre avis Utile +0 Signaler kemo_juju 12Messages postés vendredi 1 février 2008Date d'inscription 2 avril 2012 Dernière intervention 27 août 2008 à 21:38 voila le log.txt de eset : #

I tried even with compatibility mode, and doesn't seems to work. ^45 Says: August 16, 2009 at 10:45 pm | Reply Does the software work on 64bit environment like vista 64bit jaquot Says: April 7, 2008 at 9:04 pm | Reply un disque dur c'est infecté comment y acceder sans perdre mes sauvegardes? In this way, it will be able to propagate across users' machines. Back to top #4 shizznats shizznats Topic Starter Members 3 posts OFFLINE Local time:12:53 AM Posted 07 December 2008 - 03:12 PM I dont know if this is relevant, but

Windows Live OneCare detected the worm and even pretended to clean it. http://forums.majorgeeks.com/index.php?threads/nar-vbs-vbs-autorun-s-worm.176074/ Montgomery Brother Mel AutoRunHow to Remove AutoRun from Your ComputerTo completely purge AutoRun from your computer, you need to delete the files, folders, Windows registry keys and registry values associated with and, i read form another site that when he used ur program, his autorun didn't activate anymore. I deleted these files in safe mode, but im not naive enough to think that got rid of this thing.

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/... this content H:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP90\A0015123.vbs [DETECTION] Contains recognition pattern of the VBS/RunAuto.Q VBS script virus [NOTE] The file was deleted! eXPeri3nc3 Says: June 8, 2008 at 2:07 am | Reply It's a false positive. any help would be much appreciated.

Reidman Says: November 27, 2008 at 3:16 am | Reply Did not fix the Win32/autorun virus on the flash drive. It's EASY, USER FRIENDLY AND EXTREMELY EFFECTIVE!!! Restart your computer and see if problem still persists. weblink You have helped a lot of people worldwide.

When reboot survival has been ensured, VBS autorun worms will start infecting available drive's root folders by creating and copying the malicious script in the same folder. I suggest therefore that you treat your USB as broken, using data-recovery utilities, rather than standard Windows utilities, to recover the data. munauwar Says: November 22, 2007 at 6:48 pm | Reply Hi, I've run flash disinfector, re start my computer but "Hacked By Spiderman 2007-10" still appearing every time IE is launched.

That virus was in there pretty deep.

i got a little thing asking me if i installed it correctly, to which i said yes. thanks again for the flash disinfector for takin out that destrukto crap. You must exercise caution here though, because there's a (slim) chance that you have legitimate executable files on your pen drive that are the same size as the malware. GREAT JOB BUDDY SRINIVAS Says: December 8, 2009 at 9:43 pm | Reply pls how u download that antivirus.pls send me.if u send means it will be very useful for me

That program can also fix some errors caused by virus. How many people would it take for California to run the country? PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics) Social: check over here Bill Says: October 13, 2008 at 5:52 am | Reply How long is the scan supposed to take?

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...