That's called "flashdrive' infection, in every root partition it creates the files below: You need to remove autorun.inf in every root partition, it's hidden, you can see it in DOS prompt.
* \Autorun.inf --> used to autorun the worm when the drive is accessed, so must be removed.
* \sal.xls.exe
*Windows\ufdata2000.log
I would suggest running "Flash_Disinfector.exe" not sure if "sal.xls.exe" variant is covered yet but the tool creates a bogus "autorun.inf" which would help prevent the worm from loading and spreading.
http://www.techsupportforu
According to the author, when flash_disinfector is run, it will create a bogus folder, autorun.inf in every partition. It wont stop the infected file from getting in, but it does prevent the loading point from getting created.
PrevX:(claims to remove it)
http://spywarefiles.prevx.
Main Topics
Browse All Topics





by: war1Posted on 2007-03-24 at 22:34:10ID: 18787409
tsultan,
vinfo/viru sencyclo/d efault5.as p? VName=WO RM_VB.CII
vinfo/viru sencyclo/d efault5.as p? VName=WO RM%5FVB%2E CII&VSect= Sn
The worm may be in System Restore, so that is why you cannot delete it. Disable system restore.
This is Trend Micro description of the worm
http://www.trendmicro.com/
Here is how to remove it
http://www.trendmicro.com/