Well… So far I’ve caught two using NOD32 and the USB Drives being swapped around. Ooops, quarantine, DENIED.
First up, we have VBS/Butsur.E, the one that replaces your IE Title Bar’s original value to “Taga Lipa Are”, which is actually a rewritten code, I think from the “Hacked by Godzilla” thing. It spreads thru system and removable media, by implanting an autoplay.inf in those drives, each time the drives’ autoplay is invoked, it spreads by running a VB script.
Second, we have the VBS/Small.NAC, which also implants an autoplay.inf, but causes various applications with certain keywords to minimize and terminate. I think it also spreads using the same procedure as Butsur does.
As usual, here are some general rules to follow in removing viruses:
- Disable System Restore. Some viruses and worms actually regenerate by using the modules within System Restore.
- Update your virus definitions. Make sure to do this whenever you need to scan. What use is scanning with old definitions?
- Restart Windows in Safe Mode. Safe mode only invokes functions in which it nees to run (theoretically), which may or may not cause any virus regeneration things to be loaded in memory, making it possible to remove.
- Scan away. Personally, I recommend NOD32, from ESET.
- Reload Windows.
Might I plug Firefox as well? Get it here. Now.
P. S. I’m guessing JP might say this, so… You could always change your OS and never (almost) see viruses again.