Rem-VBSworm v8.0 =========== - General info: Running under: Maurice on profile: C:\Users\Maurice Computer name: MAURICE-PC Operating System: Microsoft Windows 10 Home Boot Mode: Normal boot Antivirus software installed: Windows Defender Executed on: do 29-12-2016 @ 12:01:09,26 =========== - Drive info: Listing currently attached drives: Caption Description VolumeName A: Netwerkverbinding C: Lokale harde schijf D: Lokale harde schijf Data E: Verwisselbare schijf F: Cd-rom-schijf Z: Lokale harde schijf Recover Physical drives information: C: \Device\HarddiskVolume1 NTFS D: \Device\HarddiskVolume3 NTFS Z: \Device\HarddiskVolume4 NTFS =========== - Disinfection info: SUCCESS: The process with PID 1876 has been terminated. INFO: No tasks running with the specified criteria. =========== - Shortcut info: Shortcut: "C:\Users\Maurice\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CherryFile.lnk" ---------------------------------------------------------------- Shortcut: "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\ScpToolkit Tray Notifications.lnk" ---------------------------------------------------------------- =========== - Scheduled tasks info: TaskName: \Microsoft\Windows\NetTrace\GatherNetworkInfo Next Run Time: N/A Last Run Time: 30-11-1999 00:00:00 Task To Run: %windir%\system32\gatherNetworkInfo.vbs Start In: $(Arg1) Comment: Network information collector Run As User: Gebruikers ===================================================== Scan finished at: 12:01:57,96 Send this log only if requested by a helper. ===================================================== Made by @bartblaze Tool to delete VBS autorun worm and unhide files Quarantine folder on: C:\Rem-VBSqt Info: https://bartblaze.blogspot.com/2014/02/remediate-vbs-malware.html