Jump to content

Virus!


kkengvibul

Recommended Posts

hi people..

I am having some virus problems. I turned on my computer this morning and it was filled with virus(es). I'm using Avast! and everytime it detects a virus and I followed the recommended action, the detection popup just keeps coming up.

The file name is

D:/.MS32DLL.dll.vbs

C:/.MS32DLL.dl.vbs

Malware name:

VBS: Solow

Malware type: Virus/Worm

and some others i dont remember.

When i click delete or move to chest, the popup would not go away and it says that the file could not be found or something.

What's happening to my computer? Is there a way that i can fix this?

thank you

kkengvibul

Link to comment
Share on other sites


i tried to do some research.....but all the sites seem to say that i need to format my computer.

Is that really the case? Is there any other way i can get rid of this virus without having to format my computer?

kkengvibul

Link to comment
Share on other sites

Try AVG, altho some members here seem to hate it , they seem to hate it bc it is free. I've used it for years and never a virus, or one it couldn't clean up.

actually i hate AVG because it let several viruses through despite being up to date. I wouldn't hate something because it's free... :o I use NOD32 now a greatly prefer it.

I haven't dealt with this particular virus, but ususual strategy with a vbs virus is:

  • open task manager (CTRL-Shift-ESC) and kill the wscript.exe process
  • set explorer to show all files and extensions (Tools -> folder options, then enable 'show hidden files and folders' and uncheck 'hide protected operating system files' and 'hide extensions for know filetypes')
  • search your system for *.vbs files, including removable drives.
  • Sort results by size. You'll see the files you already know are the virus (ie. ms32dll.dll.vbs) Anything .dll.vbs is nearly always a virus, they are taking advantage of the fact that windows is set by default to hide extensions and thus the user only sees ms32dll.dll.
  • Anything the same size and nearly the same date as the known virus is likely also a virus. delete them, or rename them and move them if you're uncertain and think they might be legit. note that the bad .vbs files are usually hidden and will show up as 50% transparent in the search results.
  • check your removable drives and C drive for autorun.inf, this is how the virus spreads itself. it's unlikely that your removable drive has a legitimate autorun.inf unless it's designed to pop -up a portable application list or something when installed. Bin them.
  • run MSconfig from 'Start' --> 'Run' and examine the Startup tab for items referencing the virus and uncheck them.
  • Get a decent virus program.

Link to comment
Share on other sites

thanks for the replies.

Veazer, i tried what you said and the ms32dll.dll.vbs files was not there. There were no .dll.vbs files....only .vbs files. When i tried to delete the latest vbs files, I couldnt.

What do i do now?

Link to comment
Share on other sites

hm...although it said that i couldn't delete the files, the virus detection seems to be gone now.

Does this mean i've managed to delete the virus/worm?? Or is it still there? Is there a way to check?

thanks again

(sorry for alll the questions!)

kkengvibul

Link to comment
Share on other sites

Best answer to that is to go to one of the virus detection companies site and download a scanner, run that and see if it finds it still, if so most of the download version allow you to clean up the machine with out having to buy anything

Regards

/edit typo //

Edited by A_Traveller
Link to comment
Share on other sites

I think the virus is still in my computer since when i double click on both the C and D drive, a "Windows Script Host" says 'can not find script file C:\.MS32DLL.dll.vbs'.

when i try searching for this file, its nowhere to be seen.

Link to comment
Share on other sites

Thanks for all the help everyone!! I think I've managed to get rid of the worm now. I can double click on open my c and d drive without any problems. I used the SOPHOS program to scan my computer and deleted the infections.

However, I have another problem now. After I deleted one of the infections and restarted my computer, on start-up there's another popup that says (Windows Script Host) 'Cannot find script file C:\Windows\boot.ini'.

That is the exact file I deleted through SOPHOS Anti Virus. So what do i do now?

kkengvibul

Link to comment
Share on other sites

Thanks for all the help everyone!! I think I've managed to get rid of the worm now. I can double click on open my c and d drive without any problems. I used the SOPHOS program to scan my computer and deleted the infections.

However, I have another problem now. After I deleted one of the infections and restarted my computer, on start-up there's another popup that says (Windows Script Host) 'Cannot find script file C:\Windows\boot.ini'.

That is the exact file I deleted through SOPHOS Anti Virus. So what do i do now?

kkengvibul

Just run a repair from your Windows CD and it should tidy up the mess. Sophos should have removed the worm's entries from boot.ini, not the whole file. :o

Link to comment
Share on other sites

I don't have a Windows XP CD, only a system recovery cd. I found on the internet that i can't fix it with a recovery cd. Is this true?

Nope. Only a full reinstall.

Any Windows disk (of the same version) will do, just use your own license key. Try borrowing one from a friend.

Link to comment
Share on other sites

  • 11 months later...
Thanks for all the help everyone!! I think I've managed to get rid of the worm now. I can double click on open my c and d drive without any problems. I used the SOPHOS program to scan my computer and deleted the infections.

However, I have another problem now. After I deleted one of the infections and restarted my computer, on start-up there's another popup that says (Windows Script Host) 'Cannot find script file C:\Windows\boot.ini'.

That is the exact file I deleted through SOPHOS Anti Virus. So what do i do now?

kkengvibul

I think, your computer has infected virus called Godzilla, the virus was deleted but the command in start up still exist. Just go to run>msconfig then click Startup and uncheck the boot (wscript.exe/E:vbs C:\WINDOWS\boot.ini)

Hope it helps

Kanitsorn

Link to comment
Share on other sites

I think, your computer has infected virus called Godzilla, the virus was deleted but the command in start up still exist. Just go to run>msconfig then click Startup and uncheck the boot (wscript.exe/E:vbs C:\WINDOWS\boot.ini)

Hope it helps

Kanitsorn

Probably won't help too much, this thread is nearly a year old... :o

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.








×
×
  • Create New...
""