Help - Search - Members - Calendar
Full Version: How To Remove This.
Boostcruising.com > Computers and Technology > Technical Support
namso786
I've got this damn vbs script file virus, Not sure of the name exactly, norton picks it up as W32.SillyDC but it blocks it, does not delete it.

It copies the name of another file, but its a script file.

So say if I have a file Test.mp3. It makes a file called Test.vbs right under it, damn annoying shit, does it for like all my files.

anyone know of a software that will remove this. Tried: Norton 2009, Ad Aware, NOD32, Spybot Search and Destroy.

no shady links yo ph34r.gif
the red krawler
Malware Bytes?

http://download.cnet.com/Malwarebytes-Anti...&tag=button
Chris
Reformat.
kit
http://www.symantec.com/security_response/...-071111-0646-99

Cliffnotes:

1) Turn off System Restore (first step in dealing with any virus/worm)
2) Do a *full* system scan (if your scanner doesn't work, boot into safe mode and try)
3) Restart and do -

1. Click Start > Run.
2. Type regedit
3. Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

4. Navigate to the following registry subkeys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"load"

5. In the right pane, delete any values associated with the worm.

6. Exit the Registry Editor.
namso786
QUOTE (kit @ Sep 15 2009, 08:11 AM) *
http://www.symantec.com/security_response/...-071111-0646-99

Cliffnotes:

1) Turn off System Restore (first step in dealing with any virus/worm)
2) Do a *full* system scan (if your scanner doesn't work, boot into safe mode and try)
3) Restart and do -

1. Click Start > Run.
2. Type regedit
3. Click OK.

Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

4. Navigate to the following registry subkeys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\"load"

5. In the right pane, delete any values associated with the worm.

6. Exit the Registry Editor.


Thanks, doing it now.

cheers
namso786
I have done this now, Still does not want to go away.. Norton BLOCKS the attack if I click on the file once.

But it won't delete it. I need something that will search my whole PC and delete everyone of those vbs script files
formatting is out of the question unfortunately.
dreeft
Formatting should never be out of the question. You're running windows, it's inevitable that you are going to have to wipe it at some point.
the red krawler
He's right you know.

You can install either Linux or OS X as an alternative.

The good: You wont get viruses on Linux, minimal viruses on OS X
The bad: Nothing works on either of them because the market share is so small. This is why theres limited viruses.
namso786
Its a loan laptop, with preloaded software, I cannot change anything, if it was my desktop, i would not even hesitate, just format.

But also its in my files, on my external, that has 504gb of stuff on it. its everywhere. But I managed to fix it.

The actual virus is called W32.SillyDC, its a worm of some sort. It places an autorun.inf file on all your hard disks and removeable storage drives.

When you plug it in, it runs that autorun.inf file which executes a batch file that does all this crazy shit (some cases disabled task manager, regedit and system restore)

In my case NOD32 deleted it before it could do anything, but for some reason, I had images of all my files everywhere, but as VBS Script files.

I found that all of the files were 11kb in size and modified on 24/03/2007 at 7:47am. They all had same size/date.

So I did a search, specifying everything under 12kb that was modified/created 24/03/2007. Found 860 files, ctrl+a Shift Delete, and now its all gone.

Norton does not come up with all these notifications anymore, so I'm assuming it is clean. I will run a scan one more time though just to be safe. I'm so glad its all gone, one of the most annoying viruses i've had in a while.

PS. Thanks for the advice and suggestions though, malware bytes seems like a good program. thanks
Chris
How many AV programs are you running at once?

namso786
I only ever have 1 AV program running at a time. I had NOD32 initially, uninstalled, Norton 2009, uninstalled, NOD32 now.

Have Spybot S&D isntalled(not running), Ad Aware 2009, Malware Bytes
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.