TechSpot

KillVBS.Vbs

By 18sx
Jun 5, 2007
  1. Nite, Bruder

    Have any one of u ever have problem with KillVBS.vbs.
    its comes from flash drive actually. dont know how dont know why.

    and after painstaking long time removing the **** out of my system, with Dr. Web, suggestion from "Touch" a cool master in neighbor site.

    but the !@#$%^ keeps coming back. why, what happened?
    if use avg and deleted in virus vault, it started to crying out loud everytime i rebooting.
    something like missing file killVbs.Vbs. and when the flash drive has been infected, the syndrome is that we cannot doubleclicked on the flash drive from W-explorer anymore "missing killvbs.vbs. so formating the flashdrive will be the only way so far. anyone knew about this !@#$%^&.

    Please anyone share a way to cool down this son of a *****....
    i suspected this !@#$%^& plays with registry in the startup.
     
  2. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Important: Please read this thread HERE before you decide whether to clean or reformat your system.

    Should you decide to clean your computer, please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. These are a comprehensive mix of steps to remove common malware, as well as provide us logs of your system to look at so we can further remove any tricky nasties.
    Do follow all the instructions exactly.

    Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

    Also, please let me know the results of the AVG Antirootkit scan


    Regards,
    Your friendly momok =)

    This thread is for the use of 18sx only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    In addition to momoks instructions, please do the following.

    Download and install DrWebCureit:
    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
    http://spywareinfo.dk/download/drweb-cureit.exe to your desktop.

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

    Doubleclick the "drweb-cureit.exe" and click "ok" in the prompt window that will open , asking "start the express scan now".
    It will first make a quick scan of your system, let it clean what it find, and when it says "done"
    Click on the green screwdriver-
    Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select -Delete
    Click on the drive(s) you want to scan . A red dot will mark the selected drive(s) . Then hit the green arrow in lower right corner It will now scan your drive(s), say yes to all

    After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
    Save the report to your desktop. The report will be called DrWeb.csv
    Close Dr.Web Cureit.

    Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.

    Attach the DrWeb.csv log.

    Hopefully, DrWebCureit will delete your KillVBS.vbs problem.

    Regards Howard :)

    This thread is for the use of 18sx only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  4. 18sx

    18sx TS Rookie Topic Starter Posts: 37

    Thank Youuuuuuu Bruder!!!

    VBS is deleted.

    I have attached Drweb.csv, but because of this forum unrecognized of CSV format, therefore i add .log, u can change it afterwards.
    Thanks man,
    This forum is the best,
    very efficient.

    this is Hijack Files Loq

    Edited by Moderator: No need for double post if there are no other replies between your current and previous one. Just edit your previous post.

    oh, one more thing, actually after drweb scan and deleted the .vbs on my systems, the troublesome pop up during start up still exist, and i just use hijack this and delete everything that has ".vbs".

    and its gone!!!
    now everything is back and running great. tq..
     

    Attached Files:

  5. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Note: Please do not copy and paste logfiles. Instead, post the .log or .txt files as attachments.

    You have not posted all requested logs (ComboFix and AVG Antispyware) Please do so in your next reply.

    You may wish to copy and paste these instructions on notepad for easier reference later.

    Boot into safe mode under your normal user name. See how HERE

    Next turn on "Show all files and folders, including hidden and system". See how HERE

    Go to start > run and type services.msc. Press the enter key.
    Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    SpywareTerminator
    Spyware Terminator Realtime Shield Service


    Go to start > Control Panel > Add and Remove Programs.
    Remove anything related to the following:

    SpywareTerminator < Generally not recommended as it has had a history of having dubious repute. There are plenty of better options out there anyway.

    Open your task manager by pressing holding ctrl, alt and pressing del. Alternatively, use ctrl + shift + esc. Go to the processes tab, and end the following processes, if found:

    SpywareTerminator

    After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wscript. exe C:\WINDOWS\system32\killVBS.vbs

    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"

    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

    Close HJT.


    Navigate in Windows Explorer and delete the following files and folders in bold.

    C:\WINDOWS\system32\wscript. exe
    C:\WINDOWS\system32\killVBS.vbs

    Reboot into normal mode and rehide your protected OS files.

    Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs from normal mode as attachments into this thread. Do not copy and paste the logs.


    Regards,
    Your friendly momok =)

    This thread is for the use of 18sx only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...