WINDOWS/system32/killVBS.vbs script warning

Status
Not open for further replies.
Hi there all,

As the Title here may suggest, I have a recurring Windows script error that appears every time I start up windows.

To be exact, it reads:

Cannot find script file "C:\WINDOWS\system32\killVBS.vbs"


I have found one thread on this site regarding this, and after reviewing what I could find on other sites' threads; I have decided to come here seeking assistance.

I have both the latest version of Ad Aware 2007(free) and Spybot Search&Destroy (free) plus a copy of CA's AV program. I have run scans with all of these over the last two days, and despite Ad Aware and Spybot both finding a collection of tracking Cookies, nothing in regard to the above script warning has been found.

I believe I contracted this trojan/worm, as it had been referred to elsewhere, through either using my USB stick on one of the PC's at the local net cafe or when I used my Laptop at the same net cafe (in Thailand, Bangkok). It all begun after I had been there.

I no-longer visit this cafe, as fortunately I now have the net up and running in my apartment.

I should have gotten onto this sooner, but have neglected it up until having had the time now. Possible Symptoms of this as seen through the computer are: extreme sluggishness, occasional crashes, screen flickering.

Some of these symptoms are perhaps not due to the script warning, but I am guessing that at least the sluggishness is.

My Laptop is not that new and fancy, an IBM T20 with a Pentium III processor and only 128mb ram and a 30gig hard drive (OS is XP). Nonetheless, it has run MUCH faster in the past than it is doing so now.

Apologies for the long intro. I'm assuming that if anyone can help me they'll want a Hijackthis log file posted up here to refer to. I will get onto that now, just thought I would put the feelers out and start the ball rolling.

OK, please if anyone can aid me on this it would be extremely appreciated - it's hopeless trying to get things done on a PC that's running slower than a MAC truck being pushed up hill.

Cheers.
 
Hi scuttled and welcome to techspot. =)

Important: Please read this thread HERE before you decide whether to clean or reformat your system.

Should you decide to clean your computer, please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. Do follow all the instructions exactly. They will provide logs for analysis of your system so I will know how to instruct you to proceed.

Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

Also, please let me know the results of the AVG Antirootkit scan

PS. Windows XP really runs very slowly on on anything less than 512 MB.


Regards,
Your friendly momok =)

This thread is for the use of scuttled only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
killVBS.vbs problem. Re. HJT scan but just read your post.

Thanks for the reply Momot, more RAM is definitely needed. It's on the 'have to do list'...

OK here is the Hijackthis scan I completed.

However, having just seen your post I believe I need to complete a whole other series of steps and then run another scan before this can be of any use. After going over the info, I have decided not to reformat and clean instead.


Anyway, just in case it is of some use, here is the HJT log attached.

I'll get onto your recommended steps now.

Cheers and thanks you again for the efficient reply.
 

Attachments

  • hijackthis.log
    5.8 KB · Views: 22
Hi,

Whilst you are going through those steps and running HijackThis again, please fix these entries:

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wscript.exe C:\WINDOWS\system32\killVBS.vbs
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BDE10DD-41F7-4DF4-8DA8-A78F9F88642C}: NameServer = 58.64.124.150 58.64.7.3

After that save the log and post the other logs. Also remember to let me know the results of the AVG antirootkit scan.


Regards,
Your friendly momok =)

This thread is for the use of scuttled only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Completed 15 steps/Requested logs.

Hi there Momok,

I have completed all of the step as instructed. I did come across a few issues along the way and will let you know what these are now - just in case they are of assistance/importance in analysing my logs.

Issue 1. I couldn't get the suggested version of AVG antispyware completely installed on my computer as I kept getting the message "64-bit of Windows is not supported". I tried changing the compatibility mode, but to no avail. Consequently, I found this version - avgas-setup-7.5.1.43 - and figuring it was the next best bet, completed the instructions as were given in the same way.

Issue 2. When running Ad-Aware 2007 whilst in safe mode, I was unable find anywhere to 'uncheck scan for negligible risk entries', despite following the instructions given. I thus completed the full scan and removed what it found.

Issue 3. During safe mode, When I ran the AVG spyware version that is noted above, I selected the option to quarantine the results per the instructions. Once the scan was completed I saved the log file, plus one to the desktop. However, when I took a look at the logs there was the message as warned against in the instructions that said - 'no action taken' after each of the entries. I then checked the back to the scan settings, and found that indeed I had set the scan to quarantine. Following this I returned to the results section, deleted all 6 of the 'tracking cookies' and 'trojans' which were listed, and saved two log files once again.

Finally,

Issue 4. When running the HJT scan again I followed your instructions from the previous post and went to fix the entries you had mentioned, but only one that was in the previous scan's log appeared this time. This was entry- 017. Not knowing whether I should fix it without the others being there, I have left it as is for the time being.


Ok, so that' all for the issues.

The good news is that the VBS script warning no longer appears when I start up Windows, at least I hope this is good news. Don't know whether this is any indication that it has gone, I didn't see any reference to it in the latest HJT log so maybe it has.

In regards to the AVG anti-root scan, there was nothing found.

Here are the three logs attached as requested.

What do you think?

Cheers and thanks again,

Scuttled
 

Attachments

  • Report-Scan-20070702-150142.txt
    2.1 KB · Views: 6
Hi,

Firstly let me applaud you for your excellent posts and you followed the instructions very well. I must say your posts are much more a pleasure to read than some others.

No worries about the AVG AS; you downloaded the right version.

Have HijackThis fix this entry:
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BDE10DD-41F7-4DF4-8DA8-A78F9F88642C}: NameServer = 58.64.124.150 58.64.7.3

Apart from that, your logs look clean now.

Delete all files in AVG Antispyware Quarantine folder. (located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine)

You may also delete the C:\VundoFix Backups folder and its contents.

Turn off system restore (XP/ME only). Learn how to do that HERE.
This will remove all the remaining nasties from your old restore points.

After that turn system restore back on.
This would have created a new safe and clean restore point for your system.

Often times, an infection can occur again not due to the incompetence of programs, but because of user habits.
May I recommend you to read this article.
This can help to prevent future infections.

Should you have any further problems, please post in this thread.


Regards,
Your friendly momok =)

This thread is for the use of scuttled only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hi Momok,

Glad my posts were clear enough for you to read. I'm far from experienced when it comes to this kind of business, so although it was a lengthy process it was nonetheless an educational one.

Just a couple of quick questions for you.

Firstly, I went to the AVG Spyware quarantine directory on C: drive to delete the files as you said, but there was no Quarantine directory there. I'm presuming that there was nothing quarantined. Alternatively, perhaps what had been quarantined was deleted on my final scan and removal. I tried to load up the AVG Spyware program to have a look if there was anything there but unfortunately it won't allow me.

I get a an AVG Anti Spyware 7.5 Error exclaiming:

"connection to service failed. Please reinstall AVG AntiSpyware7.5".

I know this probably isn't the right question for this thread, but on the off chance it is related to the process I thought I should let you know. Any thoughts?

Secondly, the following link:

http://www.bleepingcomputer.com/forums/tutorial56.html

in your previous post for the System Restore directions seems to be out of order. I think the server must be down so I will try again later. Is this ok?

Right.

Currently, the computer seems to be running better than before, but I'm yet to really give it a good test. A few things seem to be a bit funny:

The Modzilla Firefox browser window opens very small and applications don't appear on the task-bar when I minimize them. Also an Internet Explorer Icon has appeared on the Desktop that wasn't there before. I suppose there are a few things in Windows that were reset and need to be adjusted.

Despite this everything else is going well.

Many thanks for your kind assistance and clear guidance throughout this process.

Keep on doing a great job!

Scuttled.
 
Hi,

Thank you for your kind comments. It was a pleasure to help you.

I've checked the link and it seems to be working. Perhaps the server was down for a while previously. Please try again.

Have you turned off system restore and turned it back on again?

With regards to AVG, I would reinstall it just to be sure, since the message states exactly that hehe.

I'm not quite sure about your task bar issue. Could you post a screenshot for me?

Regards,
Your friendly momok =)

This thread is for the use of scuttled only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.

This thread is now closed: If you need this thread unlocking, please pm a moderator with a link to the thread.

Only the original thread starter can do this. Anyone else, will be ignored.
 
Status
Not open for further replies.
Back