Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
 
Old 10-14-2007, 12:31 AM   #1 (permalink)
 
Junior Techie

Join Date: Mar 2006

Posts: 68

william232

Send a message via AIM to william232
Default VBS/Small Virus with ms32dll.dll.vbs

Hi all lately i have found a virus on my desktop yesterday morning

i am not sure if its a virus or trojan or worm

HijackthisLog is located here

http://wikdesigns.com/docs/hijackthis141007.txt

And the Name of the file is ms32dll.dll.vbs

How can i Fix this?

Thanks,
William
william232 is offline  
Old 10-14-2007, 09:05 AM   #2 (permalink)
jay_bo's Avatar
 
Ultra Techie

Join Date: Jul 2006

Posts: 898

jay_bo is on a distinguished road

Default Re: VBS/Small Virus with ms32dll.dll.vbs

download vundo fix, run your system in safe mode, then vundo fix which will scan your system.

google: vundo fix
__________________
jay_bo is offline  
Old 10-14-2007, 12:05 PM   #3 (permalink)
 
Junior Techie

Join Date: Mar 2006

Posts: 68

william232

Send a message via AIM to william232
Default Re: VBS/Small Virus with ms32dll.dll.vbs

Which one?

vundo fix - Google Search
william232 is offline  
Old 10-14-2007, 05:13 PM   #4 (permalink)
jay_bo's Avatar
 
Ultra Techie

Join Date: Jul 2006

Posts: 898

jay_bo is on a distinguished road

Default Re: VBS/Small Virus with ms32dll.dll.vbs

Download VundoFix 6.5.6 - VundoFix is a removal tool developed to remove Virtumonde infections - Softpedia

sorry i would of gave u the link never had time
__________________
jay_bo is offline  
Old 10-15-2007, 12:10 AM   #5 (permalink)
 
Junior Techie

Join Date: Mar 2006

Posts: 68

william232

Send a message via AIM to william232
Default Re: VBS/Small Virus with ms32dll.dll.vbs

I Restarted in Safe Mode but it did not find anything

What else can i do?
william232 is offline  
Old 10-15-2007, 11:56 AM   #6 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,689

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: VBS/Small Virus with ms32dll.dll.vbs

remove these entries

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Hacked by Godzilla

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

and then follow this below and then post a new log
  1. Double Click on My Computer icon on Desktop and select Tools --> Folder Options
  2. When Folder Options cliak at View tab
  3. check at Show Hidden files and folders
  4. unchuck the Hide extention… and Hide protected operating system file
  5. click OK
  6. Press Ctrl+Alt+Delete. The Windows Task Manager will dispalay. Click at Processes tab
  7. Click menu Image Name (to sort Files)
  8. Select wscript.exe (one by one)
  9. Click End Process button
  10. Open drive (By right click and select Explore. Must not Double Click !) Delete autorun.inf and MS32DLL.dll.vbs (Press Shift+Delete) in all drives include Handy Drive and Floppy disk.
  11. Open folder C:\WINDOWS to delete MS32DLL.dll.vbs inside (press Shift+Delete )
  12. Go to Start --> Run and enter regedit click OK. Registry Edit dialoq will display.
  13. Select HKEY_LOCAL_MACHINE --> Software --> Microsoft --> Windows --> Current Version --> Run to delete MS32DLL (press Delete key on keyboard)
  14. Select HKEY_CURRENT_USER --> Software --> Microsoft --> Internet Explorer --> Main to delete Window Title “Hacked by Godzilla” (press Delete key on keyboard)
  15. Click Start --> Run and enter gpedit.msc click OK. Group Policy dialoq will display.
  16. Select User Configuration --> Administrative Templates --> System --> Double Click on file Turn Off Autoplay then Turn Off Autoplay Properties will display
  17. Select Enabled
  18. Select All drives
  19. Click OK
  20. To prevent auto open when we insert CD or plug the Handy Drive that is the way virus infect.
  21. ClickStart --> Run and enter msconfig Click OK. the System Configuration Utility dialoq will display
  22. Click Startup tab
  23. Uncheck MS32DLL
  24. Click Apply
  25. Clock OK (or Close)
  26. When the System Configuration dialoq display select Exit Without Restart
  27. Double Click on icon My Computer on Desktop. Then select Tools --> Folder Options
  28. On Folder Options dialoq select View tab
  29. Check at Hide extention… and Hide protected operating system file
  30. Click OK
  31. Right Click at Recycle bin. Then select Empty Recycle Bin to make sure the virus is deleted.

__________________
Osiris is offline  
Old 10-15-2007, 05:04 PM   #7 (permalink)
 
Junior Techie

Join Date: Mar 2006

Posts: 68

william232

Send a message via AIM to william232
Default Re: VBS/Small Virus with ms32dll.dll.vbs

i cannot even locate ms32dll.dll.vbs and autorun.inf but avg is detecting it still.
william232 is offline  
Old 10-18-2007, 08:37 AM   #8 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,689

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: VBS/Small Virus with ms32dll.dll.vbs

Did you atleast move those 4 entries? If so, post a new log

Will AVG heal or delete the file?

Can you boot into safemode and run AVG?

Where does AVG say the file is located?
__________________
Osiris is offline  
Old 10-18-2007, 12:48 PM   #9 (permalink)
 
Junior Techie

Join Date: Mar 2006

Posts: 68

william232

Send a message via AIM to william232
Default Re: VBS/Small Virus with ms32dll.dll.vbs

it say it is located in windows folder on the c drive.

i have work soon ill post a new log now heres the new log

http://wikdesigns.com/docs/hijackthis.log

ill try and start and run avg in safe mode
william232 is offline  
Old 10-18-2007, 12:50 PM   #10 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,689

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: VBS/Small Virus with ms32dll.dll.vbs

and you cant browse to it with hidden files and folders enabled?
__________________
Osiris is offline  
 
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista attacked by 13-year-old virus Osiris Virus - Spyware Protection / Detection 2 09-19-2007 09:51 AM
HELP !! MSN virus froze Virus - Spyware Protection / Detection 6 08-12-2007 02:43 PM
Storm Worm Erupts Into Worst Virus Attack in 2 Years Osiris Virus - Spyware Protection / Detection 1 08-01-2007 10:32 AM
Worm Masquerades As Phony Virus Warning Osiris Virus - Spyware Protection / Detection 0 07-11-2007 01:08 PM
Proof Of Concept Virus For iPods Running Linux Osiris Linux, BSD, other *nixes & Open Source Software 0 04-06-2007 12:57 PM