aikelyu naman sab tingali ni
vbs....dats a worm virus...mao pud na ang nisulod sa ako computer.....makapa hinay na cya kay anha motago sa imo EXE files........amo gamit until now is mcafee enterprise....matangtang na cya.....
What's the filename of the .vbs?...
open a windows explorer, click TOOLS, select folder options, select view tab, check show hidden files and folders and uncheck hide protect operating system files..then click apply then OK..now..go to drive C: which is affected..right click and open files..find all file AUTORUN or all fs.dll.vbs files and delete them...restart your PC and try openning drive C: again...
windows system32 folder pud. na didto mga vbs virus. but dapt disable nimu using task man ang wscript na process before mangdelete... updated AVG can delete. also if khibaw ka registry editing kay mdelete pud nimu registries na mupoint sa script virus...
if u want to check if nagwork ba imu gibuhat, no need to restart.. task man lg and end task explorer then run nimu balik... try double click daun imu drive. if muopen, then ngwork imu gibuhat...
lisora ana sa instruction hehehe nalibog ko...not a PC expert ...hehe
mao ra man sguro ni nga case sa uban before.
kani solution taken from QuiCkiE KiLLeR's page:
-= KiLL tHe NoOB aikelyu.html =-
[*] Files to be deletedLOCATION
> kernel.dll.vbs & aikelyu.html{ C:\WINDOWS\system32 }
> pooh.vbs & autorun.inf{ C:\, D:\, E:\ or all available root drives }
[*] QuiCkiE KiLL
> End Process all "wscript.exe" from Task manager
> Delete the files stated above
[*] DeTaiLeD KiLL
> Run "taskmgr", in the Processes(tab), End Process all instances of "wscript.exe" from the Task manager
> Run "cmd", type "cd\" press enter, type "cd windows\system32" press enter
> type "attrib -h -s -r kernel.dll.vbs" press enter, type "del kernel.dll.vbs" press enter
:same process when deleting aikelyu.html
> now go to drive root, by typing "cd\" press enter
> type "attrib -h -s -r pooh.vbs" press enter, type "del pooh.vbs" press enter
:same process when deleting autorun.inf
> Do the same process from each drive root when deleting pooh.vbs and autorun.inf
[*] ReGistrY ChaNgeS
> Path: "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
- Find Shell(String Value), modify its value to "Explorer.exe"
- Remove this ->"C:\WINDOWS\system32\kernel.dll.vbs", you can see it is added to the Shell(String value)
> Path: "HKLM\software\Microsoft\Windows\CurrentVersion\Ru n\aikelyu"
- Delete aikelyu.html
> Restart and Done.
naa ko para tang tang ani nga virus sayun kayu... 1 click ra.... emaili ko sa jprnscrz@yahoo.com tabangan tamu....
Similar Threads |
|