+ Reply to Thread
Page 1 of 10
1 2 3 ... LastLast
Results 1 to 10 of 91

Thread: FS6519.dll.vbs, Autoplay and TAGA LIPA ARE! TROJAN

  1. #1
    Junior Member Entrance Examinee blueazulbughaw is on a distinguished road blueazulbughaw's Avatar
    Join Date
    Aug 2006
    Location
    日本
    Posts
    89

    FS6519.dll.vbs, Autoplay and TAGA LIPA ARE! TROJAN

    Grabe ang laki ng idinulot n2 sa laftaf ku... nagreformat nah, wala pden, tnry n kng anu anu antivirusat antispyware, d kinaya... amf... buti nlng, naisipan ko ayusin sa regedit... e2 bka makatulong...



    My Computer -> Tools Menu -> Folder Options -> View Tab:

    Select: Show hidden Files and Folders

    Uncheck: Hide Extensions for known file type and Hide Protected operating system

    Click Yes Then OK.

    You will see an autorun.inf and FS6519.dll.vbs in all your harddrives. Delete ALL of them.

    If it says that something is using the program. Press Ctrl+Alt+Del and go to processes, end ALL wscript.exe

    Then go to run type regedit and then press ok, go to Edit -> Find and type FS6519.dll.vbs.

    Edit the found registry by selecting the name, ryt click and modify, remove the last two strings which is wscript.exe and FS6519.dll.vbs and click OK.

    If finished, press F3 and it will search again for another, just do the same thing until nothing is found in your registry.

    If you are done with the FS6519.dll.vbs, its time for the TAGA LIPA ARE! be edited in your IE, type the string on the search again then it will show up the IE title ... modify then type anything you like or better delete it.



    check your local drives if still have autoplay... kng meron pa... check mo nlng maayus... hehe
    nagdudugo n ilong ko kaka english eh...

    for questions, comments and suggestions, just PM me...



    dun sa gumawa ng virus... amf ka... muntik n mawala project ko sa OJT, feb 14 pasahan ne2... pero inspirasyon kita ah...



    makagawa nga ren... TAGA MAPUA PRE! un ang taytel... wakoko...

  2. #2
    Senior Member Moderate Poster trioncross is on a distinguished road trioncross's Avatar
    Join Date
    Aug 2006
    Location
    dark side
    Posts
    297
    astig talaga si blue.... natanggal ko na rin sa laptop ko yung trojan na yan..... tnx blue......

    "Humankind cannot gain anything without first giving something in return. To obtain, something of equal value must be lost. That is alchemy's First Law of Equivalent Exchange."

  3. #3
    Freak.Depraved.Insane Class 'SSS' member Ramy is on a distinguished road Ramy's Avatar
    Join Date
    Nov 2006
    Location
    69.8.124.143
    Posts
    6,311
    um... wala mas madali method?

    or more importantly... any way we can prevent our laptops from being infected over and over?

    dami na may virus nyan
    This account has been hacked... dont trust anything he says!

  4. #4
    Junior Member Entrance Examinee blueazulbughaw is on a distinguished road blueazulbughaw's Avatar
    Join Date
    Aug 2006
    Location
    日本
    Posts
    89
    for now wala p po... meron daw antivirus nod32 ata un... pero d nya fully tinatanggal... saglit lng nmn gwen yan eh...

  5. #5
    Ownage™ Super Moderator Class 'SSS' member Botee is on a distinguished road Botee's Avatar
    Join Date
    Sep 2006
    Location
    im just here for you
    Posts
    4,173
    nahawa mo ako nyang virus na yan ate blue!!!

    waaaaa... buti na lang hindi harmful itong virus na ito...
    "...all the while i thought that things cannot change,
    but this lady came into my life and proved me wrong
    and made me remember that i too was also human
    and made me realize that i can feel love
    now she's my strength and my weakness... my delilah"
    -Winston-

  6. #6
    Tambay Newbie drkprd is on a distinguished road
    Join Date
    Feb 2007
    Posts
    1
    yung nod32 meron ako..well pang corporate edition lang ang meron sila..so kailangan ng crack...hindi mkukuha yung full version unless may valid username tska password ka kasi online nya ichecheck unlike common antivirus software na madali i-crack...all i was able to get was a file that makes the nod32 use free for like another 10000+ days....as with that stupid trojan, kahit pa madelete ng nod32, magloloko nga yung pc at magdidisplay ng error "can not find fs6519.dll.vbs" ....so wala din...still trying your suggestion blue

    yun..effective yung suggestion ni blue....there's another way nga pala....dun sa file types na tab..dun din sa tools menu...

    search for the vbs extension tapos delete nyo...
    windows extensions yan na default binubuksan ng windows..
    so everytime na may virus or trojan na vbs din ang extension, automatic na bubuksan ng windows...

    a friend suggested it to me and so far, nothing's gone wrong...
    Last edited by Botee; 02-16-2007 at 09:56 PM. Reason: dobol posted... minerge ko na po ung post nyo

  7. #7
    Tambay Newbie Enslavement is on a distinguished road
    Join Date
    Feb 2007
    Location
    Gapo
    Posts
    1
    tnx dude, naalis ko rin yung virus sa akin. actually, nakuha ko yung virus sa isang prof habang ginagamit yung laptop ko sa klase. galing sa flash disk nya yung virus, nasearch ko rin sa net na kumakalat nga through flash drives. nyweys, salamat uli!

  8. #8
    Tambay Newbie henx is on a distinguished road
    Join Date
    Feb 2007
    Posts
    2
    Quote Originally Posted by blueazulbughaw View Post
    Grabe ang laki ng idinulot n2 sa laftaf ku... nagreformat nah, wala pden, tnry n kng anu anu antivirusat antispyware, d kinaya... amf... buti nlng, naisipan ko ayusin sa regedit... e2 bka makatulong...



    My Computer -> Tools Menu -> Folder Options -> View Tab:

    Select: Show hidden Files and Folders

    Uncheck: Hide Extensions for known file type and Hide Protected operating system

    Click Yes Then OK.

    You will see an autorun.inf and FS6519.dll.vbs in all your harddrives. Delete ALL of them.

    If it says that something is using the program. Press Ctrl+Alt+Del and go to processes, end ALL wscript.exe

    Then go to run type regedit and then press ok, go to Edit -> Find and type FS6519.dll.vbs.

    Edit the found registry by selecting the name, ryt click and modify, remove the last two strings which is wscript.exe and FS6519.dll.vbs and click OK.

    If finished, press F3 and it will search again for another, just do the same thing until nothing is found in your registry.

    If you are done with the FS6519.dll.vbs, its time for the TAGA LIPA ARE! be edited in your IE, type the string on the search again then it will show up the IE title ... modify then type anything you like or better delete it.



    check your local drives if still have autoplay... kng meron pa... check mo nlng maayus... hehe
    nagdudugo n ilong ko kaka english eh...

    for questions, comments and suggestions, just PM me...



    dun sa gumawa ng virus... amf ka... muntik n mawala project ko sa OJT, feb 14 pasahan ne2... pero inspirasyon kita ah...



    makagawa nga ren... TAGA MAPUA PRE! un ang taytel... wakoko...


    nakuha ko din tong problema na to. kaso kahit anong tingin ko sa HD ko wala ang file na FS6519.dll.vbs. well, nandun yung autorun.ini pero wala talga yung FS6519.dll.vbs na file. kahit dun sa isa kong HD wala.

    ginawa ko parin yung process at naayus sya, after ko mag restart nandun na ulit sya. it just doesnt end there for me.

    help. naiirita ako dito e. you could post it here or try emailing me flemnearl at yahoo dat com
    Last edited by henx; 02-23-2007 at 08:14 AM.

  9. #9
    Active Senior Member Masteral Adik led_ikari is on a distinguished road led_ikari's Avatar
    Join Date
    Jan 2007
    Location
    mars
    Posts
    518
    nireport nyo na ba yan sa mga authorities? (meron namang mga service ang anti virus na vault and stuff tapos papadala mo sa kanila diba?)

    san ba nakukuha yan?
    Yeah it sucks sometimes but hey... lets Enjoy life

    Seeing virtue in idiocy is the prerogative of the young - Taldeer Farseer

    Only oneself assumes his own boundaries. If you really want it, YOU can DO IT.

  10. #10
    Tambay Newbie slaphoundz is on a distinguished road
    Join Date
    Feb 2007
    Posts
    2

    Taga Lipa Are! Remover

    Read and follow this instruction carefully.

    1. Go to My Computer -> Tools Menu -> Folder Options -> View Tab
    2. Check Show hidden files and folders
    3. Uncheck Hide extensions for known file type and Hide protected operating system files
    4. When Windows displays a popup warning you about protected operating system files, click on Yes
    5. Click on OK
    6. Search for FS6519.dll.vbs and autorun.inf on your hard disk drive and delete all instances of this file.
    7. If you get a warning that something is using the program. Press Ctrl+Alt+Del (to bring up the Task Manager) and go to Processes, end all instances of wscript.exe. Close the Task Manager afterwards.
    8. Run regedit.exe
    9. Go to Edit -> Find and type FS6519.dll.vbs.
    10. Edit any matching registry entry by selecting it, right-click to modify, remove the last two strings which is wscript.exe and FS6519.dll.vbs, and click on OK.
    11. To continue searching for other matching entries, press F3. Repeat step 10 if another match is found.
    12. To remove the IE title TAGA LIPA ARE!, search that string again in the registry and delete the string for every matching entry.


    NOTE: Only two files are responsible for these malware to be function.
    Dont use double click when accessing drive(partitions), instead type the
    drive letter to ad bar.
    1. DELETE the "autorun.inf"
    2. DELETE the "FS6519.dll.vbs"

    pagnatanggal nyo yan ay OK na.
    just follow carefully at unawaing mabuti...goodluck


    IKALAT nyo na lang ito pa sa ibang forum na tambayan nyo..Thanks
    Pakipost na rin po sa BULLETIN BOARD sa frenster nyo para sa iba pang infected ng malware na ito....
    Last edited by slaphoundz; 03-06-2007 at 06:05 PM.

+ Reply to Thread
Page 1 of 10
1 2 3 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts