DELAMARVIRUS.VBS

i was checking on my USB flash drive and it got this virus… i browsed around the web and its a threat…

http://www.tongjimba.com/exeviruses/6577.html

the current version of avast with updates cant remove it… please help T_T

Download and run the free Mbam. http://www.malwarebytes.org/mbam.php
asyn

^

i tried it and it didnt remove it… i also tried ad-aware…

You can also try free a-squared: http://www.emsisoft.com/en/software/free/
Be sure to update it manually after installing! Hope this helps.
If not, wait till essexboy logs in, he usually knows best how to get rid of this pest…
asyn

I suggest Panda USB Vaccine.

im now using this i think this will prevent the spreading but not the virus itself…

i tried lots of anti-malware/virus apps… still no luck… its still there… and i think it can be removed if i use a full verson of those anti-malware/virus apps… but i dont have a credit card account to do so… T_T

woe is me…

I hope you didn’t try any rogues…!!?
Please read here: http://en.wikipedia.org/wiki/Rogue_software
Usually you don’t need a paid version to remove malware…
asyn

^

no i use the trusted ones… like ad-aware and malwarebytes…

tol magaling ka ba maghanap ng file? tuturuan kita ng manual removal niyan kung may background ka sa computer.

simple script type virus lang yan kung gumagamit ka ng may script blocker di ka maapektuhan yan.

subukan mo muna basahin ang sa loob niya kung ano yan. right click>edit mabasa mo na ang laman yan

regards!!

^

edit eh? but i dont know how to remove it manually T_T

USB disk security removes it but it comes back when you plug it again… so i think my computer is the infected one…

english :o ???

ok just read the content of script first. what kind of script is that.

or just send to virus total to find out what kind of worms protecting the script

upload it here http://www.virustotal.com/

edit: post the result

or send it to the avast lab.

click avast icon>maintenance>virus chest>right click>add.
find the virus in your flask desk then open.

if the virus is in the chest. right click>submit the virus to the lab.
complete the submission data to send it.

i can guide you to manual removal of that script type but im afraid if you don’t understand what im saying it will cause damage to your system

regards!!!

have you tried

Dr.Web CureIt! http://www.freedrweb.com/cureit/?lng=en
How Do I Use Dr.Web CureIt!? http://www.freedrweb.com/cureit/how_it_works/
Norman Malware Cleaner http://www.norman.com/support/support_tools/58732/en-us

@bong2x

omg! that site is very helpful worship

thanks for the tips and i think that site shows the anti-virus/malware applications that knows that virus… ok… ive sent it to virus lab too… thanks im not good on this lol…

based on virustotal… avast and other anti viruses doesnt know this malware…

keep it in english so others can read this and fix the same problem too :slight_smile:

Па англыскы пажалуста да? (Aka speak english plz)

where is the result?

will im not fuent 8) i mean my old computer when push e it write i ;D ;D ;D

that vbs files is found in your C:\WINDOWS\system32, just make sure that it is arrange by type show in groups so that its easy to find it. it is easy to delete it will not coming back or rename the .vbs change to bat or bak.

but if you directly delete that file it will prompted you at the start-up ( “DELAMARVIRUS.VBS not found”)

so, go to C:\WINDOWS>click at regedit.exe>edit>find what>type what exactly the filename>find next> if it is find then delete it ;D :smiley:

Best Regards!!!

Uh could you please speak NORMAL english? I don’t understand wtf you said and I guess nobody does.

@bong2x

oh… sorry… i forgot to post the result…

Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.22 - AhnLab-V3 5.0.0.2 2010.04.22 Win-Trojan/Malware AntiVir 8.2.1.220 2010.04.22 HTML/Rce.Gen Antiy-AVL 2.0.3.7 2010.04.21 - Authentium 5.2.0.5 2010.04.22 VBS/Autorun.U Avast 4.8.1351.0 2010.04.22 - Avast5 5.0.332.0 2010.04.22 - AVG 9.0.0.787 2010.04.22 VBS/Autorun BitDefender 7.2 2010.04.22 Generic.ScriptWorm.FAE46803 CAT-QuickHeal 10.00 2010.04.22 VBS.SsiWg ClamAV 0.96.0.3-git 2010.04.22 VBS.Autorun-15 Comodo 4665 2010.04.22 - DrWeb 5.0.2.03300 2010.04.22 SCRIPT.Virus eSafe 7.0.17.0 2010.04.22 - eTrust-Vet 35.2.7443 2010.04.22 VBS/SillyAutorun.BLE F-Prot 4.5.1.85 2010.04.21 VBS/Autorun.U F-Secure 9.0.15370.0 2010.04.22 Generic.ScriptWorm.FAE46803 Fortinet 4.0.14.0 2010.04.21 - GData 21 2010.04.22 Generic.ScriptWorm.FAE46803 Ikarus T3.1.1.80.0 2010.04.22 - Jiangmin 13.0.900 2010.04.22 - Kaspersky 7.0.0.125 2010.04.22 Type_Script McAfee 5.400.0.1158 2010.04.22 VBS/Autorun.worm.k McAfee-GW-Edition 6.8.5 2010.04.22 Heuristic.LooksLike.Win32.Suspicious.A Microsoft 1.5703 2010.04.22 Worm:VBS/Autorun.AG NOD32 5049 2010.04.22 - Norman 6.04.11 2010.04.21 - nProtect 2010-04-22.01 2010.04.22 Generic.ScriptWorm.FAE46803 Panda 10.0.2.7 2010.04.21 - PCTools 7.0.3.5 2010.04.22 - Prevx 3.0 2010.04.22 - Rising 22.44.03.04 2010.04.22 - Sophos 4.53.0 2010.04.22 VBS/Sasan-Fam Sunbelt 6207 2010.04.22 Trojan.VBS.Autorun.a (v) Symantec 20091.2.0.41 2010.04.22 - TheHacker 6.5.2.0.267 2010.04.22 - TrendMicro 9.120.0.1004 2010.04.22 Mal_Otorun3 TrendMicro-HouseCall 9.120.0.1004 2010.04.22 Mal_Otorun3 VBA32 3.12.12.4 2010.04.22 - ViRobot 2010.4.21.2288 2010.04.22 - VirusBuster 5.0.27.0 2010.04.22 -

File size: 3423 bytes
MD5…: 409fa90b05a6cf485eb5112dafe4fd04
SHA1…: 10e3073b5157114eecedfc7e5c06a55acf61c979
SHA256: 9ff88378b19a0562b642c1f3a45d27c0dc20db841d696cc7a0e0e965ab0b4ce9
ssdeep: 48:aA7hquYnQ3Yti2I+F9u5wiUqAOyCy0AQY0hI9RlLRlyRlrqTnR5DOcOs/:aA7
hqXBw96A5OD0vi9RRRkRxqTnR5DvD
PEiD…: -
PEInfo: -
RDS…: NSRL Reference Data Set

pdfid.: -
trid…: Unknown!
sigcheck:
publisher…: n/a
copyright…: n/a
product…: n/a
description…: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…: n/a
signers…: -
signing date.: -
verified…: Unsigned

there… im going to wait for avast’s update… i hope my report on the virus lab gets through…

i think its detected by avast now? :smiley:

Best Regards!!!

^

nope… no virus database update yet…