hi there plz help me … i have got this virus called VBS:SOLOW which has affected my computer. the avast antivirus detects also delets it but the virus keeps comming back again aftere 200 sec. the file which is affected by the virus is MS32DLL.dll.vbs…
plz help me this is an annoying virus…
Hi ManasM,
Try these removal instructions or try the free version of SuperAntiSpyware:
4. To delete the value from the registry Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions refer to the document: How to make a backup of the Windows registry.
Click Start > Run.
Type regedit
Click OK.
Note: If the registry editor fails to open the threat may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.
Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
“MS32DLL” = “%Windir%\MS32DLL.dll.vbs”
Navigate to the subkey:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
In the right pane, delete the value:
“Window Title” = “Hacked by[REMOVED]”
Exit the Registry Editor.
http://www.symantec.com/security_response/writeup.jsp?docid=2006-112416-3424-99&tabid=3
How to fix Godzilla
- Double Click on My Computer icon on Desktop and select Tools → Folder Options
- When Folder Options cliak at View tab
- check at Show Hidden files and folders
- unchuck the Hide extention… and Hide protected operating system file
- click OK
- Press Ctrl+Alt+Delete. The Windows Task Manager will dispalay. Click at Processes tab
- Click menu Image Name (to sort Files)
- Select wscript.exe (one by one)
- Click End Process button
- Open drive (By right click and select Explore. Must not Double Click !) Delete autorun.inf and MS32DLL.dll.vbs (Press Shift+Delete) in all drives include Handy Drive and Floppy disk.
- Open folder C:\WINDOWS to delete MS32DLL.dll.vbs inside (press Shift+Delete )
- Go to Start → Run and enter regedit click OK. Registry Edit dialoq will display.
- Select HKEY_LOCAL_MACHINE → Software → Microsoft → Windows → Current Version → Run to delete MS32DLL (press Delete key on keyboard)
- Select HKEY_CURRENT_USER → Software → Microsoft → Internet Explorer → Main to delete Window Title “Hacked by Godzilla” (press Delete key on keyboard)
- Click Start → Run and enter gpedit.msc click OK. Group Policy dialoq will display.
- Select User Configuration → Administrative Templates → System → Double Click on file Turn Off Autoplay then Turn Off Autoplay Properties will display
- Select Enabled
- Select All drives
- Click OK
To prevent auto open when we insert CD or plug the Handy Drive that is the way virus infect.- ClickStart → Run and enter msconfig Click OK. the System Configuration Utility dialoq will display
- Click Startup tab
- Uncheck MS32DLL
- Click Apply
- Clock OK (or Close)
When the System Configuration dialoq display select Exit Without Restart- Double Click on icon My Computer on Desktop. Then select Tools → Folder Options
- On Folder Options dialoq select View tab
- Check at Hide extention… and Hide protected operating system file
- Click OK
- Right Click at Recycle bin. Then select Empty Recycle Bin to make sure the virus is deleted.
That’s all. You’ll never see Hacked By Godzilla again. I Guarantee it’ll work !
Hi ManasM,
Here is another manual cleansing instruction for this particular malware:
http://www.precisesecurity.com/computer-virus/vbssv-feb0727.htm
polonus