Solved

Can not find script file "C:\MS32DLL.dll.vbs"

Posted on 2009-04-14
10
729 Views
Last Modified: 2013-11-22
Error....Can not find script file "C:\MS32DLL.dll.vbs" trying to open local drive. I've tried all the manual removal instructions (delete ms32.dll.dll.vbs, autorun.inf, etc.) but none of the files or registry entries were located. It seems the vbs.zodgila was present and cleaned but the symtom remains.
0
Comment
Question by:sillybell
10 Comments
 
LVL 27

Expert Comment

by:David-Howard
Comment Utility
Automatic and manual removal instructions are listed here.
Please note that you will need to disable System Restore (Explained within the link) and run your scans.
http://www.symantec.com/security_response/writeup.jsp?docid=2006-112416-3424-99&tabid=3
I would suggest as well that once you have updated your antivirus software and disabled System Restore that you boot into Safe Mode (F8 at Startup) and then run your scans.
David
0
 

Author Comment

by:sillybell
Comment Utility
Thanks, David but I've already tried the manual removal links and none worked as the files and registry keys were not present to be removed.

0
 
LVL 4

Expert Comment

by:jason_woods
Comment Utility
Another option is MalwareBytes:
http://malwarebytes.org/
It can install and run in safe mode as well as update (highly recommended).
0
 

Author Comment

by:sillybell
Comment Utility
Sorry I didn't mention but I tried automatic removal tools first.
0
 

Author Comment

by:sillybell
Comment Utility
Update: I found a registry key (HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2
\{0447f8d0-cc36-11db-9499-806d6172696f}\shell\autorun\command) that has a string value of "c:\windows\system32\rundll32.exe shell32.dll, shellexec_rundll wscript.exe ms32dll.dll.vbs"

If I delete {0447f8d0-cc36-...}, the double click works to open my c: but when I reboot, the reg key is back and I'm back to square one. Any idea what could be creating this key???
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 
LVL 4

Expert Comment

by:jason_woods
Comment Utility
You may have to disable system restore...
0
 

Author Comment

by:sillybell
Comment Utility
system restore is disabled...
0
 
LVL 4

Expert Comment

by:jason_woods
Comment Utility
What tools did you try?
0
 
LVL 47

Expert Comment

by:rpggamergirl
Comment Utility
That's a flashdrive infection, Flash_Disinfector should help.
Download this tool from either of these locations... run and follow the prompts:
http://www.geekstogo.com/forum/redirect.php?url=http%3A%2F%2Fdownload.bleepingcomputer.com%2FsUBs%2FFlash_Disinfector.exe
http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
 

If the problem persists, run ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
0
 

Accepted Solution

by:
sillybell earned 0 total points
Comment Utility
Thanks for the posts but I due to time constraints I went ahead and did a format and reload.
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Preferred Cloud Managed Anti-Virus? 4 78
suspending the anti virus 6 101
How do I determine the virus in this email? 5 70
PCAnywhere 2 53
Sub-Titled: “My Way” (with apologies to Francis Albert Sinatra) Let me start by stating emphatically that I am one of those Experts who prefer doing things “My Way”. It’s kind of a no-brainer. “The following procedure works for me, so here is …
Ransomware continues to be a growing problem for both personal and business users alike and Antivirus companies are still struggling to find a reliable way to protect you from this dangerous threat.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now