Post: VBS Virus
02-28-2017, 03:40 PM #1
MessinBound
Bounty hunter
(adsbygoogle = window.adsbygoogle || []).push({}); I have noticed a program launching every start up...the program in question is Game Key Decrypter, I have not installed this. I have looked up the task manager process and it is called RegASM.exe (Quick bit of research tells me that this is a system process to do something with Windows) and in my start up tab in Task Manager there is a process called sound.vbs, opening file location takes me to:

C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sound.vbs (obviosly)

This is the code inside of the vbs:

You must login or register to view this content.

Going to the roaming folder shows multiple created files from the vbs:

You must login or register to view this content.

I dont know what to do at this point I have tried changing/deleting the vbs code. I have tried to disable on start up but that dosen't matter it just keeps reverting back to the way it was...

I have done a virus scan on my computer, active processes and root kit scans but nothing except when I scanned the file directly, my anti-virus moved the file to quarantine but that won't do anything because the file keeps coming back.

Here is the anti virus scan result

You must login or register to view this content.

I am linking the Decryptor to the VBS because they both show up on start up/I have noticed them both recently (I check my start up tab regularly and have never noticed sound.exe before and I mean come on sound.exe you have a better chance at fooling me with windows.exe Cheesy)

Help I dont know what this is/what it does!
03-01-2017, 01:35 AM #2
Kronos
Former Staff
Originally posted by MessinBound View Post
I have noticed a program launching every start up...the program in question is Game Key Decrypter, I have not installed this. I have looked up the task manager process and it is called RegASM.exe (Quick bit of research tells me that this is a system process to do something with Windows) and in my start up tab in Task Manager there is a process called sound.vbs, opening file location takes me to:

C:\Users\User 1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sound.vbs (obviosly)

This is the code inside of the vbs:

You must login or register to view this content.

Going to the roaming folder shows multiple created files from the vbs:

You must login or register to view this content.

I dont know what to do at this point I have tried changing/deleting the vbs code. I have tried to disable on start up but that dosen't matter it just keeps reverting back to the way it was...

I have done a virus scan on my computer, active processes and root kit scans but nothing except when I scanned the file directly, my anti-virus moved the file to quarantine but that won't do anything because the file keeps coming back.

Here is the anti virus scan result

You must login or register to view this content.

I am linking the Decryptor to the VBS because they both show up on start up/I have noticed them both recently (I check my start up tab regularly and have never noticed sound.exe before and I mean come on sound.exe you have a better chance at fooling me with windows.exe Cheesy)

Help I dont know what this is/what it does!


Try deleting it and finding out lol
03-02-2017, 12:14 AM #3
MessinBound
Bounty hunter
Originally posted by Kronos View Post
Try deleting it and finding out lol


I have deleted it about 5 times and all the files were just coming back :P

Don't know what I have done differently but today I seemed to have fixed it. No GKD or VBS/spam files

So this can be close if the moderator see this ayy lmao
03-02-2017, 12:16 AM #4
Kronos
Former Staff
Originally posted by MessinBound View Post
I have deleted it about 5 times and all the files were just coming back :P

Don't know what I have done differently but today I seemed to have fixed it. No GKD or VBS/spam files

So this can be close if the moderator see this ayy lmao


Hahahah good to hear,

Thread Closed

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo