Re: What does "cannot find script file "H:\Bha.dll.vbs"" mean?



On 31 Mar 2007 11:22:40 -0700, "Fei" <joey_qf@xxxxxxx> wrote:

Hi all:

Now I cannot open my external hard disc from My Computer - once I
click my external hard disc (H drive), it is said "cannot find script
file "H:\Bha.dll.vbs""! I believe that "Bha.dll.vbs" is a virus! Could
you please tell how can I deal with it?

That file is likely to be a part of the ButSur-A worm (not a virus),
as is easily discovered by doing a quick Google search. If you have
Windows set to show all hidden files, you can do a search for the
file. You may then also find files with names MS32DLL and autorun.inf
which are also part of the worm.

Several registry entries are made by the worm. All the details are
readily available, if you just do some simple searching. You'll find
that if you disable wscript, the worm will be crippled since VBS
requires wscript. Press Ctrl-Alt-Delete and open Task manager,
then find wscript running and stop it.

What antivirus product do you use? Most should be able to
iidenify the worm, and at least remove portions of it. Have
you tried scanning your main drive in Safe Mode?

Thank you so much!

Hope thayt helps

Art
.



Relevant Pages

  • Re: What does "cannot find script file "H:Bha.dll.vbs"" mean?
    ... My external hard disc is infected by my classmate ... That file is likely to be a part of the ButSur-A worm, ... that if you disable wscript, the worm will be crippled since VBS ... Press Ctrl-Alt-Delete and open Task manager, ...
    (alt.comp.anti-virus)
  • Re: WebDav Worm?
    ... > Maybe this is old news, or maybe it's scanning pattern is just now ... thought it was a script kiddie probing for various ... offsets/length of NOP sleds, ... But the activity levels increased to that of a worm. ...
    (Incidents)
  • Re: ssd attacks; worm? and precautionary steps
    ... The script comes with a database ... > or list of usernames and passwords. ... It didn't get very far is it only got into a users account ... The worm tried to see if it had root privileges and when it didn't it ...
    (comp.os.linux.security)
  • Re: [Full-Disclosure] DCOM Worm/scanner/autorooter !!!
    ... i looked at the code and it is NOT a worm. ... It can be deployed on several computers very fast, ... it doesn't have the ability self replicate itself from ... The script contains the hostname, ...
    (Full-Disclosure)
  • Re: [SLE] Advise on Worm/Phishing Emais
    ... I'd like some advise on how to handle worm and phishing emails coming to ... and the method to tell when a phish is a phish ... with a script run, in email, or web, but that's harder with all the ...
    (SuSE)