since this the clickest trojan nowadays, im posting a quick guide on how to remove it..
instead of looking for FS6519.dll.vbs or FS6519.vbs, you can search for tracker.vbs
hope this will help...
My Computer -> Tools Menu -> Folder Options -> View Tab:
Select: Show hidden Files and Folders
Uncheck: Hide Extensions for known file type and Hide Protected operating system
Click Yes Then OK.
You will see an autorun.inf and FS6519.dll.vbs or TTMS1117.dll.vbs or taga lipa in all your harddrives. Delete ALL of them.
If it says that something is using the program. Press Ctrl+Alt+Del and go to processes, end ALL wscript.exe
Then go to run type regedit and then press ok, go to Edit -> Find and type FS6519.dll.vbs or TTMS1117.dll.vbs or taga lipa.
Edit the found registry by selecting the name, ryt click and modify, remove the last two strings which is wscript.exe and FS6519.dll.vbs or TTMS1117.dll.vbs or taga lipaand click OK.
If finished, press F3 and it will search again for another, just do the same thing until nothing is found in your registry.
If you are done with the FS6519.dll.vbs or TTMS1117.dll.vbs or taga lipa, its time for the TAGA LIPA ARE! be edited in your IE, type the string on the search again then it will show up the IE title ... modify then type anything you like or better delete
in other words:
Read and follow this instruction carefully.
1. Go to My Computer -> Tools Menu -> Folder Options -> View Tab
2. Check Show hidden files and folders
3. Uncheck Hide extensions for known file type and Hide protected operating system files
4. When Windows displays a popup warning you about protected operating system files, click on Yes
5. Click on OK
6. Search for FS6519.dll.vbs and autorun.inf on your hard disk drive and delete all instances of this file.
7. If you get a warning that something is using the program. Press Ctrl+Alt+Del (to bring up the Task Manager) and go to Processes, end all instances of wscript.exe. Close the Task Manager afterwards.
8. Run regedit.exe
9. Go to Edit -> Find and type FS6519.dll.vbs.
10. Edit any matching registry entry by selecting it, right-click to modify, remove the last two strings which is wscript.exe and FS6519.dll.vbs, and click on OK.
11. To continue searching for other matching entries, press F3. Repeat step 10 if another match is found.
12. To remove the IE title TAGA LIPA ARE!, search that string again in the registry and delete the string for every matching entry.
NOTE: Only two files are responsible for these malware to be function.
Dont use double click when accessing drive(partitions), instead type the
drive letter to ad bar.
1. DELETE the "autorun.inf"
2. DELETE the "FS6519.dll.vbs"
found it from the web