Things You Need to Know About the FS6519.dll.vbs virus
The best way NOT get infected by a virus is get a good ANTIVIRUS and NEVER trust anyone with a mobile drive in one hand. Try to recognize th tiny signs to avoid getting infected….
The FS6519.dll.vbs a.k.a. “TAGA LIPA ARE” (TLA) virus does nothing harmful to your computer system, here are some of its characteristics:
- copies itself to your write-enabled drives [A..Z] (That is if you have that many drives.)
- copies itself to the /ROOT/%windir%/ folder.
- changes the Internet Explorer titlebar to “TAGA LIPA ARE!”.
- disable changing of the default homepage in Internet Explorer.
- inability to double click drives (although, opening with right-click menu enables you to open the drive).
- cloned/copied/modified from Hacked By Godzilla & Taga ESI scripts by someone named F. E. SILVA
“It is just another scripting virus modified by some noob who got his hand on the codes” (a comment by a friend of mine.. Yet he got infected from it… shongaks ka kasi!) Just a tiny sign of his being uninformed! /heh
The best way to remove this one and not get infected is to get an antivirus, I would recommend NOD32 (since I use it and it easily detects a lot of virus that my other antivirus install couldn’t remove).
Another possible way is to manually, delete it from your computer, but I would not recommend you doing it because it requires you to edit some parts of the registry.
Although it would be easy, you might accidentally, modify or remove an important information stored in the registry, So I recommend to skip the steps (but if you are brave enough, and want to delete it manually go ahead and try it, but I warn you…) and just try this:
TLA-Remover by Leerz: TAGA.LIPA.NOOB.KILLER
I havent tested the program since I didn’t get infected, but I run a couple of antivirus on the zip file and it does not include any trojan/spyware/virus. The zip also comes with a details on how to remove the virus and its brothers (cloned from/copied from versions) which is different with mine (I have a more lengthy and careful way the step by step procedure, as in which one to press/edit/delete/click).
Removing the FS6519.dll.vbs Virus Manually
Dont tell me I didn’t warn you about editing the registry when your computer does not work after edit the Windows Registry.
Here is a step by step procedure (for those who do not have much knowledge about RegEdit) on how to remove the TAGA LIPA ARE! virus:
- Connect all writtable-media that is suspected to be infected by the virus. (Anything that can be accessed and written by a computer)
- Plug it into the usb port. (some are found infront of your system unit, some at the back)
- Plug it into a card reader.
- Open the task manager and end all process with an image name WSCRIPT.EXE.
- To open Task Manager, Press CTRL+ALT+DELETE
- In the Process List, look for a process named WSCRIPT.EXE, select if found then click “End Process” and YES, repeat this until there are no more WSCRIPT.EXE in the list.
- Enable viewing of hidden files/Protected Operating System files/Extensions for known filetypes.
- The Windows Explorer way: Open Windows Explorer (My Computer), Click on Tools>Folder Options menu
- The Control Panel way: Click Start>Control Panel, Select Folder Options.
- Now the Folder Option Dialog appears. Select the View Tab, On the Advance Setting select the Show hidden files and folders radiobutton, uncheck Unhide extenstions for known file types and uncheck Hide Protected Operating System files then click OK.
- Delete the main files, FS6519.dll.vbs and autorun.inf.
- Search for the following files on your drive (Not inside folders, the root of the drive. ex. C:\, D:\) FS6519.dll.vbs and autorun.inf
- Delete the files by selecting both the files then pressing SHIFT+DELETE (this would not send the file to Recycle Bin)
- Repeat the previous steps until every drive has been searched.
- Go to the /ROOT/%SYSTEM%/ folder (mostly C:\Windows folder), and search and delete the FS6519.dll.vbs file.
- Delete all instances of WSCRIPT and FS6519.dll.vbs in the Windows Registry.
- Click Start>Run, type regedit and hit the Enter key
- Now the fun part - Removing it from the registry…
- To delete an entry in the registry, select the entry you want to delete and press the DELETE key, then answer YES to the confirmation popup.
- To edit an entry in the registry, right click on the selected entry and select modify. After modifying, click OK.
- To eradicate every Search for it… (why Search? I came across some entry of the file in other parts of the registry aside from the start-up area: ‘HKLM\software\Microsoft\Windows\CurrentVersion\Run\‘ while fixing a couple of my friends’ computers)
- Try to search for the following entries: FS6519.dll.vbs and WSCRIPT.EXE. Press CTRL+F and type the word to look for. Now, Press F3 if you want to search again for the same ‘word’
- Sometimes searching you would encounter the following entries \WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe FS6519.dll.vbs, I know that deleting the ,ShellExec_RunDLL wscript.exe FS6519.dll.vbs
part of the entry does not have anything the script nor your computer, but just for the sake of being extra careful, remove it anyway.
- The next part would be, Editing the Internet Explorer Title…
- Again, you can easily do this by searching for it in the Windows Registry, just Find TAGA LIPA ARE!, modify it or just leave it blank.
- The last part is a little bit tricky… Ask the following to yourself…
- …why didn’t I purchase/downloaded a good Antivirus that would have prevented me from reading this lengthy way of dealing the TAGA LIPA ARE! virus
- …why am I still using Internet Explorer as my browser?
- …why am I still reading this part of this article?
There you go! I hope this lengthy article provided you with the help you are seeking and hope you learned some lessons…
- Go get some better protection, better yet get a couple more alternative protection… One antivirus is not enough! I learned that the hard way a couple of months ago, when my system got corrupted and crashed. But that’s another story…
- Go get a better browser! Try

As the organizations are expanding from continent to continent, the need of data backup is mounting. These giant organizations prefers remote backup for their backup system. These organizations are using data recovery system to recover that data which is accidentally deleted. There are lots of organizations which developed their own data recovery program which is totally customized according to their specifications. The online file sharing is also gaining popularity day by day especially in companies where remote employees chat regularly with someone at the home office. To secure the data there is a need of backup computer files regularly. In the future it seems there will be lot of ISPs which will provide free internet with their other services.
The virus is not a good way of getting attention, a better way for the ‘noob’ virus maker to get some chick-action is to join and win in different programming contests… Or he might try to jump from a 50-storey building if his life isn’t worth anything any longer! He really gave me a lot of computer repairs this past few days, not that I didn’t to fix computers because of the virus, but it’s just annoying that a lot of them were from computer shops, image me searching and cleaning 20~30 computers. Running the regedit in each one those computers, I wish I had the TLA remover during those time…
These are just tiny signs that showing us that we need to constantly protect ourselves from computer viruses… When will you recognized those tiny signs around?
April 23rd, 2007 at 11:30 pm
[…] Things You Need to Know About the FS6519.dll.vbs virus […]
April 23rd, 2007 at 11:43 pm
[…] Things You Need to Know About the FS6519.dll.vbs virus […]
April 24th, 2007 at 12:08 am
[…] Things You Need to Know About the FS6519.dll.vbs virus […]
May 13th, 2007 at 1:11 am
Thank You for your help guys
We have destroyed the virus…
God Bless…
May 13th, 2007 at 2:05 am
no problem! I am glad to have been a help…
May 26th, 2007 at 2:59 pm
please tell me if anyone has succesfully eliminated the virus especially from the USB and laptop… and how they did it. Thank you so much.:-C i gor so pissed by this virus.
May 26th, 2007 at 6:35 pm
budj, you can easily remove it from the USB or even laptop. just follow which ever step you would like… You can remove it with the TLA Remover, or manually.
July 2nd, 2007 at 3:28 pm
how come i followed all the instructions now i can’t get to open my hard drives by double clicking. My only option is to right click and then explore.
July 2nd, 2007 at 3:47 pm
did it already! i had to reset my PC tnx!
July 29th, 2007 at 7:24 am
Hi! You just won one more regular reader ;)..
Good luck!
l8rz. Big lol
September 16th, 2007 at 10:55 pm
i have experienced that st|_|pid virus but the trick here is is if u have winrar installed on your pc try to erase it using the winrar software its easy as 1 2 3…
in just seconds your not infected on that sh1t virus….
thats the trick… goodluck…
September 25th, 2007 at 6:51 pm
can somebody help me?? i already downloaded the “TAGA.LIPA.NOOB.KILLER” but the FS6519.dll.vbs virus is still in my flash memory! when i attempt to heal the virus, my usb device automatically disconnects itself for a while and then it is again detected by my computer. my usb is useless now. i cant store anything in it i cant even reformat it. please help me. im so annoyed with it.
September 30th, 2007 at 2:57 am
if that still doesnt fix it, try the methods outlined in this website :
http://www.mapuaownage.com/forums/showthread.php?t=2511&highlight=lipa
October 4th, 2007 at 8:53 am
i’ve done the procedure but i can’t remove the “PROMISE” Im still waiting for the strawberry” message at the start of the computer. Please tell me what to do.
October 28th, 2007 at 6:19 pm
@madz,
is that a message at the Welcome Screen of your Operating system? if it is, then that would be legal notice…
you just have to set LegalNoticeText & LegalNoticeCaption entry on the registry to blank.
Here is the step:
1) Click Start > Run
2) Enter regedit on the box
3) Go to…
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
4) Modify LegalNoticeText, remove any values in the Key Value
5) Modify LegalNoticeCaption, remove any values in the Key Value
6) Restart!
Hope that helped.
November 10th, 2007 at 7:59 pm
Paano kung walang access sa taskmgr at sa regedit? Aha! Subukan nating gumawa ng script na babaliktad sa ginawa ng taga lipang virus na yan.November 10th, 2007 at 8:02 pm
Paano kung walang access sa taskmgr at sa regedit? Aha! Subukan nating gumawa ng script na babaliktad sa ginawa ng taga lipang virus na yan.
January 25th, 2008 at 3:40 am
None…
None…
February 2nd, 2008 at 12:30 am
TAGA.LIPA.NOOB.KILLER really works!! ive tried it and wth it worked!!
March 12th, 2008 at 9:15 am
None…
None…
August 3rd, 2008 at 9:05 pm
ei! meron bang ibang easy steps to remove the “promise virus” di kc tlga effective ung bnibigay nyong procedures eh.. even magpareprogam still the virus is there multiplying.. hope for your responses! tnx!