Virus alert: Sysres.vbs (malware)
Threat name: Vbs.Autorun.FM
Type: Malware
Filename: [Win32Root]\sysres.vbs
Threat :Whenever a removable drive is inserted, the following files are copied over:
Autorun.inf
ntdir.vbs
Manual Solution:
- Reboot System into safe mode
- Go to C:\Windows and look for Sysres.vbs and delete.
- Go to Regedit and search for Sysres.vbs and delete all values that it has.
- Also in Regedit search for ntdir.vbs and radz_services.vbs and delete all value that it has.
- Do reboot
Other Related Topics:






















thanks so much, will pass it on!
Comment by Jan Tallent — September 19, 2008 @ 8:18 pm
Autorun.inf
ntdir.vbs
radz_services.vbs
c:\windows\sysres.vbs
Manual Solution:
1. Reboot System into safemode
2. Click My Computer –> Tools –> Folder options –> View –> tick: show hidden files and folders –> untick: Hide extensions for known file types –> untick: Hide protected operating system files (Recommended)
3. Goto C:\Windows and look for Sysres.vbs and delete.
4. Goto regedit and search for Sysres.vbs and delete all values that it has.
5. Also in regedit search for ntdir.vbs and radz_services.vbs and delete all value that it has.
6. Insert your WindowsXP Prof SP2 or SP3 Installer CD.
7. Navigate on I386 folder and copy Ntdetect.com
8. Overwrite C:\Ntdetect.com
9. Restart and boot to your WinXP SP2 or SP3 installer CD
10. Select “R” for REPAIR
11. Choose 1: C
12. C:\Windows prompt will appear then type “FIXMBR”
13. Answer “Y” for Yes
14. Type Exit
15. Voila, your computer is fully restored
Comment by electrogoodie — September 23, 2008 @ 3:16 am
@electrogoodie Thanks man for the detailed solution! you are the man!
Comment by admin — September 23, 2008 @ 4:33 am
The author of the said malware speaks. He has his antidote and just visit his website. You know why he created such script? Just to protect the ff:
* Internet Explorer HOMEPAGE – Protect from Pornographic Websites.
* Task Manager – Protect from Disable.
* Registry - Protect from Disable.
* Flash Drives/USB – To Protect from Auto running of Virus.
* Local Drives – To Protect from Auto running of Virus.
Comment by electrogoodie — September 27, 2008 @ 12:57 pm
where can i found regedit?
Comment by jay — November 2, 2008 @ 8:43 pm
Start -> Run -> type regedit or press Start+R and type regedit and press ok
Comment by admin — November 2, 2008 @ 9:21 pm