sowar.vbs
Home
Welcome, Guest. Please login or register.
Did you miss your activation email?

 



donations help testmy.net pay for the very high cost to run the site. Any amount is greatly appreciated.
Click to read why...

  spcr
    
News : Before you post... try a Why don't you search? - Many simple questions have already been answered.  If your query turns up dry then post, we always have people waiting for your questions. azn November 21, 2009, 09:45:22 PM
testmy.net Broadband  |  Main Forum  |  PC Security  |  Spyware & Malware  |  Topic: sowar.vbs Advanced search

Recommended Tests

Click here to run a free Performance Scan   TIP: Test how fast your system is really running
   Free Performance Scan
Click here to run a Free PC Error Scan    TIP: Test how many system errors your PC has
   Free PC Error Scan


Note: The links above are sponsored links
  0 Members and 1 Guest are viewing this topic. « previous next »
Pages 1 Go Down
Author
Topic: sowar.vbs  (Read 5622 times)
coolbuster
.
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2189


View Profile
« on: July 28, 2008, 10:51:07 AM »

this annoying virus has infected my friend's pc. she has tried to combat it with avg free, nod32 and hijackthis to no avail. it has a "restore" component.

does anyone know how to effectively remove sowar.vbs?
Logged

.
dlewis23
Inactive Moderator
TMN Seasoned Veteran
*
Offline Offline

Gender: Male
Posts: 9829

HEY! ill put it down when im good and ready.


View Profile
« Reply #1 on: July 28, 2008, 10:58:47 AM »

re install windows...

Its the most effective way to get rid of a virus.
Logged
mudmanc4
Ɠξξ₭ òƒ Ɠξξ₭z
Global Moderator
TMN Seasoned Veteran
*
Online Online

Gender: Male
Posts: 6534



View Profile WWW
« Reply #2 on: July 28, 2008, 12:39:55 PM »

 Here's a bit  I found last week , this virus is running rapid.



When first run VBS/Autorun-FM copies itself to:

Root\Cool USEP Scandal.vbs
Root\sowar.vbs
Windows\SysRes.vbs

and creates the following files:

Root\Autorun.inf
Windows\%ORIGFILENAME%

Whenever a removable drive is inserted, the following files are copied over:

Autorun.inf Cool USEP Scandal.vbs


The following registry entry is created to run SysRes.vbs on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run System Restore wscript.exe "Windows\SysRes.vbs"

VBS/Autorun-FM changes settings for Microsoft Internet Explorer by modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Main\Start Page

 EDIT: oops forgot to get the rest to you   Laughing


Go to Start > Run and type: cmd
press Ok.
At the command prompt, type in your primay drive location, usually C:
You may need to change the directory. If so type: cd \
Hit Enter.
Type: attrib -s -h -r -a autorun.inf
Hit Enter.
Type: dir
Hit Enter. This will allow you to see and confirm the Autorun files.
Type: del autorun.inf
Hit Enter.
Repeat the above commands for each drive on your computer including your flash/usb drive.
Now search for and remove sowar.vbs, SysRes.vbs, Cool USEP Scandal.vbs
At the command prompt, type in your primay drive location, usually C:
Hit Enter.
Type: attrib sowar.vbs.* -s -h -r -a
Hit Enter.
Type: dir /s sowar.vbs
Hit Enter.
If the file is present, type: del sowar.vbs
Hit Enter.
Repeat the above commands for each drive on your computer including your flash/usb drive.
Then repeat these instructions to search for and delete SysRes.vbs, Cool USEP Scandal.vbs on each drive if present.
Exit the command prompt and reboot normally.

 DISABLE AUTORUN !!!!!!!!!
« Last Edit: July 28, 2008, 01:09:40 PM by mudmanc4 » Logged



Don't do what others say - listen to them, but do what you feel good doing. ~ Warren Buffet
coolbuster
.
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2189


View Profile
« Reply #3 on: July 28, 2008, 06:13:13 PM »

thank you.   smiley

am gonna apply that when I visit her tonight  wink
Logged

.
Print  Pages 1 Go Up
testmy.net Broadband  |  Main Forum  |  PC Security  |  Spyware & Malware  |  Topic: sowar.vbs « previous next »
Jump to:  

    
testmy.net's forum is proudly Powered by SMF | SMF © 2006-2007, Simple Machines LLC
Bookmark: Del.icio.us    StumbleUpon
 
 

 

© 1999-2009 testmy.net - Contact - Legal - Facts & FAQs
Page Loading Stats: This forum Page created in 0.089 seconds with 31 queries.