Summary:
This virus enters you computer from an external device (Flash Disk, External HD, Memoery Card). It runs with explorer autoplay. It copies Sys.exe to this folder “c:\Windows\Web\Sys.exe”.
Effects:
1- Disables Windows Task Manager.
2- Disables Windows Command Prompt.
3- Disables Windows Folder Options.
4- Copies itself to all removable media.
Resolution:
Restart your computer.
After restart a message will appear “Noooh.. please try to open task manager” and an OK Button.
Don’t click the OK button.
Open the task manager and this process “Sys.exe”
Click ‘Start‘.
Open ‘My Computer‘.
Select the ‘Tools‘ menu and click ‘Folder Options‘.
Select the ‘View’ tab.
Under the ‘Hidden files and folders‘ heading select ‘Show hidden files and folders‘.
Uncheck the ‘Hide file extensions for known types‘ option.
Uncheck the ‘Hide protected operating system files (recommended)‘ option.
Click Yes to confirm.
Click OK.
Download KillBox,unzip/extract it to your desktop.
Start up Killbox and place a check in ‘Delete on Reboot‘.
In the ‘Full path of file to delete‘ box,copy and paste:
C:\Windows\Web\Sys.exe
Then press the red button with the white cross.
It will then provide a window for you to confirm the delete.
Next it will ask if you now wish to reboot,select YES.
Allow it to reboot.
If it does’nt reboot automatically,reboot manually.
————————————————————————————-
Have Hijack This fix the following by placing a check in the appropriate boxes and selecting ‘Fix checked’.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O4 – HKLM\..\Run: [NoooH] C:\Windows\Web\Sys.exe
Exit Hijackthis,restart your pc,post a new Hijackthis log in your next reply.
| 2.5 |
If you enjoyed this post, make sure you subscribe to my RSS feed!
You Should Also Check Out This Post:
- Keyboard sniffers to steal data!
- Weekend Special - Entrecard Booster
- When I double click on my local drive, I get the open with window!
- Will it blend?
- Fake Homer Simpson email spreading malware
More Active Posts:
- Virus Alert: Sys.exe Noooh (31)
- Noooh Virus AKA W32.Alnuh - Removal Tool (28)
- Free Kaspersky v7.0 one year license key (25)
- I can not open my drive or flash memory, what should I do? (12)
- How I Got 2000 Subscribers in 3 Months (7)
- The perfect virus immunization for your computer – Part 1 - Kaspersky Internet Security (4)
- Simple tip to protect from Autorun.inf viruses (3)
- Malware - Spyware - Adware - Virus - Worm - Definitions and ways to protect (2)
- Could Google Save Yahoo from Microsoft? (2)
- 13 Questions to Ask Before Publishing a Post On Your Blog (2)












My name is Ghiath. I'm 26 years old computer science graduate. I blog for fun. If you find my blog interesting please don't forget to write your comments...
Thanks for the great info, you much think if a post deserves to be one of your blog posts or not