VBS.Sorry.A - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: December 20, 2000
Updated: February 13, 2007 11:59:30 AM
Type: Worm


To repair damage done by the worm, you need to complete the following tasks:
  • Delete all files that Norton AntiVirus (NAV) detects as infected by VBS.Sorry.A.
  • Restore the Internet Explorer Start Page if desired.
  • Delete or the registry entries made by the worm.

Please refer to the appropriate sections for instructions on complete each task.

To delete the infected files:
  1. Run LiveUpdate to make sure that you have the most recent virus definitions.
  2. Start NAV and run a full system scan. Unless you are using NAV 2001, make sure that NAV is set to scan all files.
  3. Delete any files that are detected as infected with VBS.Sorry.A.

To restore the Internet Explorer Start Page:
  1. Start Internet Explorer, and go the Web page that you want to set as your home page.
  2. Click Tools, and then click Internet Options.
  3. In the Home page section of the General tab, click "Use Current."

To remove the registry entries made by the worm:
    CAUTION: We strongly recommend that you back up the system registry before making any changes to it. Incorrect changes to the registry may result in permanent data loss or corrupted files. Be sure to modify the specified keys only. See the document How to back up the Windows registry before proceeding.
  1. Click Start, and then click Run. The Run dialog box appears.
  2. Type regedit and then click OK. The Registry Editor opens.
  3. Browse to and select the following subkey:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
  4. In the right pane, locate and delete the following value:

    tfload = wscript.exe windows\fonts\ttfload.vbs
  5. Browse to and select the following subkey:

    HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
  6. In the right pane, locate and delete the following value:

    Timeout = 0
  7. Close the Registry Editor.


Writeup By: Brian Ewell
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security