Every time you turn on, a blank Notepad pops up (but the Msconfig startup entry is run, and the Notepad is not prompted to load). Although not much influence, but the feeling must be a problem. When my mobile hard disk (or USB drive) is plugged into a USB port, a blank Notepad will also pop up when I click on the letter. Subsequently, rising registry monitoring program will be modified to "Hkey_current_user\software\microsoft\windows\shellnoroam\muicache" inside the
"C:\windows\system32\wincfgs.exe".
A desktop.ini is generated below each disk root (some of the mobile devices create Autorun.inf).
Workaround:
1. Batch Removal Registry modifications:
Copy the following text to Notepad, save as "Wincfgs_kill.bat" (Note that when you save, select the file type is "All Files")
Copy Code code as follows:
echo off
Tskill KB20060111
Tskill WINCFGS
Del%windir%\kb20060111.exe
Del%windir%\system32\wincfgs.exe
reg delete "hkey_current_user\software\microsoft\windowsnt\currentversion\
Windows/V "load"/F
REG ADD "hkey_current_user\software\microsoft\windowsnt\currentversion\
Windows "/V" load "/t reg_sz/d" "/F
2. Mobile device Solutions (for example, USB flash drive):
After the USB connection is good, open My Computer, click the right button to open (do not directly click on Open or Point "open"), and then open the menu bar "Tools"-> "Folder Options"-> "View", remove the "Hide protected system files (recommended)" before the tick. Remove the Desktop.ini,wincfgs.exe and Autorun.inf from the USB flash drive. Manually remove the Desktop.ini,wincfgs.exe and Autorun.inf files under each letter of the hard drive.
Another kind of manual solution
Transmission channels: U disk, such as mobile storage.
Harmfulness: No destructive, just boot out of Notepad, anti-virus software can not detect the virus.
Manual removal Method:
Use Task Manager or Trojan kill or HijackThis to end wincfgs process, delete C:\WINDOWS\KB20060111.exe (maybe the filename is different, and the blue icon like Notepad), and C:\windows\system32\ Wincfgs.exe (hidden system file with yellow question mark icon).
Start-run-regedit, enter registry, search registry to delete Wincfgs.exe. For example, delete the following key/subkey from the registry: No, of course not.!!!
Hkey_current_user\software\microsoft\windows\shellnoroam\muicache
C:\WINDOWS\KB20060111.exec
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\msconfig\startupreg\load=b*dzs
Run Msconfig again or clean the boot up item in the [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] entry.