Virus File: wincfgs.exe (c: \ windows \ system32 \ wincfgs.exe)
Virus name: Trojanspy. USBpy.
Description: The virus is transmitted through a USB flash drive. an autorun exists in the infected USB flash drive. the inf Automatic Installation File is a folder similar to the recycle bin. There is an autorun.exemaster file and a recycle site icon, both of which are added, and autorun.exe cannot be displayed in windows. You can use the dir/a command in DOS to view the file.
Worker Process.
Symptoms: The Notebook automatically pops up at startup, and the system startup Item is modified. Some software does not respond.
Transmission path: Mobile storage such as USB flash drives
Hazard: no damage at the moment, just jump out of the notepad at startup.
Recommended anti-virus method: manual detection and removal
Related steps:
1. Run Ctl + Alt + Del to open the task manager and end the wincfgs process.
2. Control Panel-Folder option-set to display system files and hidden files.
3. Delete C: \ windows \ KB20060111.exe (the file name may be different and the blue icon is the same as that in Notepad ).
4. Delete C: \ windows \ system32 \ wincfgs.exe (the hidden system file of the yellow question mark icon ).
5. Start-run-regedit-go to Registry Editor-edit-search-Remember to select "items, values, and data" and search for "KB20060111.exe ", delete the found item/value. Press F3 to find the next item and delete the item/value until the search is complete. Similarly, you can search and delete related items/values of ". \ RECYCLER \ autorun.exe" and "wincfgs.exe.
6. In the Registry-[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run], clear boot items related to wincfgs. (Because step 1 has been deleted, if you do not see wincfgs related items, skip this step)
7. Choose "start"> "run"> "msconfig"> "start"> "cancel" wincfgs ">" OK ">" restart ">" restart ", and then ask if ** is displayed for each boot. Select" no. (If you do not see the wincfgs startup Item, skip it)
8. End.
It is best to format the disk