How to clear wincfgs.exe Virus

Source: Internet
Author: User


Virus File: wincfgs.exe (c: \ windows \ system32 \ wincfgs.exe)
Virus name: Trojanspy. USBpy.
Description: The virus is transmitted through a USB flash drive. an autorun exists in the infected USB flash drive. the inf Automatic Installation File is a folder similar to the recycle bin. There is an autorun.exemaster file and a recycle site icon, both of which are added, and autorun.exe cannot be displayed in windows. You can use the dir/a command in DOS to view the file.
Worker Process.
Symptoms: The Notebook automatically pops up at startup, and the system startup Item is modified. Some software does not respond.
Transmission path: Mobile storage such as USB flash drives
Hazard: no damage at the moment, just jump out of the notepad at startup.

Recommended anti-virus method: manual detection and removal
Related steps:
1. Run Ctl + Alt + Del to open the task manager and end the wincfgs process.
2. Control Panel-Folder option-set to display system files and hidden files.
3. Delete C: \ windows \ KB20060111.exe (the file name may be different and the blue icon is the same as that in Notepad ).
4. Delete C: \ windows \ system32 \ wincfgs.exe (the hidden system file of the yellow question mark icon ).
5. Start-run-regedit-go to Registry Editor-edit-search-Remember to select "items, values, and data" and search for "KB20060111.exe ", delete the found item/value. Press F3 to find the next item and delete the item/value until the search is complete. Similarly, you can search and delete related items/values of ". \ RECYCLER \ autorun.exe" and "wincfgs.exe.
6. In the Registry-[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Run], clear boot items related to wincfgs. (Because step 1 has been deleted, if you do not see wincfgs related items, skip this step)
7. Choose "start"> "run"> "msconfig"> "start"> "cancel" wincfgs ">" OK ">" restart ">" restart ", and then ask if ** is displayed for each boot. Select" no. (If you do not see the wincfgs startup Item, skip it)
8. End.

It is best to format the disk

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.