How can I get rid of it?
1. First download process explorer ,run it and end all the process which are running as wscript.exe
2. Download RRT.exe (Remove restrictions tool) . RRT (Remove Restrictions Tool) v.2.0 is a tiny tool that does the work for AVs, it re-Enables all what the virus had disabled, and brings every thing including task manager ,regedit ,msconfig and hidden folder options back.
3. Now, you have regedit command enabled.
Browse to Go to HKEY_LOCAL_MACHINE \Software \Microsoft \Windows \Current Version \Run and delete MS32DLL (right click on it and select delete)
Go to HKEY_CURRENT_USER \Software \Microsoft \Internet Explorer \Main and delete “Window Title” which has it’s value of “Hacked by Godzilla“ or you can also write your name as a recognition for yourself.
4. Open My Computer,File menu go to Tools -> Folder Options, click on View tab
- Under Advance settings,
- check “Show Hidden files and folders“,
- uncheck “Hide extensions for known file types“,
- uncheck “Hide protected operating system files (Recommended)”
- and click “OK” button
5. Now right click on each of your drive and click explore now delete the files with names autorun.inf and MS32DLL.dll.vbs including your USB Drive
Related Posts :
- Enable Show Hidden Files Option
- Remove AUTORUN.INF from infected computers
- How to remove Funny UST Scandal.avi.exe Virus