How to remove Trojan.VBS.Autorun.J
THREAT NAME
Trojan.VBS.Autorun.J
CLEAN INSTRUCTIONS
1. Restart the system in Safe Mode.
2. Open Windows Explorer, go to C:\Windows\System32\ and delete the winini.vbs file.
3. Go to Start, Run type regedit and press OK.
4. Locate and delete the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, Winini.dll
5. Run a full system scan with BullGuard.
SYMPTOMS
1. Computer slowdown.
2. A fake message informs you that an email has been received and copied to the Desktop.
DESCRIPTION
1. When run, it will create the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, Winini.dll
2. It will drop a file named winini.vbs in the C:\Windows\System32\ folder. This is recognized as
Trojan.VBS.StartPage.BK
This file will be executed the next time the computer starts.
Author:
The BullGuard Team