1- Go to task manager (Ctrl+Shift+Esc)
- Choose the processes tab, click on any file you see with the name wscript.exe
- Note: There might be more then one. So look carefully and remove them all.
- To remove it just click on it and then click end process
2- right click on my computer and choose open
- Note: DO NOT DOUBLE CLICK to open it!!! that is how this malware gets activated. If you did by mistake, go back to step #1.
- On the top choose tools > folder options.
- Choose the view tap
- Look for show hidden files and folders and choose it.
- Look for Hide protected operating system files and untick it.
- click ok.
3- right click and choose Open on the harddisk which your windows is on. For example C:
- look for 2 files: autorun.inf and ms32dll.vbs
- use Shift+delete to delete them for good.
4- Go start > run and type regedit
-browse for this location: HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows>CurrentVersion>Run
- On the right find ms32dll.vbs
- delete it.
5- check msconfig (to go to it click start > run and type msconfig)
- on the startup tab, look for ms32dll.vbs; if you found it untick it.
6- Go to your windows harddisk, for example C: then enter your windows folder and look directly there for ms32dll.vbs and delete i