Once launched, every second the Trojan scans the system for a process called "explorer.exe". It will then terminate the process.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
- Use Task Manager to terminate a process called "wscript.exe".
- Terminate the "explorer.exe" process.
- Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
- Update your antivirus databases and perform a full scan of the computer (download a trial version of Kaspersky Anti-Virus).
This Trojan has a malicious payload. It is a Visual Basic script. It is 227 bytes in size.
Payload
Subscribe
Hot Articles