This IS a Virus...

NOT ALL PAGES ARE CONVERTED TO CELL PHONE FORMAT!

Home     Sitemap

www.diy-computer-repair.net logo

WMPSCFGS.exe a Nasty Virus

This virus wmpscfgs.exe will drive you crazy... Skip the craziness and use your back up image...

What it is and how it works.

I downloaded a program a couple of weeks ago to test and evaluate for this web site.

Well the program was cripple ware and not worth the money the publisher wanted me to pay for it. I might do an article on it at some future date.

What I got in addition to the program was one of the worst virus I have ever came across.

Although the program package was infected with the virus if you DON'T read the pdf document in the package you will not get the virus because the virus in in the Adobe Reader that comes with the package. The virus is activated by reading the pdf. Very devious.

What makes this virus so bad is the persistence that it has in replicating itself and the devious way it hides.

The name of the virus is wmpscfgs.exe, and the only program that I use (of the top ten AV programs) that found it was Trojan Remover by Simply Super Software Unfortunately it could not clean out all the infections as you will see later on in this article.

What it does:

  • It replicates it self by renaming a running program then names itself as the executable. It uses programs in the registry that are in the Run keys for the System and the User.
  • It uses either Windows Internet Explorer or Firefox browser to contact it's home base.
  • It sets up a schedule task to open the browser in the background to transmit the data it has stolen.
  • You will find it in your temp directories and in the browser directory.
  • You will also find it in this key in the registry: HKLM\SOFTWARE\Microsoft\Windows\
    CurrentVersion\Run\"Adobe_Reader"

You need this in your IT Tool Box! Get yours today...

Troubleshoot, repair, maintain, upgrade & secure...

    With this!


To see the virus check your run keys then go to each folder and look at the names of the executable, there will be two or more of them, the virus will be the first executable, then the executable will be the same name with a space between the name and the period before the file extension such as:

desktops.exe

desktops .exe

desktops  .exe

With the Task Manager look at the Running Processes, if you see two of the same executable and one or more has a space or spaces between the end of the executable name and the period then your computer is infected.

After Trojan Remover cleaned the infection and a restart the virus was still there.

You can try to eradicate the virus but after two tries I just put a clean image back on my computer.

If you want to try cleaning the virus this page has the instructions:

how-to-get-rid-of-the-wmpscfgs.exe-
virus-a-reader-contributed-guide

This little exercise proves three things:

  • Backup your data and make an image of your system drive
  • Keep your AV up to date
  • Keep an eye on the Task Manage for anomalies if you download programs to test.

Better still I should take my own advice about viruses such as the  wmpscfgs.exe and run these programs in a VM! (Virtual Machine)

You will find more information and techniques on cleaning viruses in the Self Computer Repair Unleashed! 2nd Edition Manual...



Emergency Repair
D
isk (ERD) - Will Yours Work?

Emergency
Repair Disk


Custom made for you...



You keyboard isn't thirsty, and it doesn't need calcium. Milk and other liquids will ruin a keyaboard!


This Web
Site is a
labor of Love
!
But Love
doesn't pay
the bills!

Please chip in $5 to keep it live...

Need A Checklist?

Need A Repair Manual?


    Page copy protected against web site content infringement by Copyscape
 

You can:


Return to
previous page:



 

 

 

 


Thank you for visiting my web site, and please come back again.

This website is not intended for children under the age of 18

Author of this web site: Monte Russell


FTC Endorsement Rules
All testimonials on the DIY Computer Repair web site are from customers who were not paid to comment on any products!


The Flag of The United States of America!   Proudly Made in The U. S. A.

Copyright and Registered to www.diy-computer-repair.net, all thieves will be prosecuted to the fullest extent of international law!www.diy-computer-repair.net

From the Desert South West ~ Arizona, U. S. A.
Copyright DIY-Computer-Repair.Com 2006-2016

 

"You found this web site through:"

Active Search Results


Return to top of wmpscfgs.exe

The wmpscfgs.exe one of the hardest viruses I have yet to clean, forget it and either put your image on the partition or reload the Operating System...





Home    About    Sitemap
Fix It Blog!

From the Desert South West ~ Arizona, USA
Copyright www.diy-computer-repair.net 2006-2015