Got hit by Worm:Win32/Mogoogwi.A or Trojan:Script/Phonzy.A!ml? 😬 Don’t panic — I’ve been there.
In this video I’ll show you how this sneaky malware hides as fake Google Chrome and Mozilla Firefox files, how it spreads through USB drives, and the exact steps to remove it completely using Task Manager, CMD, and Registry Editor.
👉 Watch till the end — you’ll see what happens when AutoIt v3 tries to fight back 😂
Credit to Zarestel Ferrer and securityhome.eu for the malware analysis.
🔧 Quick commands & registry paths (copy-paste)
Run Command Prompt as Administrator before using the commands below.
Delete the fake folder (example):
rmdir /s "C:\GoogleChrome"
rmdir /s "C:\MozillaFirefox"
(When prompted type Y to confirm deletion.)
Open Registry Editor:
Press Windows + R, type regedit, press Enter.
Registry keys to check / remove suspicious entries under:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(look for keys like JavaUpdate, NewJavaInstall → delete suspicious ones)
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
(look for AdopeUpdate, AdopeFlash, GoogleChrome → delete suspicious ones)
Task Manager (stop the running script):
Open Task Manager: Ctrl + Shift + Esc
Go to Startup → disable entries named googlechrome or googleupdate (no space).
Go to Users (expand your user) → kill process AutoIt v3 Script if present.
Final step:
Run a quick scan with Windows Defender (or your AV) and manually check C:\ for leftover .lnk shortcut files.
💻 Fix it. Learn it. Tech smarter with NeofroTech.
If this helped you, drop a like and subscribe.
Learn fast, vibe smart. ✌🏾
#neofrotech #windowsvirus #malwareremoval #pcfix #trojanremoval