Page 1 of 4 1234 LastLast
Results 1 to 12 of 42

Thread: How to remove new folder exe or regsvr exe or autorun inf virus

  1. #1
    toor_malang is offline Senior Member+
    Last Online
    22nd September 2014 @ 01:08 PM
    Join Date
    05 Dec 2008
    Age
    41
    Posts
    103
    Threads
    29
    Credits
    1,080
    Thanked
    14

    Question How to remove new folder exe or regsvr exe or autorun inf virus

    How to remove new folder exe or regsvr exe or autorun inf virus

    --------------------------------------------------------------------------------

    I want to tell you a story, two days back i got affected by this virus very badly as it eat up all my empty hard disk space of around 700 MB .

    I was surprised that my most reliable friend Avast, for the first time failed me in this war against viruses but then again avg and bitdiffender also failed against it. This virus is know popularly as regsvr.exe virus, or as new folder.exe virus and most people identify this one by seeing autorun.inf file on their pen drives, But trend micro identified it as WORM_DELF.FKZ. It is spreading mostly using pen drives as the medium.

    Well, so here is the story of how i was able to kill the monster and reclaim my hard disk space.

    Manual Process of removal

    I prefer manual process simply because it gives me option to learn new things in the process.

    So let’s start the process off reclaiming the turf that virus took over from us.

    1. Cut The Supply Line

    a. Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option
    b. Open the file in notepad and delete everything and save the file.
    c. Now change the file status back to read only mode so that the virus could not get access again.
    d.
    e. Click start->run and type msconfig and click ok
    f. Go to startup tab look for regsvr and uncheck the option click OK.
    g. Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.
    h. Now go to control panel -> scheduled tasks, and delete the At1 task listed their.

    2. Open The Gates Of Castle
    a. Click on start -> run and type gpedit.msc and click Ok.
    b.
    c. If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.

    d. Go to users configuration->Administrative templates->system
    e. Find “prevent access to registry editing tools” and change the option to disable.
    f.
    g. Once you do this you have registry access back.
    3. Launch The Attack At Heart Of Castle
    a. Click on start->run and type regedit and click ok
    b. Go to edit->find and start the search for regsvr.exe,
    c.
    d. Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.
    e. At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe

    4. Seek And Destroy the enemy soldiers, no one should be left behind
    a. Click on start->search->for files and folders.
    b. Their click all files and folders
    c. Type “*.exe” as filename to search for
    d. Click on ‘when was it modified ‘ option and select the specify date option
    e. Type from date as 1/31/2008 and also type To date as 1/31/2008
    f.
    g. Now hit search and wait for all the exe’s to show up.
    h. Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 31st January.
    i. Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.
    j. Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)

    5. Time For Celebrations
    1. Now do a cold reboot (ie press the reboot button instead) and you are done.
    I hope this information helps you win your own battle against this virus. Soon all antivirus programs will be able to automatically detect and clean this virus. Also i hope Avast finds a way to solve this issues.
    As a side note i have found a little back dog( winpatrol ) that used to work perfectly on my old system. It was not their in my new PC, I have installed it again , as I want to stay ahead by forever closing the supply line of these virus. You can download it form Winpatrol website.

    Please do reply if it works and u like my Post

  2. #2
    starwaker is offline Senior Member+
    Last Online
    12th April 2018 @ 01:23 PM
    Join Date
    08 May 2009
    Age
    38
    Posts
    67
    Threads
    2
    Credits
    1,053
    Thanked: 1

    Default

    zuberdust jinab very informative

  3. #3
    koiaya's Avatar
    koiaya is offline Advance Member
    Last Online
    15th May 2020 @ 01:00 PM
    Join Date
    02 Mar 2006
    Posts
    1,624
    Threads
    20
    Credits
    88
    Thanked
    94

    Default

    Nice info thanks

  4. #4
    *ESHA*'s Avatar
    *ESHA* is offline Advance Member+
    Last Online
    15th December 2019 @ 12:01 PM
    Join Date
    29 Mar 2009
    Location
    Islamabad
    Age
    32
    Gender
    Female
    Posts
    10,158
    Threads
    536
    Credits
    78
    Thanked
    164

    Default

    اسکو اردو میں لکھھ کے بھیجو

  5. #5
    Trainerinit's Avatar
    Trainerinit is offline Advance Member
    Last Online
    31st October 2021 @ 07:45 PM
    Join Date
    12 Mar 2010
    Location
    Karachi, Pakistan. - PKT
    Age
    39
    Gender
    Male
    Posts
    5,159
    Threads
    170
    Credits
    315
    Thanked
    278

    Default

    nice

  6. #6
    noker_ghazi_da is offline Senior Member+
    Last Online
    6th July 2017 @ 02:37 PM
    Join Date
    16 Jun 2010
    Posts
    602
    Threads
    19
    Credits
    57
    Thanked
    14

    Default thanks

    beautiful sharing

  7. #7
    M Adnan Ahmad is offline Senior Member+
    Last Online
    26th January 2018 @ 08:23 PM
    Join Date
    12 Jan 2010
    Age
    36
    Gender
    Male
    Posts
    454
    Threads
    17
    Credits
    0
    Thanked
    26

    Default

    Nice sharing.......

  8. #8
    awaisshahid1 is offline Senior Member+
    Last Online
    9th January 2018 @ 01:39 PM
    Join Date
    06 Nov 2008
    Age
    32
    Posts
    179
    Threads
    58
    Credits
    1
    Thanked
    3

    Default

    very nice sharing bro

  9. #9
    Abdulwahid is offline Advance Member
    Last Online
    7th December 2020 @ 05:56 PM
    Join Date
    17 Nov 2008
    Location
    Gujranwala
    Age
    47
    Posts
    4,135
    Threads
    10
    Credits
    1,346
    Thanked
    187

    Default

    Nice Sharing..........

  10. #10
    sanabal's Avatar
    sanabal is offline Senior Member+
    Last Online
    27th October 2011 @ 02:32 PM
    Join Date
    12 Jun 2010
    Age
    35
    Posts
    164
    Threads
    0
    Credits
    690
    Thanked
    6

    Default

    Nice

  11. #11
    Safoo is offline Senior Member+
    Last Online
    7th August 2019 @ 04:11 PM
    Join Date
    26 May 2010
    Location
    Faisalabad
    Posts
    68
    Threads
    3
    Credits
    6
    Thanked
    3

    Default

    bohot hee aalaaa i was finding this i needed it... lets try

  12. #12
    pk_khan is offline Senior Member+
    Last Online
    14th October 2022 @ 02:51 PM
    Join Date
    19 Jun 2010
    Location
    Peshawar
    Age
    31
    Gender
    Male
    Posts
    516
    Threads
    13
    Credits
    4
    Thanked
    25

    Default

    weldone yar i was also need this .

Page 1 of 4 1234 LastLast

Similar Threads

  1. Remove USB Virus & Autorun Files
    By QADGHAN in forum Tips and Tricks
    Replies: 78
    Last Post: 31st October 2014, 09:44 AM
  2. Replies: 58
    Last Post: 15th October 2014, 07:59 PM
  3. Autorun.Virus.Remove
    By A_R_MANI..... in forum General Discussion
    Replies: 41
    Last Post: 20th October 2012, 03:10 PM
  4. Remove Autorun.inf Virus
    By ITPROFESSIONAL in forum General Discussion
    Replies: 26
    Last Post: 29th June 2011, 02:58 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •