<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>am i works? &#187; Vrius Removal</title>
	<atom:link href="http://amiworks.co.in/talk/category/vrius-removal/feed/" rel="self" type="application/rss+xml" />
	<link>http://amiworks.co.in/talk</link>
	<description>all about my work</description>
	<lastBuildDate>Fri, 02 Dec 2011 09:49:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>How To Install Group Policy Editor</title>
		<link>http://amiworks.co.in/talk/gpeditmsc-missing/</link>
		<comments>http://amiworks.co.in/talk/gpeditmsc-missing/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 06:11:05 +0000</pubDate>
		<dc:creator>Amit Kumar Singh</dc:creator>
				<category><![CDATA[Vrius Removal]]></category>
		<category><![CDATA[find gpedit.msc]]></category>
		<category><![CDATA[gpedit.msc]]></category>
		<category><![CDATA[group policy editor]]></category>

		<guid isPermaLink="false">http://amiworks.co.in/talk/gpeditmsc-missing/</guid>
		<description><![CDATA[Since I started publishing my manual virus removal series lot&#8217;s of people asked me where about Group Policy Editor. For example In &#8220;How to remove antivirus XP 2008&#8220;  MK asked when i go to start run gpedit.msc my computer says windows can not find it ??? So I thought instead of replying to in the [...]]]></description>
			<content:encoded><![CDATA[<p>Since I started publishing my manual virus removal series lot&#8217;s of people asked me where about Group Policy Editor.</p>
<p>For example In &#8220;<a href="http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/">How to remove antivirus XP 2008</a>&#8220;  MK asked</p>
<blockquote><p>when i go to start run gpedit.msc my computer says windows can not find it ???</p></blockquote>
<p>So I thought instead of replying to in the comments itself I will post the solution here and refer everyone to this post <img src='http://amiworks.co.in/talk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>As I had already mentioned in my first <a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/">newfolder.exe virus removal</a> article you can download the <a href="http://bogdan.org.ua/2007/11/15/windows-xp-he-home-edition-gpedit-msc-group-policy-editing-via-registry.html">french version of gpedit.msc from bogdan.org.ua</a>.</p>
<p>Once you download it you can install it as follows. I am quoting directly from that article itself</p>
<blockquote><p>However, here are some short instructions in English for manual MMC snap-in installation (batch file from the archive does everything automatically, but you’ll have to edit-verify the batch file first):</p>
<p>* put these files: (appmgmts.dll, appmgr.dll, fde.dll, fdeploy.dll, gpedit.msc, gpedit.dll, gptext.dll) into %SystemRoot%\system32\ folder</p>
<p>* put these files: (system.adm, inetres.adm, conf.adm) into %SystemRoot%\system32\GroupPolicy\Adm\ (create if this folder doesn’t exist)</p>
<p>* finally, run these commands one by one in the CMD window:</p>
<p>regsvr32 gpedit.dll<br />
regsvr32 fde.dll<br />
regsvr32 gptext.dll<br />
regsvr32 appmgr.dll<br />
regsvr32 fdeploy.dll</p>
<p>That should do it.</p></blockquote>
<p>You should <a href="http://bogdan.org.ua/2007/11/15/windows-xp-he-home-edition-gpedit-msc-group-policy-editing-via-registry.html">read the article at Bogdan</a> for more detailed instructions.</p>
<p>As for french, most of the articles that I have written I have attached the image that shows the exact line that needs to be modified, you can use them as reference.</p>
<p>I hope this will help you install the gpedit.msc on your system.</p>
<!-- WP Boastful Plugin by WPoets Team --> <div id='boastful'><strong></strong></div><hr style="border-top:black solid 1px" /><a href="http://amiworks.co.in/talk/gpeditmsc-missing/">How To Install Group Policy Editor</a> was first posted on July 26, 2008 at 6:11 am.<br />©2008 "<a href="http://amiworks.co.in/talk">am i works?</a>". <br />]]></content:encoded>
			<wfw:commentRss>http://amiworks.co.in/talk/gpeditmsc-missing/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>How to Remove Antivirus XP 2008</title>
		<link>http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/</link>
		<comments>http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 04:37:32 +0000</pubDate>
		<dc:creator>Amit Kumar Singh</dc:creator>
				<category><![CDATA[how too?]]></category>
		<category><![CDATA[Vrius Removal]]></category>
		<category><![CDATA[Antivirus XP 2008]]></category>
		<category><![CDATA[clean antivirus xp 2008]]></category>
		<category><![CDATA[remove rootkit virus]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[Simple Instructions For Virus Removal(cleaning)]]></category>
		<category><![CDATA[uninstall antivirus 2008]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/</guid>
		<description><![CDATA[I hate these spywares, they keep finding ways to sneak into my system every now and then. Earlier it was &#8220;New Folder.exe&#8221; and then these other irritating viruses, and now Antivirus XP 2008. Thanks god this time my Avast was able to detect the virus and delete it. But the real problem was, the moment [...]]]></description>
			<content:encoded><![CDATA[<p>I hate these spywares, they keep finding ways to sneak into my system every now and then.</p>
<p>Earlier it was &#8220;<a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/" title="remove newfolder.exe and regsvr.exe virus">New Folder.exe</a>&#8221; and then these other <a href="http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/" title="regedit automatically closes">irritating viruses</a>, and now Antivirus XP 2008.</p>
<p>Thanks god this time my Avast was able to detect the virus and delete it. But the real problem was, the moment this <em>rootkit</em>  virus was detected and deleted, Antivirus XP would again install this rootkit virus.</p>
<p><a href="http://www.flickr.com/photos/thecancerus/2678476421" title="Antivirus XP 2008 wallpaper"><img src="http://farm4.static.flickr.com/3035/2678476421_d80f0a0d87.jpg" alt="Antivirus XP 2008 wallpaper" /></a></p>
<p>Initially I thought that a boot time scan would be sufficient to remove this virus from my system, though it does not turned out that effective even though Avast removed more then 240 infected files.</p>
<p>The reason turned out to be Antivirus XP 2008, it was running at boot time resulting in re-infection.</p>
<p>So I finally had to get into action, to take back the control of my PC.</p>
<p><a href="http://www.flickr.com/photos/thecancerus/2679293950" title="Antivirus XP 2008 GUI"><img src="http://farm3.static.flickr.com/2045/2679293950_96c47837e5.jpg" alt="Antivirus XP 2008 GUI" /></a></p>
<p>Here is step by step account of what I did(remember all this was done immediately after boot-time scan by Avast) to uninstall and remove it from my PC.</p>
<p><span id="more-140"></span></p>
<h3>Step 1: Open Task Manager And End The Infecting Processes</h3>
<p>Right click on the task bar and select the task manager, go to processes tab and end following process if found running(please note down the path)</p>
<ul>
<li>lphc9u2j0ejde.exe, and</li>
<li>rhccu2j0ejde.exe (this is the process for antivirus xp software)</li>
</ul>
<p>please not the actually name in you list may very, so you may want to kill any process name starting with <em>lphc or rhc. </em>Just remember even if you make mistake by closing wrong process you can always restart you system.</p>
<h3>Step 2: Delete The Infecting Programs</h3>
<p>Find the files whose process you just closed(&amp; path noted above), and either rename them or delete them.</p>
<p>They are usually found at following locations</p>
<ul>
<li>C:\windows\system32\lphc9u2j0ejde.exe,</li>
<li>c:\windows\system32\blphc9u2j0ejde.scr, (updated on 28th july) and</li>
<li>C:\program files\rhc75dj0e1an\rhccu2j0ejde.exe</li>
</ul>
<p>Once you delete these two files you effectively removed the virus, but now we have to remove the side effects.</p>
<p>(update 8 august 2008) it is worth highlighting comment made by Jim, thanks Jim.</p>
<blockquote><p> <span id="comment_content_1197">In order to avoid the problem with french I had my brother email me the english gpedit files from his computer. In addition to the files you indicated to delete from task manager I also found pphc5u2j0ejde.exe, so anyone doing this should look for files similar in nature. the <strong>jOejde.exe part on the end is the same</strong> but the beginning may be different</span></p></blockquote>
<h3>Step 3: Open msconfig To Clean Start Programs</h3>
<p>Click &#8216;start&#8217;-&gt;run and type &#8216;msconfig&#8217; in run window. This will open system configuration utility. If you get any warning or the msconfig window closes automatically then you should check out &#8220;<a href="http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/" title="How to stop regedit, taskmanager or msconfig from closing automatically">How to stop regedit, taskmanager or msconfig from closing automatically</a>&#8220;.</p>
<p>Click on startup Tab, and uncheck the boxes in front of &#8220;<em>lphc and rhc</em>&#8221; files as shown in figure, and click apply.</p>
<p><a href="http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/system-configuration-utility/" rel="attachment wp-att-127" title="system configuration utility"><img src="http://amiworks.co.in/talk/wp-content/antivirusxp2008_3.thumbnail.png" alt="system configuration utility" width="179" height="135" /></a></p>
<p>Let&#8217;s now do a cold boot of the system(basically press the reset button on your PC). Wait for computer to boot again.</p>
<p><a href="http://www.flickr.com/photos/thecancerus/2678476577" title="Antivirus XP 2008 hides deskotp tab"><img src="http://farm4.static.flickr.com/3140/2678476577_cbbcfdc89e.jpg" alt="Antivirus XP 2008 hides deskotp tab" /></a></p>
<h4>Step 4: Change Group Policy To Restore Wallpaper</h4>
<p>Click &#8216;start&#8217;-&gt;run and type &#8216;gpedit.msc&#8217; in run window. This will open Group policy.</p>
<p>Now navigate to User configuration -&gt; Administrative Templates -&gt;Control Panel-&gt; Display.</p>
<p><a href="http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/change-group-policy-to-restore-wallpaper/" rel="attachment wp-att-126" title="Change Group Policy To Restore Wallpaper"><img src="http://amiworks.co.in/talk/wp-content/7172008_101855-pm.thumbnail.jpg" alt="Change Group Policy To Restore Wallpaper" width="234" height="161" /></a></p>
<p>Finally double click on following items to open properties window and change the setting to disabled.</p>
<ol>
<li>Remove Display in Control Panel</li>
<li>Hide Desktop Tab</li>
<li>Prevent changing wallpaper</li>
<li>Hide Appearance and Themes tab</li>
<li>Hide Settings tab</li>
<li>Hide Screen Saver tab</li>
</ol>
<p>Check the picture above for more detailed view.</p>
<p>This will allow you to change the wallpaper back to normal.</p>
<p>Please also check the alternative suggested by <strong>itzel</strong> in comments below, in case you don&#8217;t have gpedit on your system.</p>
<p>(Update 5th step added on 28th July)</p>
<h3>Step 5 : Change Screen Saver</h3>
<p>You will need to change the screen saver from &#8220;blphc9u2j0ejde&#8221; to something else.</p>
<p>updated on 9-august-2008</p>
<p><object type="application/x-shockwave-flash" style="width:425px; height:355px;" data="http://www.youtube.com/v/mqOZLLp-S3k&amp;rel=0&amp;color1=0x2b405b&amp;color2=0x6b8ab6"><param name="movie" value="http://www.youtube.com/v/mqOZLLp-S3k&amp;rel=0&amp;color1=0x2b405b&amp;color2=0x6b8ab6" /></object></p>
<p>Video of screensaver that is installed by Antivirus xp 2008.</p>
<p>After this attack I have decided to install a dedicated Anti-Spyware program. After looking through bunch of them, I have finally settled for <a href="http://www.kqzyfj.com/click-2891866-10540041?url=http%3A%2F%2Fwww.pctools.com%2Fspyware-doctor%2Fpurchase%2F&amp;cjsku=Spyware+Doctor" target="_top"><br />
Spyware Doctor</a><br />
<img src="http://www.tqlkg.com/image-2891866-10540041" width="1" border="0" height="1" />.</p>
<p>I think it is good idea to have one, on your system.</p>
<!-- WP Boastful Plugin by WPoets Team --> <div id='boastful'><strong></strong></div><hr style="border-top:black solid 1px" /><a href="http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/">How to Remove Antivirus XP 2008</a> was first posted on July 18, 2008 at 4:37 am.<br />©2008 "<a href="http://amiworks.co.in/talk">am i works?</a>". <br />]]></content:encoded>
			<wfw:commentRss>http://amiworks.co.in/talk/how-to-remove-antivirus-xp-2008/feed/</wfw:commentRss>
		<slash:comments>191</slash:comments>
		</item>
		<item>
		<title>How to stop regedit, taskmanager or msconfig from closing automatically</title>
		<link>http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/</link>
		<comments>http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/#comments</comments>
		<pubDate>Tue, 29 Apr 2008 13:33:04 +0000</pubDate>
		<dc:creator>Amit Kumar Singh</dc:creator>
				<category><![CDATA[how too?]]></category>
		<category><![CDATA[Vrius Removal]]></category>
		<category><![CDATA[msconfig]]></category>
		<category><![CDATA[msconfig closing automatically]]></category>
		<category><![CDATA[regedit]]></category>
		<category><![CDATA[regedit closing automaticaly]]></category>
		<category><![CDATA[task manager closing automatically]]></category>
		<category><![CDATA[taskmanager]]></category>

		<guid isPermaLink="false">http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/</guid>
		<description><![CDATA[Since i published my &#8220;How to remove new folder exe or regsvr exe or autorun inf virus&#8221; article many readers have asked me about how to prevent regedit, taskmanger, msconfig etc from closing withing second of it&#8217;s opening. Now i have to say as i have yet to face this issue personally myself, i am [...]]]></description>
			<content:encoded><![CDATA[<p>Since i  published my &#8220;<a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/" title="How to remove new folder exe or regsvr exe or autorun inf virus">How to remove new folder exe or regsvr exe or autorun inf virus</a>&#8221; article many readers have asked me about how to prevent regedit, taskmanger, msconfig etc from closing withing second of it&#8217;s opening.</p>
<p>Now i have to say as i have yet to face this issue personally myself, i am not really able to suggest anything but to recommend people to do a boot time scan from  avast, and hope that fixes their problem.</p>
<p>But after receiving a repeated request to fix this issue, i decided to write about the approach that i would take if i face this problem and  to collaborate with you to solve your problem and in the process create a workable solution to fix this problem, once and for all.</p>
<p><strong>Symptoms</strong> of the problem that we are tying to solve,</p>
<ol>
<li>you open regedit, the regedit window flickers and closes again,</li>
<li>you open taskmanager, window opens and immediately closes.</li>
<li>you try to open msconfig, window closes the moment it opens.</li>
</ol>
<p><span id="more-75"></span></p>
<p><strong>What might be happening?</strong></p>
<p>My thinking is that some rouge process is running that is scanning for these applications and the moment they open, it closes them.</p>
<p><strong>Our Aim : to identify and kill</strong></p>
<p>so what we need to do is, identify these rouge programs and destroy them by first killing the running process and then deleting the actual application from the system. We need to do this to prevent them from running again.<br />
So first let&#8217;s try this solution,</p>
<ol>
<li>Create the copy of regedit.exe file and put it in another directory.
<ol>
<li>you can do this by selecting the regedit.exe file(located in c:\windows directory) and pressing <strong>crtl+c</strong>  and then <strong>crtl+v</strong></li>
<li>move this copied file to another new directory say c:\eme_utils</li>
</ol>
</li>
<li>Similarly create the copy of task manager located at (C:\WINDOWS\system32\taskmgr.exe) and system configuration utility aka msconfig located at (C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe)</li>
<li>Now run these copies by clicking them, to see if you can access the respective applications.</li>
</ol>
<p>if you don&#8217;t want to do this manually you may want to download the <code><a class="downloadlink" href="http://amiworks.co.in/talk/wp-content/plugins/download-monitor/download.php?id=3" title=" downloaded 5385 times" >xp_emergency tool</a></code>  which does this for you in Windows XP OS.</p>
<p>With this hopefully we may have bypassed the restrictions imposed by the virus or worm or any rouge application, we still need to identify and kill them so that we can leave in peace instead of using alternative solutions.</p>
<p><strong>So let&#8217;s start the identification process</strong>,</p>
<p>just a warning, this is a repetitive and frustrating process but if you really want to use the taskmanger, regedit or msconfig then you will have to find the process and kill it, so let&#8217;s start the journey.</p>
<p>you will need to download <code><a class="downloadlink" href="http://amiworks.co.in/talk/wp-content/plugins/download-monitor/download.php?id=4" title=" downloaded 6737 times" >Process Explorer</a></code> from system internals, so that we can identify the culprit process.</p>
<p>once you have downloaded it, extract the zip file and run the procexp.exe file by double clicking it. This will show you all the processes running right now.</p>
<p align="center"><a href="http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/process-explorer/" rel="attachment wp-att-73" title="Process Explorer"><img src="http://amiworks.co.in/talk/wp-content/process-explorer.thumbnail.jpg" alt="Process Explorer" /></a></p>
<p>From here onwards you are almost on your own, you will have to trust your own knowledge of your system and your intuition.  What we now need to do is to kill the processes that you can&#8217;t identify.</p>
<p><strong>Note</strong> : before making any changes please keep a screen shot or write down the changes that you are doing.</p>
<ol>
<li>Look for any process that you can&#8217;t identify the source. as you can see from this image&lt;image above&gt;   process explorer  gives the description and company name of all the  process that are running.  so the first targets would be the application that you can&#8217;t identify the company name or application that you might not have installed.</li>
<li>Once you think a process as rouge, note down the path of that application(this will help you delete the file later) by right clicking the name and clicking on properties window in the pop up.</li>
<li><a href="http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/pop-up-option/" rel="attachment wp-att-74" title="pop up option"><img src="http://amiworks.co.in/talk/wp-content/properties_killprocess.thumbnail.jpg" alt="pop up option" /></a>   <a href="http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/properties-window-of-process-explorer/" rel="attachment wp-att-72" title="properties window of process explorer"><img src="http://amiworks.co.in/talk/wp-content/path_notedown.thumbnail.jpg" alt="properties window of process explorer" /></a></li>
<li>Now kill the process tree by right clicking and choosing the kill process tree option &lt;image&gt;</li>
<li>It is the time now to check if we have killed the right process or not, do find that out simply run the regedit or taskmanger or msconfig and see if they stay opened. if they do, move on to next step otherwise get back to step 1.</li>
</ol>
<p>Worst that can happen at this stage is that you might kill some important process,  in that case you have to just restart the system and you will be back from where you started.</p>
<ol start="6">
<li>Once you have identified the process, we will now rename this application by changing the extension to something like *.fix or any thing you like by going to the path that we noted above. We did not delete the file at this stage because we want to be sure that this is the culprit file and not some other file.</li>
<li> To verify this just restart you system and see if you can still access the regedit, task manger or msconfig, if you can then you want to delete the file that we renamed above.</li>
<li> If not then we will have to start the identification process again, so start from step 1.</li>
</ol>
<p>Here are some of the known rouge process  that are know to do such things</p>
<ul>
<li>WebRebates0.exe</li>
<li>WebRebates1.exe</li>
<li>msconfig35.exe</li>
<li>msconfig45.exe</li>
<li>funny ust scandal.avi.exe,</li>
<li>SMSS.exe ( an important windows process, Session Manager Subsystem, of same name also exists so be very careful before killing it.)</li>
<li>Killer.exe</li>
</ul>
<p>If you fear, or, are not able to identify the process in that case you may want to save the process explorer output in a text file by hitting <strong>crtl+s</strong> and post the output in comment below so that I or others who have faced the problem will try to help you identify the rouge process to kill.</p>
<p>I am interested in knowing if this process helped you or not,  It will be really good if you can participate in this process and leave a note below about all the rouge process or application that you identified.</p>
<p>This will help others to solve their problem as you might have already noticed their is very little help out their regarding this problem.</p>
<!-- WP Boastful Plugin by WPoets Team --> <div id='boastful'><strong></strong></div><hr style="border-top:black solid 1px" /><a href="http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/">How to stop regedit, taskmanager or msconfig from closing automatically</a> was first posted on April 29, 2008 at 1:33 pm.<br />©2008 "<a href="http://amiworks.co.in/talk">am i works?</a>". <br />]]></content:encoded>
			<wfw:commentRss>http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/feed/</wfw:commentRss>
		<slash:comments>52</slash:comments>
		</item>
		<item>
		<title>How to remove new folder exe or regsvr exe or autorun inf virus</title>
		<link>http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/</link>
		<comments>http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/#comments</comments>
		<pubDate>Sat, 29 Mar 2008 12:45:39 +0000</pubDate>
		<dc:creator>Amit Kumar Singh</dc:creator>
				<category><![CDATA[how too?]]></category>
		<category><![CDATA[Vrius Removal]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[new folder .exe]]></category>
		<category><![CDATA[regsvr.exe]]></category>
		<category><![CDATA[virus  removal]]></category>

		<guid isPermaLink="false">http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/</guid>
		<description><![CDATA[I want to tell you a story, two days back i got affected by this virus very badly as it eat up all my empty hard disk space of around 700 MB . I was surprised that my most reliable friend Avast, for the first time failed me in this war against viruses but then [...]]]></description>
			<content:encoded><![CDATA[<p>I want to tell you a story, two days back i got affected by this virus very badly as it eat up all my empty hard disk space of around 700 MB  <img src='http://amiworks.co.in/talk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  .</p>
<p>I was surprised that my most reliable friend <a title="Avast Antivirus" href="http://avast.com">Avast</a>, for the first time failed me in this war against viruses but then again avg and bitdiffender also failed against it. This virus is know  popularly as regsvr.exe virus, or as new folder.exe virus and most people identify this one by seeing autorun.inf file on their pen drives, But trend micro identified it as <a title="worm_delf" href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDELF%2EFKZ&amp;VSect=Sn">WORM_DELF.FKZ</a>.  It is spreading mostly using pen drives as the medium.</p>
<p align="center"><img src="http://amiworks.co.in/talk/wp-content/newfolder-thumb.jpg" alt="New folder.exe virus" /></p>
<p>Well, so here is the story of how i was able to kill the monster and reclaim my hard disk space.</p>
<p>Manual Process of removal</p>
<p class="MsoNormal"><span id="more-40"></span><br />
I prefer manual process simply because it gives me option to learn new things in the process.</p>
<p class="MsoNormal">
<p class="MsoNormal">So let’s start the process off reclaiming the turf that virus took over from us.</p>
<ol style="margin-top: 0in" type="1">
<li class="MsoNormal"><strong>Cut      The Supply Line</strong>
<ol style="margin-top: 0in" type="a">
<li class="MsoNormal">Search       for <em>autorun.inf file</em>. It is a read only file so you will have to change       it to normal by right clicking the file , selecting the properties and <em>un-check the read only option</em></li>
<li class="MsoNormal">Open       the file in notepad and delete everything and save the file.</li>
<li class="MsoNormal">Now       change the file <em>status back to read only</em> mode so that the virus could not get       access again.</li>
<li class="MsoNormal"> <a rel="attachment wp-att-213" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/autorun1/"><img class="alignnone size-thumbnail wp-image-213" title="Autorun INF: cutting the supply line" src="http://amiworks.co.in/talk/wp-content/uploads/2008/03/autorun1-150x150.jpg" alt="Autorun" width="150" height="150" /></a></li>
<li class="MsoNormal">Click       <em>start-&gt;run and type msconfig</em> and click ok</li>
<li class="MsoNormal">Go       to startup tab look for <em>regsvr and uncheck the option</em> click OK.</li>
<li class="MsoNormal">Click       on <em>Exit without Restart</em>, cause there are still few things we need to do       before we can restart the PC.</li>
<li class="MsoNormal">Now go to <em>control panel -&gt; scheduled tasks</em>, and <em>delete the At1 task</em> listed their.</li>
</ol>
</li>
<li class="MsoNormal"><span> </span><strong>Open The Gates Of Castle</strong>
<ol style="margin-top: 0in" type="a">
<li class="MsoNormal">Click       on <em>start -&gt; run and type gpedit.msc </em>and click Ok.</li>
<li class="MsoNormal"><a rel="attachment wp-att-214" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/run1/"><img class="size-thumbnail wp-image-214" title="Opening the gate of castle: starting the gepedit or msconfig" src="http://amiworks.co.in/talk/wp-content/uploads/2008/03/run1-150x150.jpg" alt="" width="150" height="150" /></a></li>
<li class="MsoNormal">If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from <a title="Windows XP Home Edition: gpedit.msc" rel="nofollow" href="http://bogdan.org.ua/2007/11/15/windows-xp-he-home-edition-gpedit-msc-group-policy-editing-via-registry.html">Windows XP Home Edition: gpedit.msc</a> and then follow these steps.<a title="Windows XP Home Edition: gpedit.msc" rel="nofollow" href="http://bogdan.org.ua/2007/11/15/windows-xp-he-home-edition-gpedit-msc-group-policy-editing-via-registry.html"><br />
</a></li>
<li class="MsoNormal">Go       to <em>users configuration-&gt;Administrative templates-&gt;system</em></li>
<li class="MsoNormal">Find       “<em>prevent access to registry editing tools</em>” and change the option to       <em>disable</em>.</li>
<li class="MsoNormal"> <a rel="attachment wp-att-215" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/gpedit1/"><img class="alignnone size-thumbnail wp-image-215" title="Opening the gate of castle: Group Edit Policies" src="http://amiworks.co.in/talk/wp-content/uploads/2008/03/gpedit1-150x150.jpg" alt="Opening the gate of castle: Group Edit Policies" width="150" height="150" /></a></li>
<li class="MsoNormal">Once       you do this you have registry access back.</li>
</ol>
</li>
<li class="MsoNormal"><strong>Launch The Attack At Heart Of Castle</strong>
<ol style="margin-top: 0in" type="a">
<li class="MsoNormal">Click       on <em>start-&gt;run and type regedit</em> and click ok</li>
<li class="MsoNormal">Go       to <em>edit-&gt;find and start the search for regsvr.exe</em>,</li>
<li class="MsoNormal"> <a rel="attachment wp-att-216" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/gate1/"><img class="alignnone size-thumbnail wp-image-216" title="Launch the attack in the heart of castle: registry search" src="http://amiworks.co.in/talk/wp-content/uploads/2008/03/gate1-150x150.jpg" alt="Launch the attack in the heart of castle: registry search" width="150" height="150" /></a></li>
<li class="MsoNormal">Delete       all the occurrence of regsvr.exe; remember to <em>take a backup before       deleting</em>. KEEP IN MIND <strong>regsvr32.exe       is not to be deleted. </strong><em>Delete regsvr.exe occurrences only</em>.</li>
<li class="MsoNormal">At       one ore two places you will find it after explorer.exe in theses cases       only delete the regsvr.exe part and not the whole part. E.g.  <strong> Shell = &#8220;Explorer.exe regsvr.exe&#8221; </strong>the just delete the regsvr.exe and leave the explorer.exe</li>
</ol>
</li>
<li class="MsoNormal"><strong>Seek And Destroy the enemy soldiers</strong>, no one should be left behind
<ol style="margin-top: 0in" type="a">
<li class="MsoNormal">Click       on <em>start-&gt;search-&gt;for files and folders</em>.</li>
<li class="MsoNormal">Their       <em>click all files and folders</em></li>
<li class="MsoNormal">Type       “<em>*.exe” </em>as filename to search for</li>
<li class="MsoNormal">Click       on ‘<em>when was it modified</em> ‘ option and <em>select the specify date</em> option</li>
<li class="MsoNormal">Type       <em>from date</em> as 1/31/2008 and also type <em>To date</em> as 1/31/2008</li>
<li class="MsoNormal"> <a rel="attachment wp-att-217" href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/search2/"><img class="alignnone size-thumbnail wp-image-217" title="Seek and destory enemy soldiers: the search option" src="http://amiworks.co.in/talk/wp-content/uploads/2008/03/search2-150x150.jpg" alt="Seek and destory enemy soldiers: the search option" width="150" height="150" /></a></li>
<li class="MsoNormal">Now       hit search and wait for all the exe’s to show up.</li>
<li class="MsoNormal">Once       search is over <em>select all the exe files and shift+delete</em> the files,       <strong>caution</strong> must be taken so that you don’t delete the legitimate exe file       that you have installed on 31<sup>st</sup> January.</li>
<li class="MsoNormal">Also       selecting lot of files together might make your computer unresponsive so       delete them in small bunches.</li>
<li>Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)</li>
</ol>
</li>
<li class="MsoNormal"><strong>Time For Celebrations</strong>
<ol>
<li class="MsoNormal"> Now do      a cold reboot (ie press the reboot button instead) and you are done.</li>
</ol>
</li>
</ol>
<p>I hope this information helps you win your own battle against this virus. Soon all antivirus programs will be able to automatically detect and clean this virus. Also i hope Avast finds a way to solve this issues.</p>
<p>As a side note i have found a little back dog( winpatrol ) that used to work perfectly on my old system. It was not their in my new PC, I have installed it again , as I want to stay ahead by forever closing the supply line of these virus. You can download it form <a title="Free Download - Install WinPatrol 2007 " href="http://www.winpatrol.com/download.html">Winpatrol website</a>.</p>
<p><strong>UPDATE : Avast Boot Time Scheduling </strong></p>
<p><img src="http://amiworks.co.in/talk/wp-content/avast_boot_time_scan.thumbnail.jpg" alt="Avast Boot Time Scan" width="128" height="76" /></p>
<p>Check out <a title="How to stop regedit, taskmanager or msconfig from closing automatically" href="http://http://amiworks.co.in/talk/how-to-stop-regedit-taskmanager-or-msconfig-from-closing-automatically/">How to stop regedit, task manager and msconfig  from closing automatically </a> if your regedit or msconfig closes automatically.</p>
<!-- WP Boastful Plugin by WPoets Team --> <div id='boastful'><strong></strong></div><hr style="border-top:black solid 1px" /><a href="http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/">How to remove new folder exe or regsvr exe or autorun inf virus</a> was first posted on March 29, 2008 at 12:45 pm.<br />©2008 "<a href="http://amiworks.co.in/talk">am i works?</a>". <br />]]></content:encoded>
			<wfw:commentRss>http://amiworks.co.in/talk/how-to-remove-new-folderexe-or-regsvrexr-or-autoruninf-virus/feed/</wfw:commentRss>
		<slash:comments>177</slash:comments>
		</item>
	</channel>
</rss>

