How to remove newfolder.exe or regsvr.exe or autorun.inf virus

Welcome back to , toady i will tell you how to easily remove autorun.inf or regsvr.exe or newfolder.exe viruses manually .

I was surprised that my most reliable friend Avast, for the first time failed me in removing these viruses but then again avg and bitdiffender also failed against it. This virus is know popularly as regsvr.exe virus,  or as newfolder.exe virus and most people identify this one by seeing autorun.inf file on their pen drives, But trend micro identified it as WORM_DELF.FKZ. It is spreading mostly using pen drives as the medium.

Well, so here is  how i removed these viruses manually :

Manual Process of removal

I prefer manual process simply because it gives me option to learn new things in the process.

So let’s start the process off reclaiming the turf that virus took over from us.


1. Removing the viral codes from viruses

a. Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option
b. Open the file in notepad and delete everything and save the file.
c. Now change the file status back to read only mode so that the virus could not get access again.
d.Click start->run and type msconfig and click ok
e. Go to startup tab look for regsvr and uncheck the option click OK.
f. Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.
g. Now go to control panel -> scheduled tasks, and delete the At1 task listed their.

2. Editing in Group Policy
a. Click on start -> run and type gpedit.msc and click Ok.
b. If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.
c. Go to users configuration->Administrative templates->system
d. Find “prevent access to registry editing tools” and change the option to disable.
e. Once you do this you have registry access back.

3. Deleting files from Regitry
a. Click on start->run and type regedit and click ok
b. Go to edit->find and start the search for regsvr.exe,
c. Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.
d. At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe

4. Seek And Destroy the viruses
a. Click on start->search->for files and folders.
b. Their click all files and folders
c. Type “*.exe” as filename to search for
d. Click on ‘when was it modified ‘ option and select the specify date option
e. Type from date as 5/1/2008 and also type To date as 5/1/2008
f. Now hit search and wait for all the exe’s to show up.
g. Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 1st May.
h. Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.
i. Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)

5. Time For Celebrations
1. Now do a cold reboot (ie press the reboot button instead) and you are done.
I hope this information helps you to remove these viruses. Soon all antivirus programs will be able to automatically detect and clean this virus. Also i hope Avast finds a way to solve this issues.
As a side note i have found a little back dog( winpatrol ) that used to work perfectly on my old system. It was not their in my new PC, I have installed it again , as I want to stay ahead by forever closing the supply line of these virus. You can download it form Winpatrol website.


Please do reply if it works and u like my Post

Tags: , , , , , , , , , ,

Show 18 Comments


  • avatar image
    May 3, 2009 Reply

    i followed worked...great...thx a lot i have windows xp profesional(english) but after i did this when i tried to install sumthings the language is in diff language....plz help me....

  • avatar image
    $unil Jain
    May 3, 2009 Reply

    tell me which virus you wanted to remove ?????

  • avatar image
    May 3, 2009 Reply

    i removed regsvr.exe n outorun.inf

    • avatar image
      Sunil Jain
      May 3, 2009 Reply

      ok can u tell me which soft are u trying to install ???

  • avatar image
    May 4, 2009 Reply

    mks vir(2k7).....and it will be help if u tell me which is best antivirus in d world right now.....n d reason for that...thx

  • avatar image
    May 4, 2009 Reply

    Hi, interesting post. I have been thinking about this topic,so thanks for writing. I will definitely be coming back to your posts.

  • avatar image
    Sunil Jain
    May 10, 2009 Reply

    @chethan I recommend you to use NOD32 ANTIVIRUS it's the best antivirus software i have eveer seen :)

  • avatar image
    May 17, 2009 Reply

    Thanks dude for this great info!! i just want share,i use malwarebytes for remove all spyware,virus and worm from my computer.this software is free and very powerfull !! just install,update to latest definition and make full scan...after finish scan remove all infected file found by Malwarebyte. restart computer for see the result.for more better result you can scan in safe mode. Thanks..

  • avatar image
    May 25, 2009 Reply

    Hi Thanks for ur suggestions. I will try it out and get back to u.

    • avatar image
      Sunil Jain
      May 26, 2009 Reply

      @prathima ok :)

  • avatar image
    July 10, 2009 Reply

    Pls give the information about how delate this viruses manually.

  • avatar image
    August 30, 2009 Reply

    You were only supposed to remove them from a usb key for example,NOT from Your Computer,why oh why don't people read everything and then read again before going off and doing stupid things. regsvr32 for example is very important to the computer and IS NOT regsvr.exe

  • avatar image
    November 23, 2009 Reply

    Good post. here are so many types of computer viruses in this world that removing them and finding a specific solution for each of them is a big ask. One such virus that screwed me is regsvr.exe classified as a W32.Imaut worm. To view solution Visit link below

  • avatar image
    July 20, 2010 Reply

    Remove autorun.inf virus manually. 1). Go to any folder.In that on the top menu go to Tools--> Folder Options, which will be beside File, Edit, View, Favourites. 2). A window pops up after you click on folder options.In that window go to View tab and select the option Show hidden files and folders.Now uncheck the option Hide protected Operating system files.Click Ok 3). Now Open your drives (By right click and select Explore. Don't double click!) Delete autorun.inf and MS32DLL.dll.vbs or MS32DLL.dll (use Shift+Delete as it deletes files forever.) in all drives include Handy Drive and Floppy disk. 4). Open folder C:WINDOWS to delete MS32DLL.dll.vbs or MS32DLL.dll (Use Shift+Delete ) 5). Go to start --> Run --> Regedit and the Registry editor will open 6). Now navigate in the left pane as follows: HKEY_LOCAL_MACHINE --> Software --> Microsoft --> Windows --> Current Version --> Run .Now delete the entry MS32DLL (Use Delete key on keyboard) 7). Go to HKEY_CURRENT_USER --> Software --> Microsoft --> Internet Explorer --> Main and delete the entry Window Title "Hacked by Godzilla" 8). Now open the group policy editor by typing gpedit.msc in Start --> run and pressing enter. 9). Go to User Configuration --> Administrative Templates --> System. Double Click on entry Turn Off Autoplay then Turn Off Autoplay Properties will display.Do as follows: Select Enabled 10). Select All drives and Click OK 11). Now go to start --> Run and type msconfig there and press Enter.A system configuration utility dialogue will open. 12). Go to startup tab in it and uncheck MS32DLL .Now click Ok and when the system configuration utility asks for restart ,click on exit without restart. 13). Now go to Tools --> Folder Options on the top menu of some folder again and select the Do not show Hidden files and check Hide operating system files. 14). Go to your recyclable bin and empty it to prevent any possiblity of MS322DLL.dll.vbs lying there. Now restart your PC once and you can now open your hard disk drives by double clicking on them

  • avatar image
    August 12, 2010 Reply

    Do you also know how to remove csrss.exe virus and recycker please help.

  • avatar image
    September 8, 2010 Reply

    Well that was a good news specially those people who does not know that the autorun.inf and folder.exe are virus. Thanks guys for the information.

  • avatar image
    November 6, 2010 Reply

    i just want share,i use malwarebytes for remove all spyware,virus and worm from my computer

Leave a Reply

Story Page