Browse By

How to remove newfolder.exe or regsvr.exe or autorun.inf virus

Welcome back to , toady i will tell you how to easily remove autorun.inf or regsvr.exe or newfolder.exe viruses manually .

I was surprised that my most reliable friend Avast, for the first time failed me in removing these viruses but then again avg and bitdiffender also failed against it. This virus is know popularly as regsvr.exe virus,  or as newfolder.exe virus and most people identify this one by seeing autorun.inf file on their pen drives, But trend micro identified it as WORM_DELF.FKZ. It is spreading mostly using pen drives as the medium.

Well, so here is  how i removed these viruses manually :

Manual Process of removal

I prefer manual process simply because it gives me option to learn new things in the process.

So let’s start the process off reclaiming the turf that virus took over from us.


1. Removing the viral codes from viruses

a. Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option
b. Open the file in notepad and delete everything and save the file.
c. Now change the file status back to read only mode so that the virus could not get access again.
d.Click start->run and type msconfig and click ok
e. Go to startup tab look for regsvr and uncheck the option click OK.
f. Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.
g. Now go to control panel -> scheduled tasks, and delete the At1 task listed their.

2. Editing in Group Policy
a. Click on start -> run and type gpedit.msc and click Ok.
b. If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.
c. Go to users configuration->Administrative templates->system
d. Find “prevent access to registry editing tools” and change the option to disable.
e. Once you do this you have registry access back.

3. Deleting files from Regitry
a. Click on start->run and type regedit and click ok
b. Go to edit->find and start the search for regsvr.exe,
c. Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.
d. At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe

4. Seek And Destroy the viruses
a. Click on start->search->for files and folders.
b. Their click all files and folders
c. Type “*.exe” as filename to search for
d. Click on ‘when was it modified ‘ option and select the specify date option
e. Type from date as 5/1/2008 and also type To date as 5/1/2008
f. Now hit search and wait for all the exe’s to show up.
g. Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 1st May.
h. Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.
i. Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)

5. Time For Celebrations
1. Now do a cold reboot (ie press the reboot button instead) and you are done.
I hope this information helps you to remove these viruses. Soon all antivirus programs will be able to automatically detect and clean this virus. Also i hope Avast finds a way to solve this issues.
As a side note i have found a little back dog( winpatrol ) that used to work perfectly on my old system. It was not their in my new PC, I have installed it again , as I want to stay ahead by forever closing the supply line of these virus. You can download it form Winpatrol website.


Please do reply if it works and u like my Post


18 thoughts on “How to remove newfolder.exe or regsvr.exe or autorun.inf virus”

  1. chethan says:

    i followed this….it worked…great…thx a lot
    i have windows xp profesional(english) but after i did this when i tried to install sumthings the language is in diff language….plz help me….

  2. $unil Jain says:

    tell me which virus you wanted to remove ?????

  3. chethan says:

    i removed regsvr.exe n outorun.inf

    1. Sunil Jain says:

      ok can u tell me which soft are u trying to install ???

  4. chethan says:

    mks vir(2k7)…..and it will be help if u tell me which is best antivirus in d world right now…..n d reason for that…thx

  5. Anonymous says:

    Hi, interesting post. I have been thinking about this topic,so thanks for writing. I will definitely be coming back to your posts.

  6. Sunil Jain says:

    I recommend you to use NOD32 ANTIVIRUS it's the best antivirus software i have eveer seen 🙂

  7. HACKING MAN says:

    Thanks dude for this great info!!
    i just want share,i use malwarebytes for remove all spyware,virus and worm from my computer.this software is free and very powerfull !!
    just install,update to latest definition and make full scan…after finish scan remove all infected file found by Malwarebyte.
    restart computer for see the result.for more better result you can scan in safe mode.


  8. prathima says:


    Thanks for ur suggestions. I will try it out and get back to u.

    1. Sunil Jain says:

      ok 🙂

  9. chahal says:

    Pls give the information about how delate this viruses manually.

  10. LePoken says:

    You were only supposed to remove them from a usb key for example,NOT from Your Computer,why oh why don't people read everything and then read again before going off and doing stupid things.
    regsvr32 for example is very important to the computer and IS NOT regsvr.exe

  11. Chandrashekhar says:

    Good post.
    here are so many types of computer viruses in this world that removing them and finding a specific solution for each of them is a big ask. One such virus that screwed me is regsvr.exe classified as a W32.Imaut worm.
    To view solution Visit link below

  12. Smartjani says:

    Remove autorun.inf virus manually.

    1). Go to any folder.In that on the top menu go to Tools–> Folder Options, which will be beside File, Edit, View, Favourites.

    2). A window pops up after you click on folder options.In that window go to View tab and select the option Show hidden files and folders.Now uncheck the option Hide protected Operating system files.Click Ok

    3). Now Open your drives (By right click and select Explore. Don't double click!) Delete autorun.inf and MS32DLL.dll.vbs or MS32DLL.dll (use Shift+Delete as it deletes files forever.) in all drives include Handy Drive and Floppy disk.

    4). Open folder C:WINDOWS to delete MS32DLL.dll.vbs or MS32DLL.dll (Use Shift+Delete ) 5). Go to start –> Run –> Regedit and the Registry editor will open

    6). Now navigate in the left pane as follows: HKEY_LOCAL_MACHINE –> Software –> Microsoft –> Windows –> Current Version –> Run .Now delete the entry MS32DLL (Use Delete key on keyboard)

    7). Go to HKEY_CURRENT_USER –> Software –> Microsoft –> Internet Explorer –> Main and delete the entry Window Title "Hacked by Godzilla"

    8). Now open the group policy editor by typing gpedit.msc in Start –> run and pressing enter.

    9). Go to User Configuration –> Administrative Templates –> System. Double Click on entry Turn Off Autoplay then Turn Off Autoplay Properties will display.Do as follows: Select Enabled

    10). Select All drives and Click OK

    11). Now go to start –> Run and type msconfig there and press Enter.A system configuration utility dialogue will open.

    12). Go to startup tab in it and uncheck MS32DLL .Now click Ok and when the system configuration utility asks for restart ,click on exit without restart.

    13). Now go to Tools –> Folder Options on the top menu of some folder again and select the Do not show Hidden files and check Hide operating system files.

    14). Go to your recyclable bin and empty it to prevent any possiblity of MS322DLL.dll.vbs lying there.

    Now restart your PC once and you can now open your hard disk drives by double clicking on them

  13. kris says:

    Do you also know how to remove csrss.exe virus and recycker please help.

  14. Smart says:

    Well that was a good news specially those people who does not know that the autorun.inf and folder.exe are virus. Thanks guys for the information.

  15. vicky says:

    i just want share,i use malwarebytes for remove all spyware,virus and worm from my computer

Leave a Reply