How to remove NewFolder.exe virus? - NarutoBase Forums
Register Blogs FAQ Members List Award Search Today's Posts Mark Forums Read My Notes

Go Back   NarutoBase Forums > Media Base > Konoha IT Centre


Konoha IT Centre Come here if you need help with computers or just want to talk about anything related to computers or the internet.

Reply
 
LinkBack Thread Tools Display Modes
Old 06-29-2009, 03:08 PM   #1 (permalink)
WHITE LIONS: KING OF KING
rahul's Avatar
Join Date: Nov 2008
Location: india
Points: 25,397, Level: 48 Points: 25,397, Level: 48 Points: 25,397, Level: 48
Activity: 0,3% Activity: 0,3% Activity: 0,3%
Last Achievements
Award-Showcase
Awards Showcase
 
rahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legendrahul is a Legend
Male  rahul is offline    
rahul trying not to become a man of success but a man of value
Having problem with NewFolder.exe virus here is the solution?

newfolder.exe is an executable file that starts a malicious process, launches certain parasite components or runs a destructive payload.

Even if the newfolder.exe file does nothing suspicious, its presence indicates that your computer is infected with a particular threat.

The newfolder.exe file is installed and used by Iddono.

You are highly advised to scan the system, delete executable newfolder.exe and terminate all the processes it started. Please note that the newfolder.exe file actually may be a fully legitimate part of the operating system or legitimate software. Often parasites use files with unsuspicious names, but malicious functionality.

You should always carefully check the file before deleting it. It may not be related with malware, but can be required by your essential programs to work properly.



Manual Process of removal

I prefer manual process simply because it gives me option to learn new things in the process.

So let’s start the process off reclaiming the turf that virus took over from us.

* Cut The Supply Line
o Search for autorun.inf file. It is a read only file so you will have to change it to normal by right clicking the file , selecting the properties and un-check the read only option

o Open the file in notepad and delete everything and save the file.

o Now change the file status back to read only mode so that the virus could not get access again.
o Click start->run and type msconfig and click ok

o Go to startup tab look for regsvr and uncheck the option click OK.

o Click on Exit without Restart, cause there are still few things we need to do before we can restart the PC.

o Now go to control panel -> scheduled tasks, and delete the At1 task listed their.
* Open The Gates Of Castle

o Click on start -> run and type gpedit.msc and click Ok.

o If you are Windows XP Home Edition user you might not have gpedit.msc in that case download and install it from Windows XP Home Edition: gpedit.msc and then follow these steps.

o Go to users configuration->Administrative templates->system

o Find “prevent access to registry editing tools” and change the option to disable.

o Once you do this you have registry access back.

* Launch The Attack At Heart Of Castle

o Click on start->run and type regedit and click ok

o Go to edit->find and start the search for regsvr.exe,

o Delete all the occurrence of regsvr.exe; remember to take a backup before deleting. KEEP IN MIND regsvr32.exe is not to be deleted. Delete regsvr.exe occurrences only.

o At one ore two places you will find it after explorer.exe in theses cases only delete the regsvr.exe part and not the whole part. E.g. Shell = “Explorer.exe regsvr.exe” the just delete the regsvr.exe and leave the explorer.exe

* Seek And Destroy the enemy soldiers, no one should be left behind
o Click on start->search->for files and folders.

o Their click all files and folders

o Type “*.exe” as filename to search for

o Click on ‘when was it modified ‘ option and select the specify date option

o Type from date as 1/31/2008 and also type To date as 1/31/2008

o Now hit search and wait for all the exe’s to show up.

o Once search is over select all the exe files and shift+delete the files, caution must be taken so that you don’t delete the legitimate exe file that you have installed on 31st January.

o Also selecting lot of files together might make your computer unresponsive so delete them in small bunches.

o Also find and delete regsvr.exe, svchost .exe( notice an extra space between the svchost and .exe)

* Time For Celebrations

1. Now do a cold reboot (ie press the reboot button instead) and you are done.

I hope this information helps you win your own battle against this virus.

Last edited by rahul; 06-29-2009 at 03:28 PM..

Reply With Quote
 
     
The Following 3 Users Say Thank You to rahul For This Useful Post:
angelinhell (07-06-2009), rahulrocks (07-08-2009), ~Shigure~ (07-08-2009)
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
This is not spam. dont remove it. Narutoftw General Discussion 10 04-21-2009 08:55 PM
Vex teaches Pietro how to remove peoples clothes using fire O.O PietroUchiha Naruto Training Grounds 44 02-11-2009 11:31 PM
weegee virus weegee Request GFX 17 07-10-2008 11:10 AM
weegee virus spreads weegee Chatterbox 9 07-06-2008 07:02 PM
How do u remove ppl out of ur group? Madara Uchiha Questions and Suggestions 1 05-13-2008 06:58 PM


All times are GMT. The time now is 07:10 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2