Ask Experts Questions for FREE Help!
  Advanced
Register  |  Log in  
   Ask    
 Answer  
  Help  

Ask QuestionsprogressAnswer QuestionsprogressBuild ReputationprogressBecome an Expert
 
Free Answers in 3 Easy Steps

Register Now
3 Steps

At Ask Me Help Desk you can ask questions in any topic and have them answered for free by our experts. To ask questions or participate in answering them you must register for a free account. By registering you will be able to:
  • Get free answers from experts in any of our 300+ topics.
  • Accept money for answers that you provide.
  • Communicate privately with other members (PM).
  • See fewer ads.

Home > Computers & Technology > Security > Spyware, Viruses, etc.   »   New Folder.exe

 
Thread Tools Display Modes
Question
 
 
#1  
Old Feb 19, 2007, 11:58 PM
DJ-Jokool's Avatar
DJ-Jokool
New Member
DJ-Jokool is offline
 
Join Date: Feb 2007
Posts: 9
DJ-Jokool See this member's comment history on his/her Profile page.
New Folder.exe

Hi all I'm new here, I'm a noobs in this site.. I just would like to ask you peeps if someone here encoutered same problem. My computer is infected with worm vb.k as what AVG detected. I creates New Folder.exe in my drives. then I cant access my registry, msconfig and task manager. I have tried doin HJT on the computer and also tried sysmantec way of editing the registry. I play with registry also delete policies. I manage to gain the computer again but when I turn it off and boot the following morning the virus or the worm is there again help...

Reply With Quote
 
     

Answers
 
 
Old Feb 20, 2007, 12:24 AM   #2  
Administrator
Curlyben is offline
 
Curlyben's Avatar
 
Join Date: Mar 2005
Location: Behind You !!
Posts: 6,990
Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.
Pay to call Curlyben for advice ($1/min)
Call Curlyben via Skype™
C&P time again:
Quote:
Originally Posted by Curlyben
To make sure everything is running fine run both anti virus and anti spyware apps in normal AND safe modes. (make sure that they are updated first ! ) (AVG is good and free AV)
(A couple of good removal tools are Spybot and Adaware)

ALso an on line virus and spyware scanner is Trend Housecall

Just a note; actively running two AV's on one machine can cause problems.
So if you are thinking about it make sure your current one is disabled first.
Same thing applies to online scanners as well.

Then remove any left over junk and clean the registry.
Removal of junk files is easy with CCleaner a free app that does exactly what.
**A word of warning**
NEVER mess about in the registry as removing the wrong key will result in a non functioning comouter and the need for a complete rebuild
  Reply With Quote
 
     
 
 
Old Feb 20, 2007, 12:33 AM   #3  
New Member
DJ-Jokool is offline
 
DJ-Jokool's Avatar
 
Join Date: Feb 2007
Posts: 9
DJ-Jokool See this member's comment history on his/her Profile page.
Guys is there a manual way of doin this.. I know about destroying the O.S. if messing up with the registry. thanks for the warning.. I very cautious on doin it any does this Spybot and CCleaner run or windows 2000 or Windows 2000 server
  Reply With Quote
 
     
 
 
Old Feb 20, 2007, 12:35 AM   #4  
Administrator
Curlyben is offline
 
Curlyben's Avatar
 
Join Date: Mar 2005
Location: Behind You !!
Posts: 6,990
Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.Curlyben See this member's comment history on his/her Profile page.
Pay to call Curlyben for advice ($1/min)
Call Curlyben via Skype™
Manual; WHY ?? Use the all the tools you can
Win2000 No worries
  Reply With Quote
 
     
 
 
Old Feb 20, 2007, 04:38 AM   #5  
Relationship Expert
talaniman is offline
 
talaniman's Avatar
 
Join Date: Nov 2005
Location: Space Is The Place
Posts: 18,027
talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.talaniman See this member's comment history on his/her Profile page.
I use spybot search and destroy and avant anti virus with some good results as I'm all over the web. No problem on windows XP.
  Reply With Quote
 
     
 
 
Old Feb 18, 2008, 10:00 PM   #6  
New Member
mcgaiver is offline
 
Join Date: Feb 2008
Posts: 1
mcgaiver See this member's comment history on his/her Profile page.
Here's a way to manually remove the virus. I assume you couldn't execute task manager too.

1) First you have to disable the process
*start command prompt
*check the running process by tasklist command (i.e. C:\>tasklist)
*look for malicious process like blastclnnn.exe, SSVIHOST.exe, New Folder.exe...
*terminate each malicious process by using taskill command(i.e. C:\>TASKKILL /F /IM SSCVIHOST.EXE).

2)Now that you've killed the process, you have to delete the virus file from the system32 folder(autorun.ini, SSVIHOST.exe, blastclnnn.exe) but you have to change their attributes by command prompt before you could delete them. Wondering why the virus keeps on running the next day? that's because the virus crated a task alt1.job to ensure that it'll always execute every 9:00 am everyday. You could delete this at Scheduled Tasks folder.

3)Now you have to enable the Task Manager & Registry Editor at Group Policy.

4)Lastly, you have to search delete all the new folder.exe . be sure not to execute them or you'll have to start over again. there's a way to prevent you from accidentally opening them. But i'm to busy to explain. I'm creating program to automatically fix this pesky virus. just IM me at [email address] if you need more guidance.
  Reply With Quote
 
     
 
 
Old Feb 19, 2008, 12:46 PM   #7  
Junior Member
TechEmperor is offline
 
Join Date: Jan 2008
Posts: 92
TechEmperor See this member's comment history on his/her Profile page.
For anyone having trouble re-enabling the task manager this article has step by step instructions, lists the registry keys necessary, and even provides a batch file to do it for you.
  Reply With Quote
 
     

Bookmarks


Thread Tools
Display Modes

 
Similar Sponsors

Similar Threads
Question Asker Forum Answers Last Post
Password protecting a folder Murdrwrtr Other Security 1 Jan 9, 2007 02:53 PM
Is cmd.exe under lsass.exe a Virus Grammarian-Bot Internet & the Web 3 Jul 3, 2006 02:44 PM
Issas.exe, iau.exe etc how to get rid of? citroes Spyware, Viruses, etc. 5 Apr 23, 2005 07:43 PM
my favorites folder swhy Other Security 4 Jan 25, 2005 09:52 AM
highlighted folder in XP wthai Windows 1 May 21, 2004 12:11 AM




Copyright ©2003 - 2007, Ask Me Help Desk.
All times are GMT -8. The time now is 09:47 PM.