Sunday, August 23, 2009

How to Remove Regsvr.exe Virus

Regsvr.exe:

Regsvr.exe is identified as a worm that was first detected around 2007-08. This worm is usually detected along with the Newfolder.exe. Similar to the Newfolder.exe, this worm also spreads with the help of pen drives. When the flash drive is inserted into the infected system, the regsvr.exe immediately creates a copy of itself in the USB and also an autorun.inf file with the help of which it can launch in the target's system. This virus is capable of editing the registry and autoexecuting itself at the system startup. It generally resides in the Windows/ system32 directory. However, it can be removed by scanning the pen drive using a good antivirus or simply opening the USB using the Windows Command Prompt. Using a good firewall is recommended to prevent viruses like this one. Anyway, here is a simple manual removal method to this virus.

  • The worm launches a process with the names Newfolder.exe, server.exe, AT1.exe. Make sure that you kill these processes first.
  •   Now go to the control panel -> scheduled tasks, and delete the task of launching this process.
  • Traverse to the Windows/ system32 folder and delete the file from there.
  • You are almost done. Now go to Start -> Run and type regedit and go to the following location:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

  • Edit Shell ="Explorer.exe regsvr.exe" and delete the regsvr.exe from the registry.
  • Now you are free from the virus.

0 comments:

Post a Comment

 

About Me

My photo
Hey guys this is Vaseem Ansari, 25 years old, Software & Web Developer, Blogger & works on Open Sources Technologies I love my family and my loved once very much. It takes a while for me to build trust in someone new. I am honest, thoughtful, and my friends tell me that I am wise. I would also say that I am stubborn. but I do learn from my mistakes. I'm Glad I'm Me No one looks The way I do. I have noticed That it's true. No one walks the way I walk. No one talks the way I talk. I am me. There's no one else I'd rather be! Have fun reading this blog and don't forget to subscribe to the feed to keep updated on the latest articles. Visit my Blog at http://www.VaseemAnsari.com/blog/

Followers