Hi
My system is affected with NewFolder.exe virus which is also creating lot of exe files in the name of the folders I don't know how to remove this my avg antivirus pack is not removing this what else could solve my problem. What are all the registry modifications to be done after removing this virus.

Thanks with regrds.
Satya. G

Dani AI

Generated

Short summary and containment notes: the behaviour described by (an executable creating many .exe copies named after folders) is typical of autorun/replicating worms. Immediate containment is the highest priority — isolate the affected PC from networks and stop using removable media on other machines until the infection is cleaned.

Recommended removal workflow (in order):

  • Run a full scan from a trusted on-demand product and an offline scanner if the AV engine inside Windows cannot remove active components (examples: Malwarebytes and ).
  • Use a rescue disk or offline scanner when an active process resists removal; that prevents reinfection while the OS is running.
  • After an on-disk cleanup, inspect persistence points rather than editing the registry blindly (see notes below). Autorun files on removable drives should be removed and all external media scanned on a clean machine before reuse.

Quick unhide / autorun cleanup (run from an elevated command prompt; replace X: with the infected drive letter):

X:
attrib -h -s -r /s /d *.*
del /f /q autorun.inf

Notes on registry/persistence and safe editing: infections often persist in Run keys, services, scheduled tasks, or the Startup folder. Rather than manually hunting registry keys, use a vetted tool like Autoruns (Sysinternals) to identify and disable suspicious entries. Do not remove keys unless their purpose is known — backing up the registry or creating a disk image first is essential. System Restore points created while infected can reintroduce malware; clear or disable restore points and re-enable them only after a thorough clean.

Follow ’s suggestion to generate and post diagnostic logs (HijackThis or Autoruns reports) and, as indicated, perform scans in a minimal environment. Avoid making registry edits or removing entries until specific lines are identified by an experienced helper; if uncertainty remains, a clean OS reinstall and restoring only scanned personal data is the safest final option.

Recommended Answers

All 2 Replies

have you run your antivirus in safe mode?

Hi, please download the latest copy of HijackThis from and save it to your desktop.

  • Double click on HJTInstall.exe to install it. Click on Install. By default, it will install to C:\Program Files\Trend Micro\HijackThis.
  • Read through the License Agreement presented to you on the next screen and click on I Accept.
  • Once installed, HijackThis will start automatically. If it doesn't, please go to your desktop and double click on the HijackThis shortcut created there.
  • Select Do a system scan and save a logfile.
  • Close HijackThis.

Note : Do not fix any lines you see in HijackThis as most entries are harmless and needed for the normal functioning of Windows.

Please post the contents of the HijackThis logfile here.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.