How to Remove New Win32 Virus

By Thomas King

New Win32, also known as Trojan.Win32.Agent.crhz, is a Trojan downloader virus. This means that once it infects your computer, New Win32 may download additional Trojans and viruses. In addition, New Win32 may collect your personal information and communicate it to a remote hacker, slow your computer, change your Internet and desktop settings, and cause your computer to crash. The best way to remove New Win32 is to run your antivirus program. However, the virus can also be removed manually by following the steps below.

End Processes

Step 1

Press \"Ctrl-Alt-Delete.\"

Step 2

Click on the \"Task Manager,\" then click on the \"Processes\" tab.

Step 3

End the following processes. To end a process, right-click on it and select \"End Process.\"\"Windir\\INETINFO.exe\"\"Windir\\messenger\\messenger.exe\"

Delete Registry Values

Step 1

Hold down the Windows key and press \"R\" (or click \"Start\" and then \"Run\"). A dialog box opens.

Step 2

Type \"regedit\" (without the quotation marks) into the box and click \"OK.\" The Registry Editor opens.

Step 3

Locate the following registry values in the left pane of the Registry Editor and delete them. To delete a registry value, right-click on it and select \"Delete.\"\"[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\Root\\LEGACY_NETRA\\0000\\Control]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\Root\\LEGACY_NETRA\\0000]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\Root\\LEGACY_NETRA]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\netra\\Enum]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\netra\\Security]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\netra]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Enum\\Root\\LEGACY_NETRA\\000\\Control]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Enum\\Root\\LEGACY_NETRA\\0000]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Enum\\Root\\LEGACY_NETRA]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netra\\Enum]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netra\\Security]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\netra]\"\"[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ServiceCurrent]\"\"[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\ServiceCurrent]\"

Delete DLL Files

Step 1

Hold down the Windows key and press \"R\" (or click \"Start\" and then \"Run\"). A dialog box opens.

Step 2

Type \"cmd\" (without the quotation marks) into the box and click \"OK.\" The Command Prompt opens.

Step 3

Type \"regsvr32 /u licxnoc\" (without the quotation marks) at the Command Prompt and press \"Enter.\"

Step 4

Type \"regsvr32 /u temp\" (without the quotation marks) and press \"Enter.\"

Delete Files

Step 1

Click \"Start.\"

Step 2

Click on the \"Search Programs and Files\" box.

Step 3

Search for and delete the following files. To delete a file, right-click on it and select \"Delete.\"\"System\\Setup\\licxnoc.dll\"\"Windir\\inf\\pp3.inf\"\"ProgramFiles\\Windows NT\\fsdd.log\"\"Windir\\INETINFO.exe\"\"Windir\\messenger\\messenger.exe\"\"System\\temp.dll\"