Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I've got a program called Newmovie.exe on my drive which was not executed. My anti-virus software detected it as a variety of SubSeven.backdoor, but could not delete it or rename, etc. Now what do I do? I managed to view it's properties and they do not say it is read-only but I don't believe that.

Are you saying that right clicking on the file and selecting DELETE will not delete the file? How about re-booting and trying the same thing.

Yes, that's what I'm saying. Right clicking brings up my QuickHeal anti-virus's warning dialoge box and after I grope my way out of that and get back to the right click window I can't delete it, nor can QuickHeal. I'll try rebooting but if I have deleted another file with no problem so I can't see that that will change anything. I want to try a DOS attrib change but can't remember the syntax.

Changing it to read only won';t help. The reason you can't delete it is possibly because it is in use. Sub Seven is a common trojan but as far as I know its a Win32 file. Try booting into DOS and deleting it from there.
attrib /? gives you all commands and syntaxes
to delete simple
del worm.exe. Also get a better antivirus

First, download the RxPack from
http://home.earthlink.net/~rmbox/Reticulated/Toys.htmlThen restart to DOS, CD to the appropriate directory and
DEL Newmovie.exeWhen you restart to windows you will then need to run EXEFIX08 to fix up the registry
Then run edit-wi and edit-si to review the win.ini and system.ini files to ensure that you have cleaned out everything.Then, since it IS a backdoor, change all of your passwords everywhere.

Thanks all and to the last post: I have the RxPack but I didn't run this .exe. I'm getting smarter. Now, what I did was just rebooted to DOS and I was able to delete it. But I wonder how the program keeps itself from being deleted like it did?
I should have gone to DOS before I posted here, but I always like to go into the jungle world of worms and viruses with lotsa company. Thanks again.

Sometimes when you select a programme in Windows, it tells your comp that it's in use, therefore you can't delete it. If you wait a couple of minutes, then try deleting, then it does work! Happens to me sometimes! J

![]() |
cd-rom runs
|
Internet Explorer 5.5 sp1...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |