Infected files
Moderator: Wiz Feinberg
- Dave Little
- Posts: 287
- Joined: 4 Aug 1998 11:00 pm
- Location: Atlanta
Infected files
My McAfee detected 2 infected files in my C:/_Restore/Temp directory. However, I'm unable to delete these files, even though I've closed all running programs. Another thing- a few days ago, McAfee found that wininit.exe had been infected, then deleted wininit.exe. Now, at start-up, I get a MS-DOS window that is titled WININIT-FINISHED
and a message that WININIT.EXE cannot be run in windows. WININIT is still in my Windows directory. (Windows ME)
Any suggestions?<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Dave Little on 21 February 2001 at 05:37 AM.]</p></FONT>
and a message that WININIT.EXE cannot be run in windows. WININIT is still in my Windows directory. (Windows ME)
Any suggestions?<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Dave Little on 21 February 2001 at 05:37 AM.]</p></FONT>
- Jack Stoner
- Posts: 22136
- Joined: 3 Dec 1999 1:01 am
- Location: Kansas City, MO
Windows ME has a recovery procedure built in that will restore your computer to an earlier date.
If you know when (or approximately when) the computer was infected you may be able to restore it back to where it was before the virus infected it.
Click on Start and the Run. Enter msconfig in the box and then click OK. This will bring up the msconfig window. At the lower left will be an option to "Launch System Restore". Click on that and then follow the instructions to restore your computer to an earlier date.
This may take care of both the virus and your deleted files. I've never tried it to remove a virus so I don't know if that part will work. If it doesn't you will be back to where you were before running McAfee. McAfee should tell you what kind of virus(es) you have. You can go to the McAfee site and they have detailed instructions on removing many of the viruses which may help in getting the winint file restored.
If you know when (or approximately when) the computer was infected you may be able to restore it back to where it was before the virus infected it.
Click on Start and the Run. Enter msconfig in the box and then click OK. This will bring up the msconfig window. At the lower left will be an option to "Launch System Restore". Click on that and then follow the instructions to restore your computer to an earlier date.
This may take care of both the virus and your deleted files. I've never tried it to remove a virus so I don't know if that part will work. If it doesn't you will be back to where you were before running McAfee. McAfee should tell you what kind of virus(es) you have. You can go to the McAfee site and they have detailed instructions on removing many of the viruses which may help in getting the winint file restored.
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Dave,
This sounds like a virus to me. I had a client a couple of weeks ago that this happened to. I ran a virus check and couldn't. So I did some research and found out they had a W32.blebla.B.worm virus a.k.a Romeo and Juliet.
check out: http://service1.symantec.com/sarc/sarc.nsf/html/W32.Blebla.B.Worm.html
Hope this helps.
Marcus
This sounds like a virus to me. I had a client a couple of weeks ago that this happened to. I ran a virus check and couldn't. So I did some research and found out they had a W32.blebla.B.worm virus a.k.a Romeo and Juliet.
check out: http://service1.symantec.com/sarc/sarc.nsf/html/W32.Blebla.B.Worm.html
Hope this helps.
Marcus
-
- Posts: 497
- Joined: 13 Jul 1999 12:01 am
- Location: Marengo, OH, USA (deceased)
Dave -- Seems like Jack has a good idea, there, about 'recovering' to an earlier condition. Depending upon the virus type and whether it is 'active' that MAY not get rid of it.
If the recovery fails (or even if it works), you might try TrendMicro's on-line antivirus procedure.
http://housecall.antivirus.com/housecall/start_corp.asp
This does a virus scan/clean with no purchase or obligation. They do ask, but don't require, you to 'register'. The first time you use HOUSECALL will take several minutes for them to temporarily download their files. If/when you get a security dialogue about 'running and installing', select 'yes'.
After they are prepared, the Trend system will display a window in which you may select the drives and/or folders to be scanned. The actual scan goes pretty quick so don't be too selective about folders.
IMO they have a good product and provide much virus info and advice on their site.
Any question, ask me. -- Everett
P.S. You should be able to restore the WININIT file(s) from your Windos CDRom or from cabinet files on your hard disk if the recovery fails.
If the recovery fails (or even if it works), you might try TrendMicro's on-line antivirus procedure.
http://housecall.antivirus.com/housecall/start_corp.asp
This does a virus scan/clean with no purchase or obligation. They do ask, but don't require, you to 'register'. The first time you use HOUSECALL will take several minutes for them to temporarily download their files. If/when you get a security dialogue about 'running and installing', select 'yes'.
After they are prepared, the Trend system will display a window in which you may select the drives and/or folders to be scanned. The actual scan goes pretty quick so don't be too selective about folders.
IMO they have a good product and provide much virus info and advice on their site.
Any question, ask me. -- Everett
P.S. You should be able to restore the WININIT file(s) from your Windos CDRom or from cabinet files on your hard disk if the recovery fails.
- Craig A Davidson
- Posts: 3914
- Joined: 16 Feb 2001 1:01 am
- Location: Wisconsin Rapids, Wisconsin USA
- Contact:
- Jack Stoner
- Posts: 22136
- Joined: 3 Dec 1999 1:01 am
- Location: Kansas City, MO
Craig, check the McAfee site. They seem to have more info on manually removing viruses than Norton.
Norton seems to be lacking in that area as I've had some e-mails from others that have files "quarantined" but didn't know how to remove them, and I currently have Norton Antivirus 2001 installed on my machine.
Norton seems to be lacking in that area as I've had some e-mails from others that have files "quarantined" but didn't know how to remove them, and I currently have Norton Antivirus 2001 installed on my machine.
- Dave Little
- Posts: 287
- Joined: 4 Aug 1998 11:00 pm
- Location: Atlanta
- Jack Stoner
- Posts: 22136
- Joined: 3 Dec 1999 1:01 am
- Location: Kansas City, MO
- Dave Little
- Posts: 287
- Joined: 4 Aug 1998 11:00 pm
- Location: Atlanta
Answer to Jack:
Actually, when I tried your suggestion of system restore, there were no restore points available. Just for fun, I tried to create a new restore point and it seemed to work as I was proceeding. I then went back to see if I could restore to my "new" restore point but was informed that there were no restore points. I think there is more wrong than just the recent virus attack. Another glitch is that my Windows Help doesn't come up. All of my programs are working fine at this point so I can't justify a complete reformat just now......but some day.
Thanks again for your time and help.
Actually, when I tried your suggestion of system restore, there were no restore points available. Just for fun, I tried to create a new restore point and it seemed to work as I was proceeding. I then went back to see if I could restore to my "new" restore point but was informed that there were no restore points. I think there is more wrong than just the recent virus attack. Another glitch is that my Windows Help doesn't come up. All of my programs are working fine at this point so I can't justify a complete reformat just now......but some day.
Thanks again for your time and help.
-
- Posts: 497
- Joined: 13 Jul 1999 12:01 am
- Location: Marengo, OH, USA (deceased)
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Dave,
I thought back to when everyone in my company got this virus and remembered it was not that Romeo and Juliet like I said earlier, but it is the W32.HLLW.Bymer
Go to the Start Menu, Find, Files or folders, make sure you are aimed at the C:\ drive. Then look for WININIT.EXE You should have a couple. Delete the WININIT.EXE that is in the C:\Windows\System folder. DO NOT AND I REPEAT DO NOT DELETE THE FILE THAT IS IN THE C:\Windows FOLDER.
Also do a search on your C:\ drive for dnetc
you should have a couple of files named dnetc that were put there by the virus. Just go ahead and delete them.
email me off the forum if you would like more help removing this.
Marcus
I thought back to when everyone in my company got this virus and remembered it was not that Romeo and Juliet like I said earlier, but it is the W32.HLLW.Bymer
Go to the Start Menu, Find, Files or folders, make sure you are aimed at the C:\ drive. Then look for WININIT.EXE You should have a couple. Delete the WININIT.EXE that is in the C:\Windows\System folder. DO NOT AND I REPEAT DO NOT DELETE THE FILE THAT IS IN THE C:\Windows FOLDER.
Also do a search on your C:\ drive for dnetc
you should have a couple of files named dnetc that were put there by the virus. Just go ahead and delete them.
email me off the forum if you would like more help removing this.
Marcus