Go Back   PCMech Forums > Help & Discussion > Software Discussion & Support

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 02-15-2005, 01:31 PM   #1
Member (8 bit)
 
trelarah's Avatar
 
Join Date: Jul 2003
Location: Thunder Bay, Ontario, Canada
Posts: 251
Need To Delete Virus

A friend of mine had a virus on his computer. This virus sent out a link to all of the contacts on his MSN Messenger. When I got the link I presumed it was legit, and therefore I went to it, and opened the suggested file. Once that happened a picture of a half naked girl showed up, and my internet shut down.

I am on a University LAN, and I know for a fact that the problem was not my connection.

It turns out that when I pressed ctrl+alt+delete, and went to PROCESSES there was a application running that I didn't recognize called "wini.exe". So I closed that app. and now my internet runs just fine. However, I can't seem to find this file to permanently delete it, and it keeps restarting every time I reboot my computer. I've attempted to find it with SEARCH, but I haven't had any luck. Any suggestions?

(I've also ran SpyBot, Ad-Aware, AVG, Trend Mircos, and can't find the file)
__________________
HP dv6t QE | Intel Quad Core i7-2630QM | 2GB GDDR5 Radeon HD 6770M | 8GB DDR3 | 750GB 7200rpm | Blu-ray Player & Burner | TrueVision HD Webcam | 15.6" Full HD LED 1080p Display | 9cell Battery | Windows 7 64bit

Last edited by trelarah; 02-15-2005 at 01:38 PM.
trelarah is offline   Reply With Quote
Old 02-15-2005, 01:41 PM   #2
Blizzard Fanboy
 
spyder003's Avatar
 
Join Date: May 2003
Location: Northrend
Posts: 1,411
Check the startup tab in msconfig, see if it's checked to run on startup. You can uncheck it from there until you can find it.

If it's a malacious file, 9 times out of 10 it will be in the system32 folder.
__________________
EVGA 750i SLI - EVGA 9800 GX2 - Intel Q6700 - 4GB Corsair PC6400 - 1TB Seagate HDD - X-fi Gamer - Logitech G51 5.1 - ViewSonic 22" WS - Vista Premium
spyder003 is offline   Reply With Quote
Old 02-15-2005, 01:55 PM   #3
Member (8 bit)
 
trelarah's Avatar
 
Join Date: Jul 2003
Location: Thunder Bay, Ontario, Canada
Posts: 251
spyder003, i checked system32 and couldn't find it. and i don't know where or what msconfig is, little help with that please.
trelarah is offline   Reply With Quote
Old 02-15-2005, 02:11 PM   #4
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
MSCONFIG.........Click START>RUN type msconfig in the box and click OK
When the window opens click on the STARTUP tab and check in the list for the offending article.
Does this thing open an IE page and connect to the internet?
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta.
rjfvillarosa is offline   Reply With Quote
Old 02-15-2005, 03:23 PM   #5
Member (8 bit)
 
trelarah's Avatar
 
Join Date: Jul 2003
Location: Thunder Bay, Ontario, Canada
Posts: 251
rjfvillarosa, i did what you said and I deselected the "wini.exe" app from starting at the next boot up. so now it won't start, and everything works just fine.

however, i still want to remove this file. i couldn't find it in system32, so does anyone have any other suggestions?

(in msconfig, under the start up tab, then in the column 'LOCATION', it says that "wini.exe" is in: SOFTWARE\Microsoft\Windows\CurrentVersion\Run
But when I look under the coloumn 'COMMAND' it doesn't give the actual location like all the other applications, it just says "wini.exe")

Last edited by trelarah; 02-15-2005 at 03:38 PM.
trelarah is offline   Reply With Quote
Old 02-15-2005, 03:53 PM   #6
Member (10 bit)
 
Join Date: Jan 2002
Location: Edmonton, AB, Canada
Posts: 628
open up the command prompt and use this command
del "\\?\c:\path_to_file\name_of_file_or_folder"

include the quotation marks and all characters
that should eliminate the file

Last edited by Trent Steel; 02-15-2005 at 04:57 PM.
Trent Steel is offline   Reply With Quote
Old 02-15-2005, 04:23 PM   #7
Member (8 bit)
 
trelarah's Avatar
 
Join Date: Jul 2003
Location: Thunder Bay, Ontario, Canada
Posts: 251
Thank you Trent Steel.
However there are a few problems since I am very new to this kind of thing.
1) I don't understand 'open up the command prompt', what is that?
2) How do I put in the "path_to_file" if I don't actually know the path?
3) I am very sorry, but this is quite confusing to me.

Any other suggestions, or "how to... for dummies" intructions?
trelarah is offline   Reply With Quote
Old 02-15-2005, 05:47 PM   #8
Blizzard Fanboy
 
spyder003's Avatar
 
Join Date: May 2003
Location: Northrend
Posts: 1,411
Removal Instructions

If your AV isn't finding it, you're not going to be able to get rid of the files. Look at the bottom of the link for instructions on manually cleaning up the registry.

You can try downloading and running The Cleaner, it specializes in trojans. Maybe that will find it for you.

Edit - Look next to the wini.exe entry in msconfig, it should give you a pathname for where the file is hiding. It might just point you towards the registry though.
spyder003 is offline   Reply With Quote
Old 02-15-2005, 06:29 PM   #9
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 37,776
Use the Windows Search function - and tell it to include system and hidden files.
glc is offline   Reply With Quote
Old 02-18-2005, 01:21 PM   #10
Member (8 bit)
 
trelarah's Avatar
 
Join Date: Jul 2003
Location: Thunder Bay, Ontario, Canada
Posts: 251
spyder003, the trojan that your link talks about is called "Backdoor.Optix.04.d", that (from what I can tell) is not what I have. However I still downloaded THE CLEANER, and updated my AV but still no luck finding/removing the file. And when I look next to the wini.exe entry in msconfig, it does not give me the pathname, it's just blank.

glc, I tried using Windows Search function (incld. system and hidden files), but that didn't work either.

anyone have any other suggestions?
trelarah is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:42 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2