Computing.Net > Forums > Security and Virus > killing winserv.exe trojan.imiserv.

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

killing winserv.exe trojan.imiserv.

Reply to Message Icon

Name: rd1516
Date: January 12, 2003 at 21:06:43 Pacific
OS: pentium
CPU/Ram: 80
Comment:

Hi....
I too am having problems with my puter. it's always giving me the "error" and end task crap. I'm running windows 98 and Today I loaded the Eanthology stop sign and it said I have an infected c:\windows\winserv.exe trojan.imiserv.
Now, I have AVG AND ZOne alarm and neither picked this up, I also tried to find this in my computer and it shows nothing. What the heck do I do now? PLEASE HELP!
Thank You in advance!



Sponsored Link
Ads by Google

Response Number 1
Name: Imp
Date: January 12, 2003 at 21:30:33 Pacific
Reply:

Hello Rdl,
When you are corrupted by a trojan, you need quickly a program specialized to detect and eradicate it... Zone Alarm is a firewall, it protects you as long as you are safe, but absolutely not when you are corrupted.
Trojan has two parts: the "spread" and the "worm". As long as you have the "worm" hiden somewhere in your hard drive the virus will stay active as soon as you connect to internet.
I recommend you to download the program "Trojan Remover" which use two differents scan to find and erase Trojan's betrayals.....
This is a freeware for one month:
http://www.simplysup.com/tremover/details.html
Good luck....


0

Response Number 2
Name: Tom41
Date: January 12, 2003 at 21:42:52 Pacific
Reply:

Click Start > Run > type msconfig and click OK. Click the Startup tab. Locate the following two entries and uncheck them:

Win Server Updt C:\Windows\wupdt.exe
Win Server C:\Windows\winserv.exe

Click Apply/OK and reboot. Do a find files for: wupdt.exe and winserv.exe and delete them.


0

Response Number 3
Name: rd1516
Date: January 12, 2003 at 23:10:42 Pacific
Reply:

In response to tom....
I tried that, but when I find the files after I rebooted and try to delete them they says "The file wupdt is a program. if you remove it you will no longer be able to run this program or edit some documents". and it says the same thing on the winserv.exe

What's going to happen if I delete them?


0

Response Number 4
Name: Tom41
Date: January 12, 2003 at 23:26:35 Pacific
Reply:

Nothing, They are the virus. Delete them.


0

Response Number 5
Name: rd1516
Date: January 13, 2003 at 00:43:49 Pacific
Reply:

IMP.....I got the trojan remover too, big help (NOT) 30 minutes of loading and scanning and it said it found NOTHING but whenn I did another eanthology scan, there was the trojan once again!

TOM.....
OK, I deleted them both...I hope it works...and THANK you both!


0

Related Posts

See More



Response Number 6
Name: Tom41
Date: January 13, 2003 at 01:10:43 Pacific
Reply:

"IMP.....I got the trojan remover too, big help (NOT) 30 minutes of loading and scanning and it said it found NOTHING but whenn I did another eanthology scan, there was the trojan once again!"

Hehe..That's because Trojan Remover isn't as good as he thinks it is...


0

Response Number 7
Name: AndyM
Date: January 13, 2003 at 07:22:39 Pacific
Reply:

Usually Trojans do not have "worm" payloads. They have no way of self spreading.
There are a few exeptions to this rule but this is not one of them.
Your correct in saying they have two parts but they are the "Client" and "Server".
The server is the infection part and the Client is used to parse commands to the infected machine EG> Open CD-Rom Tray, Upload / Download files...etc
The server.exe (could be called anything - in this case it's WinServ.exe) is installed on your machine and then uses Windows to start everytime the operating system starts. There are only a handful of ways these files can "autostart", the oldest of the methods being; Win.ini, System.ini and HKCU & HKLM Run Keys.
These methods are all documented on the Internet;

http://www.megasecurity.org/Trojaninfo/auto_start_methods.htm

Installing good Antivirus is excellent practise and I would highly reccomend using Kaspersky Labs AV (www.kasperskylabs.com) Probably the best AV on the market!
This will NOT guarentee infection as all AV's can only scan for what it knows so by installing some Anti-Trojan Software is good practise as well.
An excellent piece of software for this is TDS-3 (http://tds.diamondcs.com.au/)

Removal Instructions for the backdoor you currently have on your machine can be read here;

http://vil.nai.com/vil/content/v_99813.htm

Hope this helps


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: killing winserv.exe trojan.imiserv.

winservs.exe NOT winserv.exe - troj www.computing.net/answers/security/winservsexe-not-winservexe-troj/1937.html

Trojan Horse attached to winserv.exe www.computing.net/answers/security/trojan-horse-attached-to-winservexe/385.html

winservs.exe removal www.computing.net/answers/security/winservsexe-removal/2911.html