Computing.Net > Forums > Security and Virus > Viruses Altering .ini files

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Viruses Altering .ini files

Reply to Message Icon

Name: Mark
Date: December 5, 2003 at 09:01:17 Pacific
OS: NA
CPU/Ram: NA
Comment:

I just thought I'd pass along some info that made my life easier.
More and more viruses and trojans are adding themselves to the system.ini and win.ini files, e.g "Shell=Explore.exe" Changed to "Shell=Explorer.exe dust.exe" is what W32.HLLW.Studd uses for startup in system.ini. Delete the file "dust.exe" and you could get the "Error Loading Explorer.exe You must reinstall Windows" message. Remove "dust.exe" from the ini and it's fixed. Through this forum I found a freeware utility called ChangeINI, that will alter the entry no matter what the change was: http://elmo.winsite.com/bin/Info?500000027109
I you can't boot, a batch with this utililty run from dos is valuable. Or, in my case, you can remove the garbage in the ini files on large number of computers with a batch run from the login script as a big part of virus control.



Sponsored Link
Ads by Google

Response Number 1
Name: Imp
Date: December 5, 2003 at 21:26:09 Pacific
Reply:

Hello Mark,
I don't remember in my life any success when touching the contents of win.ini or system.ini in a computer....
I don't know who told you that it could be done, these vitals programs are modificated only by windows when runing your computer.
As you don't mention anything about your config (all information are bookmarked as NA)
I just suggest in order to make easy the problem, to reinstall totally your windows OS to rid off that situation, otherwise you get white hairs prematuraly....


0

Response Number 2
Name: Mark
Date: December 6, 2003 at 14:38:16 Pacific
Reply:

Many programs alter ini files, including a growing number of viruses. In win.ini, its Run= and Load=; in system.ini, its Shell=Explorer.exe. These are the only ones I modify. Nothing needs to be there, ever. There are better ways to start a program when booting. As far as reinstalling windows, I oversee about six thousand computers, so that's not an option. Reinstalling is the last refuge of the ignorant, no offense intended.
If the ini files bother you, I won't tell you what I do to the registry with batch files.


0

Response Number 3
Name: Gerard
Date: December 17, 2003 at 23:37:18 Pacific
Reply:

Mark,

This might just be the answer to the program I've been looking for. I've manually removed all instances of Dust.exe on my system, and found after a reboot that my Explorer was gone (XP Pro).

Do a <CTRL><ALT><DEL> and the TaskManager starts up, from there you can start Explorer.exe manually. So I know the software is working.

Before I read your solution, I was already in the middle of reinstalling, and I'm now stuck in a loop ... 'setup is being restarted' ... I can't get out of.

I've reinstalled Win98 on my system, to be at least able to start a normal DOS prompt, but I can't touch my NTFS drives.

Can you, Mark, or can anyone help me out in removing the Dust.exe line in system.ini on a NTFS drive from DOS or Win98.

Any reply is greatly appreciated.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Viruses Altering .ini files

Can a virus hide in files that have www.computing.net/answers/security/can-a-virus-hide-in-files-that-have/11368.html

Virus, pos.tmp files, C: has red X www.computing.net/answers/security/virus-postmp-files-c-has-red-x/22086.html

Multiple .ftt and desktop.ini files www.computing.net/answers/security/multiple-ftt-and-desktopini-files/2669.html