Computing.Net > Forums > Security and Virus > Win32.alemod virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Win32.alemod virus

Reply to Message Icon

Name: bdthomas02
Date: May 10, 2006 at 07:28:30 Pacific
OS: Windows XP
CPU/Ram: 2.6 GB and 256 RAM
Product: Dell Dimension 4700
Comment:

I found out my wininet.dll is infected by the win32.alemod virus. Can anyone tell me how to manually delete this virus or any (working) free spyware removal tool that will repair my system? I have downloaded numerous free spyware removal software but you have to purchase the software before it works or the free ones does not work at all. I have spent two days trying to remove this virus but nothing is working. My McAfee virus software keeps displaying that the wininet.dll is infected by win32.alemod and the file cannot be deleted or quarantined. Please help!!!!! I am at the end of my rope because I do not want to wipe out the hard drive and reinstall Windows XP. I have a lot of important files that I need to keep and I am unable to work on my computer without any problems.

Thank,

bdthomas02



Sponsored Link
Ads by Google

Response Number 1
Name: jabuck
Date: May 10, 2006 at 09:12:38 Pacific
Reply:

Will the computer boot and get on line?


0

Response Number 2
Name: dperdomo
Date: May 10, 2006 at 12:44:07 Pacific
Reply:

If your computer work, try to execute:
http://secured2k.home.comcast.net/tools/AntiPuper.exe
A friend fix it with this.


0

Response Number 3
Name: XpUser4Real
Date: May 10, 2006 at 13:25:17 Pacific
Reply:

http://www.precisesecurity.com/computer-virus/antivirus-00011.htm
Has the removal procedure

Hopefully my advice will help you...Please post back with your results....thanks


0

Response Number 4
Name: bdthomas02
Date: May 11, 2006 at 10:15:51 Pacific
Reply:

I tried several suggestions on the internet on how to get rid of this virus along with many software tools and none of it worked. However, I did find a simple code that removed the infected file from my system. After I entered the code I scanned my system and was unable to locate any viruses. If any computer happens to get this terrible virus here is the code to remove it.

Here are the steps:
*Disable your AntiVirus during this procedure.
*Click Start
*Click Run
Type in CMD.exe
Click OK

A command prompt will appear.
Type the following into the command prompt:
*CD %SYSTEMROOT%\SYSTEM32
*DIR /A DLLCACHE\WININET.DLL

If the results show 1 file found, keep going, otherwise you will have to try another method.

*ATTRIB -S -R -H WININET.DLL
*REN WININET.DLL *.VIR
*COPY /Y DLLCACHE\WININET.DLL
*EXIT

Now restart the computer.

Here is an explanation of the instructions:

You have to disable your AntiVirus before doing these steps because if the AV is running, it will prevent access to the infected file. You DO want to manually rename this file but the AV would stop us if it's running.

The Start -> Run -> CMD.exe .. is how we get to a command prompt to do Command line instructions.

Now we want to be in the Windows System folder. To get to this, we use a variable
%SYSTEMROOT% which will always point to the Windows folder. This is for some who have Windows 2000 (\WINNT) or a custom Windows install directory. CD = Change Directory. (CD %SYSTEMROOT%\SYSTEM32)

The DIR /A DLLCACHE\WININET.DLL command shows if there is a copy of WININET.DLL in the DLLCACHE folder. This DLLCACHE folder is also known as the Windows File Protection folder. It contains files that have been digitally signed and that will be used to automatically replace bad files should they be deleted or replaced by new versions in Windows' folders.

If the file is listed, we can continue. First we make sure the attributes for WININET.DLL are NOT Hidden, ReadOnly, and/or System. (ATTRIB -S -R -H WININET.DLL)

Next we rename WININET.DLL file to WININET.VIR (REN WININET.DLL *.VIR)

Ideally, within 2 seconds, Windows File Protection should automatically copy the DLLCACHE\WININET.DLL back to the SYSTEM32 folder (An event log is generated). Let's be sure by manually copying the file. (COPY /Y DLLCACHE\WININET.DLL)

The WININET.VIR file is actually still in memory and will be used until the system is restarted. However all new programs started will begin using the new WININET.DLL immediately. Restart your computer and the locks on WININET.VIR will be released, allowing the Virus Scanner to repair/clean/delete the file.


0

Response Number 5
Name: jabuck
Date: May 11, 2006 at 10:27:46 Pacific
Reply:

Thanks for the great information, some real good stuff.


0

Related Posts

See More



Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Win32.alemod virus

Win32 Weird Virus www.computing.net/answers/security/win32-weird-virus/1414.html

Win32/Parite Virus www.computing.net/answers/security/win32parite-virus/4260.html

Win32:Afcore Virus www.computing.net/answers/security/win32afcore-virus/11885.html