Computing.Net > Forums > Windows 95/98 > win.ini virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

win.ini virus

Reply to Message Icon

Name: alonos
Date: July 1, 2003 at 08:20:29 Pacific
OS: win 98
CPU/Ram: pent 4
Comment:

i've run a virus scan on my computer and found these files:
C:\windows\sysbckup\rb001.cab
C:\windows\sysbckup\rb002.cab
C:\windows\sysbckup\rb003.cab
C:\windows\sysbckup\rb004.cab
C:\windows\sysbckup\rb005.cab

norton AV 2003 cannot quarantine them. since they are win.ini files, i was afraid to delete them in order not to cause moer damage to the existing.

a search for this file in www.google.com brought me to your site.
there i've found a similar case, but a little long ago...:(this is the attach...)
After having trouble with the Dupator virus, I recently bought Norton SystemWorks 2003. I had it scan a few nights ago and it found the W32.Opaserv(win.ini) virus. It found and cleaned over 1900 files but still had 3 left over that it couldn't quarantine or delete. Two of these were C:\windows\sysbckup\rb000.cab and C:\windows\sysbckup\rb001.cab. Both of these were WinZip files that had just been put into my computer a few days ago. (I have since downloaded that patch.)Assuming that these weren't important files since they were only two days old and had been created during a time I wasn't on the computer, I deleted these. I ran Norton again and found that now I only have 1 infected file left. It's C:\recycled\nprotect\00001277.cab. I have no idea what this is. I have tried searching for it in my computer and within the recycling bin (using the Norton Protected UnErase Wizard) and there is nothing about it.
So, how can I find and get rid of this last infected file?

I've searched my computer for files like brasil.pif, brasil.exe, marco!.exe, etc. and havent found any of those. My Win.ini file *appears* to be normal. I don't have the renamed Put.ini or Gay.ini. I don't know where this is coming!

------------------------
back to my case:
i understand that he had a similar problem. what should i do? should i try to first delete those files and then (if it won't work, like in his case) to try and delete them from the dos?
please send me an explenation as detaias possible becase have a lack of knowledge in computer as you might have already assumed.

thanks !

alon



Sponsored Link
Ads by Google

Response Number 1
Name: Frenchie
Date: July 1, 2003 at 09:06:24 Pacific
Reply:

Hi alon, hi everyone,

>C:\windows\sysbckup\rb001.cab and similar...
These files are backups of the registry Windows 98 makes every day at first start of the day.

>C:\recycled\nprotect\00001277.cab.
As you understood, this file is already in the bin... so you could delete it emptying the bin

> 1900 files
Wow! do you still have unaltered files on your disk? ;-) (just kidding)

What about saving your data (your own files) and reformatting, reinstalling everything on the computer? I rarely suggest that as I prefer to try to cure and fix but you waited for so long that many parts of the system seem to be infected!

HTH

Have a good day,
Gérard from Paris, France


0

Response Number 2
Name: dave
Date: July 1, 2003 at 09:12:02 Pacific
Reply:

Those are registry backup files. Read about it here


0

Response Number 3
Name: barry
Date: July 1, 2003 at 09:35:09 Pacific
Reply:

Anti-virus programs are not perfect. They will sometimes report false positives and sometimes miss real viruses. It appears that those Registry backup files were mistakenly thought to contain viruses. Norton 2003 is pretty dumb if he thought a 'CAB' file could do any damage to your system.


0

Response Number 4
Name: Derek
Date: July 1, 2003 at 14:28:46 Pacific
Reply:

Since all of the cab files mentioned contain win.ini it may have been around for 5 days or so, and therefore be infected in each case (together with your current win.ini).

Maybe Norton isn't so dumb, because if you restored the registry it would also put back win.ini from one of those cabs.

Have you tried right clicking your current win.ini and asking your AV to check the file?
Take a copy of it and save it elsewhere as a text file. Then you can peer at it with no risk of messing anything up.

Derek


0

Response Number 5
Name: Derek
Date: July 1, 2003 at 14:41:52 Pacific
Reply:

You can do it with a hosts file (not just pop-ups):

http://yoyo.org/~pgl/adservers/

When you download the file I would advocate changing all the 127.0.0.1 entries to 0.0.0.0
(use Replace option in WordPad).

Derek


0

Related Posts

See More



Response Number 6
Name: Frenchie
Date: July 1, 2003 at 15:31:08 Pacific
Reply:

Hi Derek,

>You can do it with a hosts file (not just
>pop-ups): etc.
???
Are you sure you didn't post in a wrong thread? wasn't it destined for anti-ad?

Have a good day,
Gérard from Paris, France


0

Response Number 7
Name: barry
Date: July 1, 2003 at 15:31:11 Pacific
Reply:

Excellent point Derek. I didn't think of that. I hate Norton and was too quick to criticise. :-)


0

Response Number 8
Name: Frenchie
Date: July 1, 2003 at 15:33:49 Pacific
Reply:

Hi Derek, hi everyone,

>Have you tried right clicking your current
>win.ini and asking your AV to check the
>file?
>Take a copy of it and save it elsewhere as
>a text file.
Sorry... I don't understand! isn't win.ini a text file?

HTH

Have a good day,
Gérard from Paris, France


0

Response Number 9
Name: Derek
Date: July 1, 2003 at 18:42:11 Pacific
Reply:

oooer....disregard my #5.

Sometimes if I don't refresh "my computing.net" page the entries get out of step.

Apologies (will try and find right thread).

Derek


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: win.ini virus

opaserv win.ini virus www.computing.net/answers/windows-95/opaserv-winini-virus/147055.html

win.ini config.sys etc www.computing.net/answers/windows-95/winini-configsys-etc/112850.html

win ini www.computing.net/answers/windows-95/win-ini/61649.html