winini.exe do i need to, and if so how do i get rid of this

Discussion in 'Malware Help (A Specialist Will Reply)' started by greenhorn, Feb 19, 2006.

  1. greenhorn

    greenhorn Private First Class

    my computer, in working on the internet, has been fritzing out on me. ran thru the steps outlined by this site, and nothing showed up with the other antivirus and spyware programs till panda came up with the stuff in the attached file. i deleted the first two. but the winini.exe says i cant delete it because some other program is using it. what should i do :confused:


    would also like to thank the people responsible for this site
    its a godsend
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MG's.

    Please complete the remaining step of the READ & RUN ME and attach the BitDefender log (if it shows anything) and also complete step 7 and attach the HijackThis log.
     
  3. greenhorn

    greenhorn Private First Class

    ummm....the bitdefender....kinda......i ....i thought i saved it, but now i cant find it....sorry......
    is there anyway i can retreive it off line?

    heres the hijackthis file at least
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not installed HijackThis properly per step 7 of the READ ME but right now it does not matter since there is no real malware showing in your log.

    I also see no signs of any winini.exe process running. Where are you seeing this?
     
  5. greenhorn

    greenhorn Private First Class

    the winini.exe showed up in the activescan from panda
    i can go to the exe file and try to delete it, but it says some program is using it

    sorry about the hijack this wrongdoing
    will get on that.
     
  6. greenhorn

    greenhorn Private First Class

    think i got hijack this set up right this time


    i did learn starting up with everthing in the msconfig start up checked causes chaos in my computer
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What items were you previously not loading?

    And define in greater detail what you mean by "chaos"?

    What is the below process for? Is this some junk from your ISP?
    O4 - HKLM\..\Run: [SSRunScript] "C:\Program Files\Support.com\Charter\bin\SSRunScript.exe" /script "C:\Program Files\Support.com\Charter\vbs\verifyconnection.vbs" /args //b startupdelay

    Also is the below something you added for your ISP?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://proxy/:8080

    Do you use the Viewpoint and Real Player programs?

    Have you tried booting in safe mode and deleting the the winini.exe file? Make sure it is not Read Only.
     
    Last edited: Feb 20, 2006
  8. greenhorn

    greenhorn Private First Class

    both those are things of my ISP.
    i have no clue what the SSrunScript bit is tho, other than that. :confused:

    i mean chaos as in taking forever to load up, and sluggish after it is running

    dumped the realplayer since posting
    and never use viewpoint

    will try the safeboot delete on winini.exe
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I only mentioned two things. One of them was SSRunScript.exe. So is it part of your ISP or not? I would think so. You should ask them if those lines are actually needed.
     
  10. greenhorn

    greenhorn Private First Class

    the ssrunscript is part of some help, support, troubleshooting, program from my ISP

    does that make sense?

    what the hell is it?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what it is! It looks like it is used by your ISP to run a script after startup of your PC to verify your connection. I'm not sure why they always need to do this everytime you boot your PC but I guess that is the way they work.

    What's the story with winini.exe ? Did you find it and delete it in safe mode or not?
     
  12. greenhorn

    greenhorn Private First Class

    even in safe mode i can not delete the winini.exe file.
    it says it is being used by some other program or person?
    :confused:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download GetRunKey125b.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey125b.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment.

    These scan will only take a few second to run. It will take longer for you to attach than it does to run. :)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Question: Is this PC on a network with other computers? If so, you better run all cleaning procedures on all of them.
     
  15. greenhorn

    greenhorn Private First Class

    here's the file
    thanks for your help

    this is a lone home computer

    on a side note my internet started fritzing out again
    what got me started on looking for something in the first place. it never finishes loading pages, it got better after running all the virus programs in safe mode and running the online virus scans....for a couple days..but now its back to before. and it wont download alot of things.......its weird...
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now Download
    - Pocket Killbox

    Now run Pocket Killbox and extract it to its own folder. Then run killbox.exe.

    Now highlight the lines below and press the Ctrl key and the C key (CTRL-C) at the same time to copy them to the clipboard:

    C:\WINDOWS\winini.exe
    C:\WINDOWS\System32\winini.exe

    Now go to the Killbox application and click on the File menu and then select the Paste from Clipboard menu item. In the Full Path of File to Delete box you should see the first file. If you click the dropdown arrow by this box you should see the other file. Make sure that they are both there.

    Click on the Delete on Reboot option and then click on the red circle with a white 'X' in to to delete the files. Killbox will tell you that all listed files will be deleted on next reboot, click YES. When it asks if you would like to Reboot now, click YES. If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

    Your system will reboot now.

    After reboot attach a new HJT log and also tell me whether you still see the winini.exe file. If so, where do you see it.
     
  17. greenhorn

    greenhorn Private First Class

    when i paste from clipboard only the one file shows up in the main box and the drop down box in killbox.

    am i doin something dumb here???
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! Just complete the steps! And let me know the end result.
     
  19. greenhorn

    greenhorn Private First Class

    thanks
    here ya go
    :)
     

    Attached Files:

  20. greenhorn

    greenhorn Private First Class

    i think i made a mistake on the last one....
    here is a new log
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you did not tell me the end result! What about the winini.exe file?
     
  22. greenhorn

    greenhorn Private First Class

    the winini.exe seems to be gone
    looked manualy
    and ran the windows search
    :)
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  24. greenhorn

    greenhorn Private First Class

    thank you so much for your help chaslang
    and for putting up with me
    much appreciated:D
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     
  26. greenhorn

    greenhorn Private First Class

    hi chaslang
    this is going to sound funny
    but my computers back to the way it was.
    getting ready to run the steps again, but wanted to put out there that it only downloads 74% of any file, and im assuming that it does the same with webpages cause it never finishes loading them either?
    does that sound like anything in particular to you?

    seems kinda weird that its always 74%?
    right now this page still isnt loaded

    anyways going to run the steps this afternoon and will post the results.

    74%??????
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In only 15 days???? ;)

    Not sure what's up! But yes it would be best to start over.

    Did you install Firefox and are you using it? If not, try it and tell me how web pages load.
     
  28. greenhorn

    greenhorn Private First Class

    been using firefox all along (i like it alot better)
    when it does go online (about 2/3 of the time) it loads most everything, but a few pics and acts sluggish.
    with firefox the bar on the bottom right never finishes and in internet explorer it always says theres a couple items remaing.
    i have mcafee antivirus and spybot and adware se, none will update
    and i cant download new definitions off majorgeeks, like i said it will get to 74% and just stop?

    will run the steps tonight. (its a nice day out here, gotta enjoy it)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run with what you have and if you cannot do the online scans make sure you tell me.
     
  30. greenhorn

    greenhorn Private First Class

    hi chaslang
    somethings wrong with my windows installer?
    it wont let me install anything now!!?!?!?
    i need to install counter spy again cause i cant run the windows stuff...microsoft wont let me download those other programs from them......not nessicarily their fault.....
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said in msg # 29, just run with what you got and attach all logs that you can get to run.
     
  32. greenhorn

    greenhorn Private First Class

    worked good for a day after doing what i could, the first online scan found nothing
    wont let me upload anything
    cant attach files, will try later
    damit
     
  33. greenhorn

    greenhorn Private First Class

    i think i got it
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There really is not too much showing in your logs but you can do the below.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?www.viewpoint.com&6&&unknown&unknown&www.viewpoint.com&6&&unknown&unknown&www.viewpoint.com&6&&unknown&unknown&www.viewpoint.com&6&&unknown&unknown&www.viewpoint.com
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    And if you do not know what the below is for add it to the fix list too.
    O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://210.134.20.21/kxhcm10.ocx
    After clicking Fix, exit HJT.

    You may want to try using another browser like FireFox from the How to protect thread and see if it works any better.
     
  35. greenhorn

    greenhorn Private First Class

    did all that jazz
    working good still

    i always use firefox,
    been using it for about 6 months now
    love it
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So is everything working okay now?

    What version of FireFox are your running?
     
  37. greenhorn

    greenhorn Private First Class

    fire fox 1.0.7
    right now i had to use internet explorer because fire fox wouldnt load the forum page????
    microsoft probably put a bug in my computer for deserting them

    computer still is acting weird
    will work great for a bit...then will never finish loading a page for awhile....then will work just fine again......even IE

    and i keep getting the little yellow microsoft sheild
    poping up on the tool bar to say that its downloading updates. and never does anything. then disapears for a while, then pops back up???

    i think im a loss cause chaslang
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's the reason you need to click on the links we give in our procedures. You cannot assume you have the correct version. FireFox is on 1.5.0.1 ! You need to update. If you are so far off with this, it make me wonder whether your other tools are really current.

    Get this: Mozilla FireFox

    You should have follow all the steps in the How to protect thread and click on all the links to check them out!!!!
     
  39. greenhorn

    greenhorn Private First Class

    :eek:

    wow i really blew it there........
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    LOL! Yep!

    Are you still having problems?
     
  41. greenhorn

    greenhorn Private First Class

    yeah.....i lost my dignity.........
    :rolleyes:

    but at least the computer seems to be running good right now.
    it seems not to act as crazy when i disable zonealarm,
    and suggestions on a different firewall?
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps you just do not have things setup properly thru ZoneAlarm. It will not matter what firewall you have if you do not set things up properly for all your applications. Actually I prefer ZoneAlarm and it is really one of the easier to setup and configure. Many things are auto configured for you. Others are not so automatic.

    You could try one of the others in the How to Protect yourself from malware! thread! Personally I would use Sygate anymore since it is no longer supported and it can be a pain setting it up correctly. ZA is still the easiest. Are you using the free version? Maybe you should just uninstall ZA, reboot, download the latest version and reinstall ZA.
     
  43. greenhorn

    greenhorn Private First Class

    computers acting up again

    it seems to have something to do with pics
    it bogs the computer down and wont load'em
    like right now writing this the smilies and most of the buttons up above just show the little thingy that means a pic is supposed to be there, and firefox says its been trying to load for 200 secs and counting so far?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds