PDA

View Full Version : Cannot Delete a Virus


BLiNG
June 23rd, 2003, 01:00 AM
I accidently downloaded an infected file from Kazaa and i go to delete it and it says "Cannot delete h4x0r: the specified file is being used by windows" . So i go to msconfig and i turn it off on startup, that did not work and also in the win.ini. I made a wininit.ini file and had the following "[Rename] nul=C:\Windows\h4x0r.exe" Which was supposed to delete it, which it did not. Im wondering if i typed the wrong command for the wininit.ini or what i should do, thanks. OS = win98

Janus
June 23rd, 2003, 09:31 AM
that and do u have an anti-virus protection? sounds like you dont, after you delete it I recommend getting a good one, pm me on irc and ill help you out ;)

BLiNG
June 23rd, 2003, 02:20 PM
Here is what i have done so far, and its not gone. I updated my Virus Scanner (Norton 2002 pro), it found the virus and couldnt not fix it or delete it. I restarted in safe mode and it still wouldn't let me delete it, giving me the same error telling me its in use by windows. In the virus scanner here is what it's called. File name: h4x0r.exe , Virus name: Trojan.DiabKey and it says repair failed. Also along with this virus is a file called h4x_6-23-03_3_MISC.ztd. And when i open this file here is what it says:
Date of log: 2003-06-23
Started logging at 11:06
RAS Cached Passwords:
11:07:47 - Find: Files named oleacc32
oleacc32
11:11:36 - Files to Scan
All Files (*.*)
11:11:42 - Files to Scan
h4x0r
11:13:24 - Find: All Files
x´D

I have deleted the file oleacc32.dll. But still cannot get rid of this virus:(

philly
June 23rd, 2003, 02:46 PM
Reboot your comp to the dos prompt (you can do this by creating/using a boot disk and selecting boot without cd support). At the prompt type delete c:\windows\h4x0r.exe and hit enter. this should delete the file. You can double check by doing a dir lookup, change to the windows dir by doing a cd\windows. Then type dir *.exe / and see if that file is gone.

BLiNG
June 23rd, 2003, 03:16 PM
Thanks man that worked, and all the infected files are now gone.:D