From: jase on 05/24/2003
This could be a trojan or a virus...
First, go to Start, then Shutdown. Select 'Restart computer in MS-DOS mode.' and click ok. This should put you at a C:\windows\ prompt.
To see if your infected, type:
and if your infected you should see a file listed at 347,136 bytes. This is wincrash.
If this file is indeed there, to remove it type:
Now type exit to return to windows. You will see numerous error boxes saying windows cannot start server.exe. This is normal and a good thing, as server.exe was the trojan.
To make the errors stop, you will need to edit your win.ini file.
To do this, use Windows Explorer, or Windows itself to open C:\WINDOWS\ and find the file win.ini
Double clicking this icon will open win.ini in a text editor. At the top you should see a line that reads
Select this line and delete it, then click File and Save. Close the text editor.
At this point you are uninfected however the trojan already deleted your copy of regedit, and there is a registry line left (however it cant do much damage without the server.exe file.)
If you want to stop at this point to backup your data and reinstall windows, that would work too. If you cant afford to reinstall windows again, its possible you can reinstall regedit using the information below:
This example assumes your CDROM is D: and the harddrive is C:
It is also for users with the Windows 95 install CD (not 98).
Go to Start -> Programs -> MS-DOS Prompt.
At the msdos window, type the following command, replacing your cdrom drive letter if need be:
extract /L c:\windows d:\win95\win95_02.cab regedit.exe
This should reinstall regedit.exe
For users with the Windows 98 Upgrade CD, you can use the following command:
extract /L c:\windows d:\win98\win98_42.cab regedit.exe
It is untested at this point if the Windows 98 Full cd has regedit in the same CAB, so this may not work on full windows 98 cdroms.
The final step is to remove the registry line.
Click Start, and go to Run. In the box, type regedit and click OK.
When regedit starts, you will see a file-like tree on the left hand panel. Open the folders to follow the path:
At the end, click on 'Run', and the right hand panel should change.
Look on the right hand side for the key:
WinManager = "c:\windows\server.exe"
Right click on that line only and choose delete. Close regedit and your done!
PortugueseBrazilian PortugueseGermanDutchLatin American SpanishSpanishEuropean SpanishFrenchJapanese (Shift JIS)DanishIcelandicFinnishItalianNorwegianSwedishRussian (CP 1251)Croatian (CP 1250)Hungarian (CP 1250)Polish (CP 1250)Czech (CP 1250)Serbian (Latin)Slovenian (CP 1250)GreekWelsh