This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Your system is infected! Fake desktop backround.

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Something dropped a naughty version of a legitimate Windows file where your OS expects to find it, and a number of other copies elsewhere to make it difficult to remove and replace - tsk, tsk! Do you access to another copy of XP that you can get a legitimate copy of this file from?
Hm, unfortunately this computer came straight from the factory with the copy of XP already installed and I never recieved any CD. Would it be a simple case of finding a computer with XP installed and copying the file I need to replace onto a flash drive?

Would it be a simple case of finding a computer with XP installed and copying the file I need to replace onto a flash drive?

Yup, as long as the PC is fully updated - you don't want an old copy of the file, now do you.
Okay I copied the wininet.dll from my sisters computer. It took some time to install some Windows updates and service pack 3 on the computer, but we got there. I just scanned the wininet.dll while it was still on my flash drive using Jotti's malware scan and this was the result.

http://virusscan.jotti.org/en/scanresult/8…a32835192b41567

My infected file is 898KB and the one I copied from my sisters computer is 650KB if that information is any use.
Right click the file you got from your sister's PC and select Properties. Under the Version Tab you should find the version number - what is it?
That's a seriously old file - i've got a version numbered 8.0.6001.18806. I've attached a zipped folder with a copy of that in. You'll need to unzip it and then Copy and Paste it to the following folders:

C:\WINDOWS\system32
C:\WINDOWS\system32\dllcache


When you get the prompt to overwrite, say OK.

Let me know how you get on.
I was able to overwrite it in C:\WINDOWS\system32\dllcache without a bother. But when trying to overwrite the file in C:\WINDOWS\system32 I get this error message. Cannot copy wininet: It is being used by another person or program. Close any programs that might be using the file and try again.
Sorry, my bad. Try to replace the file in Safe Mode - this should be more successful.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Nope, still will not let me overwrite even in safe mode. I had a similar problem once when trying to delete a partially downloaded file, I closed down explorer.exe and just deleted it using command prompt. But this is more complicated than that… all I had to do that time was type in del and the file path.
Rename the existing file to wininet.old, reboot the PC and then copy and paste the new one into the System32 folder. If you have any issues with this, simply renaming the old file back to .dll will undo things.
It looks the two files have been replaced by the clean version, the file size is smaller than it was and I done a virus scan using that online tool and nothing was found. But I have this feeling that if I reboot it is going to come back. What happened was that, When I tried to rename the file to .old and reboot the computer, explorer.exe refused to start so I renamed the infected file back to .dll and then deleted it using command prompt and replaced it with the clean file.
Nice job!

Files to delete:

c:\windows\system32\wincode.dat
c:\windows\system32\krncode.dat
c:\windows\system32\pwrcode.dat


File to replace, or just to add to the folder if they aren't present:

c:\windows\system32\dllcache\powrprof.dll
c:\windows\system32\dllcache\kernel32.dll


I've attached my copies of powrprof.dll and kernel32.dll to save you hunting for copies.

Once you've done the above, you'll need to rename the following files:

c:\windows\system32\kernel32.dll to c:\windows\system32\kernel32.old.
c:\windows\system32\powrprof.dll to c:\windows\system32\powrprof.old

As long as you've replaced the two .dll files in the dllcache folder, Windows will use these copies to replace the renamed ones when you reboot - i've just done this on my system to check.
Once you've rebooted, check that the files in the System32 folder are the legit ones by right clicking them and selecting Properties from the context menu. They should have the same file size as the copies i've uploaded.

Let me know how you get on.
Delete any copies of ComboFix you have onboard and then try to download a fresh copy and run it as per the instructions I posted earlier - i'm counting on you to make this work, you know! :unsure:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI