wins32.exe - virus? trojan? malware?

From: MJ (mstanton_at_nospam.matrixcc.com)
Date: 07/05/05


Date: Tue, 5 Jul 2005 12:11:55 -0400

We noticed the other day that no one could access any network shares on one
of our W2k servers. This happened once before, and we found a
virus/worm/trojan (whatever you want to call it) that was the culprit. So
we ran new virus scans and spyware scans and found nothing. However, in the
registry under HKLM/Software/Microsoft/Windows/CurrentVersion/Run - there
was an entry for wins32.exe. Googling this filename turned up many results
listing the file as a worm/trojan, but none of the descriptions of where to
find it and how to get rid of it worked. In the registry the name is
wins32.exe and the data says C:\Windows\System32\wins32.exe. When we delete
the registry entry, it recreates itself. In the system32 folder you can
only see it if you uncheck "Hide protected operating system files". We
renamed it there, whacked the registry entry again, but it still returns -
recreating itself as a hidden system32 file and in the registry. Luckily,
this server is not critical to our day-to-day operations, so we've unplugged
it from the network. This file does not exist in any of our other W2k
Servers, so we're pretty sure it's a bad file. We are just at our wits end
trying to remove it!! Any help/ideas would be greatly appreciated!!

MJ



Relevant Pages

  • Re: Losing network shares across multiple machines on Windows 2003
    ... Are you running a firewall on either the clients or the servers? ... while all other machines can continue to happily use the network. ... Network shares map to more than just one file server - ie, ... On the client, it just notes which activity failed - ie, ...
    (microsoft.public.windows.server.general)
  • Re: event id 5719
    ... I triedto input that registry entry also and see what you mean. ... when attempting to logon a domain, ... Windows 2000 Domain Controller is available for domain. ... There are currently no logon servers available ...
    (microsoft.public.windows.server.general)
  • Re: wins32.exe - virus? trojan? malware?
    ... >we ran new virus scans and spyware scans and found nothing. ... >renamed it there, whacked the registry entry again, but it still returns - ... >Servers, so we're pretty sure it's a bad file. ... it's best to post such help requests on alt.comp.virus ...
    (microsoft.public.win2000.security)
  • Re: Searching Network Share Permissions
    ... every network shares from about 100 Windows Server 2003 servers we have ... list only the network shares that have such permissions. ... useful to scan a specified group of servers. ... it lists both file and printer shares. ...
    (microsoft.public.scripting.vbscript)
  • Re: W32/Delbot-AK
    ... We have attempted to clear using sophos across servers. ... download and execute a file from a remote location to \radi.exe. ... delete that file and registry entry - or just scan with Sophos. ...
    (alt.comp.anti-virus)