Google Answers Logo
View Question
 
Q: What is Windllloader.exe??? ( No Answer,   4 Comments )
Question  
Subject: What is Windllloader.exe???
Category: Computers > Operating Systems
Asked by: mweaver54-ga
List Price: $5.00
Posted: 14 Jul 2003 21:47 PDT
Expires: 13 Aug 2003 21:47 PDT
Question ID: 231125
I have been trying to restore my computer from a virus attack.  The
latest message I get I cannot seem to find an answer for.  When I
launch Windows Explorer I get a box that says "Program not Found" and
inside the box it says "Windows cannot find windllloader.exe"  "This
program is needed for opening files of type "Application"

Where can I find this file??  What does it do?

Mark

Request for Question Clarification by missy-ga on 14 Jul 2003 22:14 PDT
Hi Mark,

Are you quite certain it isn't "winloader.exe"?

--Missy

Request for Question Clarification by livioflores-ga on 14 Jul 2003 22:54 PDT
Hi!!

Please go to Start --> Run and type msconfig in order to execute the
"Microsoft System Configuration Utility" and check the Startup tab.
See if some "strange" program is listed. Uncheck this program and
reboot. Provide us the list if you are not sure.
You can also visit this page for reference:
"How to Use MSCONFIG"
http://netsquirrel.com/msconfig/

Let me know how it works.

Regards.
livioflores-ga

Request for Question Clarification by livioflores-ga on 14 Jul 2003 23:01 PDT
One more thing:
windll.exe is part of a trojan (virus) software, may be you deleted
and eliminated the virus, but windows still have trying to start it.

Request for Question Clarification by livioflores-ga on 15 Jul 2003 09:33 PDT
Try run msconfig in safe mode, you can do this by pressing the key F8
during the startup (inmediatly after the BIOS info screen).

"To get into Windows 98 / ME safe mode as the computer is booting you
press and hold your "F8 key" on the top of your keyboard or press and
hold the left or right Ctrl key as the computer is booting. If done
properly you should get into the "Windows 98 / ME Startup Menu"
similar to the below screen example. In this menu choose option 3 by
pressing the 3 key and press enter.
Note: With some computers if you press and hold a key as the computer
is booting you will get a stuck key message as the computer is
booting. If this occurs instead of pressing and holding the "F8 key"
tap the "F8 key" continuously until you get the startup menu."
Getting into Windows Safe Mode:
http://www.computerhope.com/issues/chsafe.htm#01 

Tell us how it works!!!
Answer  
There is no answer at this time.

Comments  
Subject: Re: What is Windllloader.exe???
From: amitbhargava-ga on 14 Jul 2003 22:19 PDT
 
your machine registry is still infacted by some Torjon Virus please
make sure that machine is virus free.

About winloder.exe :
Remote Access / Steals passwords / EXE Binder May alter Win.ini and/or
System.ini. Based on SubSeven. Some of the files are packed with the
UPX 1.01. It comes with several different skins and supports plug-ins,
so features may change. With Undetected, the hacker is able to write
and execute different types of scripts, such as .bat and .vbs files,
on the infected machine.

regards

Amit
Subject: Re: What is Windllloader.exe???
From: mweaver54-ga on 15 Jul 2003 03:51 PDT
 
Thank you folks for all of your helpful ideas.  When I run msconfig I
get the same error message.  I have scanned the drive with Norton,
McAfee and PC-cillin and no viruses are detected.  It may help to know
that this all started immediately after I did a Scandisk and defrag on
my hardrive.  Any other ideas out there?
Subject: Re: What is Windllloader.exe???
From: jimmyjrosu-ga on 15 Jul 2003 09:19 PDT
 
more info can be found here http://support.microsoft.com/?kbid=319813
Subject: Re: What is Windllloader.exe???
From: themza-ga on 17 Jul 2003 15:48 PDT
 
Un-Detected 2.3a is a small trojan similar to the SubSeven trojan.
Un-Detected supports plugins, which means new features could be
created any time. The plugins are uploaded to your computer's windows
directory in the form of pluginname.dll. This trojan also comes with
an edit server. The edit server allows the infection routine,
filenames, port and password to be changed. There is also a file
binder with the edit server. The file binder can make a normal file
and the Un-Detected server combined look like a RAR archive or install
file. This version of Un-Detected just was recompiled to avoid virus
detection.

How To Remove  
===========================

*Please note %trojan file% is your "windllloader"

===========================

Manual removal: Note that trojan file could be any file. 

Open the system.ini in Notepad (Usually c:\windows\system.ini) and
rename the key under [boot]

shell=Explore.exe %trojan file%

to only:

shell=explore.exe

===========================

Now open the win.ini(Usually c:\windows\win.ini) and remove the key
under [Windows]:

load=%trojan file%

===========================

Now click Start-> Run and type regedit

In RegEdit navagate to:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Once there click on CheckRegistry and press delete.

---------------------------------------------

Now navagate to:

HKEY_LOCALE_MACHINES\Software\Classes\exefile\shell\open\command 

Change what says 

"%trojan file%" "%1"%* 

to 

"%1"%*

Reboot the computer or close %trojan file% using ctrl+alt+delete.  

Delete the trojan file %trojan file% in the windows directory.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy