Look for a WnUtils folder on the hard drive, most likely C:\WinUtils . If it's there, go into the registry, find all references to that folder and delete the key(s).
Download and install GiPo File Utilities. (http://www.gibinsoft.net/
Check the registry again, just in case the program loaded code back in there before it was deleted.
Make sure the folder is gone and has not been recreated.
Use a registry cleanup utility to remove any lingering pieces. Norton's works pretty good.
Main Topics
Browse All Topics





by: punarPosted on 2008-11-07 at 16:52:40ID: 22909746
I have the same problem. It appears the file is a virus, or part of one although none of the scanners at virustotal can detect it. On the server I found it on, It turned off several of the services at once, leving clients without network access like you described.
It looks as if it has some code to hide from detection as well.
The bootwin.exe file can be deleted in safe mode, but I don't know if that's enough to get rid of the entire virus. It might be part of a rootkit.