problem with viruses, I think

memory

Member
Okay, somebody I know called me up to look at his computer. I looked at it last night and it doesn't look good. Whenever I start it up and makes it to the desktop, all the icons will keep disappearing and reappearing several times in a row before it shows nothing. I tried to start under safe mode, but when I do that nothing will come up on the desktop. It is just a black screen that says safe mode around the edges. There is three different accounts on that machine and under the second account, the control panel is missing which is not a good sign, right? One of the accounts is a Guest and I did not check that one for the control panel. When I started up in safe mode, there is a different account that shows up called administrator that is not there when I start it normally.

Whenever the icons show up, I can open programs up so I scanned with AVG, Adaware and Spybot. AVG found several trojan horses and Adaware found quite a few things , can't remember the names, there were over 100 things. It got rid of all of them I think. Now the funny thing is Spybot did not find anything. After I scanned with all those, I restarted and it still did the same thing. Also, when the desktop first comes up there is a program that looks like some kind of antivirus that is scanning called Malware. Also, two different error messages come up, Regsvr32 LoadLibrary lybkpijy.dll failed, and error Rundll yhgbstar\evytaril.dll. One other thing he can not update the antivirus software because he does not have internet hooked up at the moment. Has anybody ever seen anything like this and what did you do to fix it besides reinstalling windows?

I would reinstall Windows XP but he has information on there he doesn't want to lose and he does not have the Windows cd, which should have came with the computer when he bought it. It is a Dell computer. He has a second hard drive so I tried moving stuff that he wanted to keep to that drive but in the middle of copying it, all the icons disappear and it cancels copying. I tried several times but there is not enough time to get it copied.

Sorry for the long post, I just wanted to make sure I let you know as much as possible so maybe someone can help me out.
 
Post a HijackThis log, and we'll take it from there:

Please download the HijackThis installer from http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe.

Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Click Do a system scan and save a logfile

When the Notepad window opens choose Edit -> Select All to select the entire log, and copy and paste the log into a reply post.
Most of what it lists will be harmless or even essential, don't fix anything yet.
 
He doesn't have internet right now and probably won't for awhile. I guess I could download it on my computer than put it on a disk but the problem is nothing stays up long enough to do anything.
 
Try downloading the standalone version and putting that on a disk or memory stick: http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe

If you can't get it to stay open, try rebooting into Safe Mode. Even if you can't see your desktop icons, press Ctrl + Alt + Del. That should bring up the Task Manager. Choose File -> New Task. Type in D:\HijackThis.exe where D: is the drive letter of your disk or memory stick and click OK. Hopefully, that should launch HijackThis.

Also try loading the Task Manager as before, and choose File -> New Task. Type in explorer.exe and click OK. See if that loads your Desktop icons.
 
Okay what if I type in explorer.exe and nothing happens? Is that a bad sign? I will try this when I get back out there to look at it. We are both kinda busy right now.
 
It's possible that something else is interfering, or that files are corrupt, so running explorer.exe from the Task Manager may not be effective.

If you have your own Windows CD, and it's the same version as the Windows on his system (e.g. both XP Home or both XP Pro), you can use his CD Key to do a Repair Reinstall. This should not cause any data loss, but will hopefully allow you to use the system.
 
Back
Top