• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Help me identify a possible virus.....

Hey guys. We have a problem on one of our main computers here where I work. Before you ask, we are a small sign shop, and there is no such thing as an IT department here, so it's either I figure it out for the owners for free, or they will have to call the local comp techs and pay out the ass.

I'm not quite sure, but I'm thinking the comp might have a virus. Here's what it's doing. It's running WinXP Home (for a business, ya, I know what you're thinking, that's the first problem), and it will go through the boot procedure fine, up until it starts to load the desktop. The login screen will pop up, and I can choose either the main account, or guest, and then the background for the particular login will show, but nothing else. Just the background, no taskbar, no desktop icons, nothing. And get this, the hard drive activity light will blink contanstly. Not a patterned blink, but just a regular on and off and on like you're copying files or what not. Also, I can bring up the task manager using CTRL+ALT+DEL, but nothing looks out of the ordinary. The only thing I find odd is a winupd.exe opened by User Name "Owner". I'm not familiar with this filename at all, but that doesn't mean it's part of the problem.

Also, when I go to File, Run, I try to open things like msconfig or regedit, and they open for a brief couple of seconds, and then are closed automatically. This is why I think it's a virus. I can open them, and even click on a tab quickly before they just close out. It's like a virus purposefully is closing out anything that opens.

Thanks for any ideas guys.
 
Thanks guys. I actually did already try booting into safe mode, and it did the same thing. I thought I mentioned that in the original post, but apparently I didn't. Sorry about that.

I worked around the issue temporarily by being able to open explorer.exe in the windows folder, as that was the main hiccup in getting the taskbar up and running. Once I opened explorer.exe, everything seemed fine then. We didn't restart the comp today, but I can only assume it will continue to not start correctly.

I'm not at work right now, but will check out what FoBoT provided me tomorrow. Thanks guys.
 
Yes, this is a classic tactic for spyware/browser hijackers. Except this one was poorly coded, as it prevented explorer.exe from loading. 😛

If you want to know who you can blame I suspect it is a relate of CoolWebSearch.com. (Don't go there)
 
Back
Top