PDA

View Full Version : Computer Virus Help....



midnightfxgt
07-13-2006, 03:33 PM
Hey guys,

I am usually the last guy to ask for computer help, but I am in a rush and dont have a ton of time to resolve this. Its my parents PC.

My step dad called me and said his PC was taking MINUTES to type MSn msg it was so slow. Norton AV also said his PC had a virus. It said he had \"Infostealer\". It also said the infected file was: c:\\windows\\system32\\xvid.dll . I have yet to take more than 5mins to look into this, but the PC is having issues logging in (making it tough to troubleshoot!). The PC boots into windows, and allows you to select the user or Administrator. When choosing either \"Loading Personal Settings\" is displayed and so is \"Logging in\", but it is followed by \"Logging out\". And then your left at the login screen AGAIN. Its a big loop.

I have yet to try the Recovery Console.

Any help is appreciated.

Thanks
John

PS - They did a NAV scan and let it take care of the virus. This all happened on reboot (I still think its related to the virus)

midnightfxgt
07-13-2006, 03:44 PM
Boot issues in Safe and Regular mode... no WinXP RD.

-John

Zaku_4
07-14-2006, 01:01 AM
wow

cant even get in safe mode?!

this requires serious pro-ness (or more knowledge about computers tahn me)

DrunknFoo
07-14-2006, 02:29 AM
I\'ve been in the IT field for a few years now and from searching the web there are 2 possible methods of getting this resolved. (none has really worked for me and I ended up formatting or restoring backed up images the computers whenever this arose)

6disk boot for xp Windows XP 6 Disk (http://www.bootdisk.com/bootdisk.htm).

or

windows/system32/userinit.exe (get a copy of this file from another computer on to disk)
run recovery console (CD)
overwrite the copied file on disk to your computer (windows/system32/userinit.exe)
if you are unable to complete the move/copy cmd, then in the prompt type,
userinit.exe c:/windows/system32/userinit.exe
reboot and cross your fingers.

if the above fails, you could try overwriting the old file with the new, then renaming the userinit.exe to wsaupdater.exe then reboot.

if you run into any other complications (norton/other quarantined your startup files), last resort is to reformat