Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop mac malware memory monitor motherboard network operating system printer problem ram registry router security slow software sound svchost.exe trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
New computer, a virus already? Urgent

Reply  
Thread Tools
ahenderson's Avatar
Junior Member with 8 posts.
 
Join Date: May 2008
22-May-2008, 11:38 AM #1
New computer, a virus already? Urgent
Hello, I am new and I have an Urgent question Please Reply asap, thanks I am running Windows Vista / IE 7(obviously :-)

After during a Spysweeper: I have received these messages:

Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 1 round of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 2 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 3 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 4 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 5 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 6 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 7 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 8 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 9 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 10 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 11 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 12 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 13 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 14 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 15 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 16 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 17 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 18 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 19 rounds of disinfection.
Informational: File C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE still infected with virus Mal/Generic-A after 20 rounds of disinfection.
Informational: Virus infected file C:\USERS\PAIGEYGIRL\APPDATA\LOCAL\TEMP\SYMLCSV1.EXE not cleaned.
--------------------------------------------

What ticks me off is that Norton states that everything is at risk because the trial period ended. But I purchased all features of Norton and states good until March 2009, but all shows at risk now, and I have been infected apparently, from what Spysweeper is stating.

What the heck would cause this? AND now, what should I do to clean?

I am a greenhorn, and do not know what to do?




Thanks



Drew
Esbenovich's Avatar
Computer Specs
Member with 69 posts.
 
Join Date: Nov 2007
Location: Denmark
Experience: Intermediate
22-May-2008, 12:15 PM #2
well maybe I can help you with the Norton part, my mother had the same problem. we couldn't find out what was wrong since the license definetly hadn't run out already..
but we found a cd with Norton on it that came with the pc. apparently the manufacturer had only installed a trial of Norton, so when we installed Norton from the cd everything worked.

by the way.. this should be in the malware removal & hjt logs forum..
__________________
If anybody calls out NERD!! i allways turn my head
Elvandil's Avatar
Computer Specs
Moderator with 48,924 posts.
 
Join Date: Aug 2003
Location: Vermont
Experience: "Been through the mill."
22-May-2008, 12:41 PM #3
Try and online scan (TrendMicro), or try cleaning in Safe Mode.

See if the process is running in Task Manager and terminate it.
ahenderson's Avatar
Junior Member with 8 posts.
 
Join Date: May 2008
22-May-2008, 01:15 PM #4
that is GREAT information for me! Thanks very much. I think I have a Norton CD? But can't remember now that I think of it. I will check. This makes me not like Norton. I logged into my Norton Account and see that I am showing active til March of 2009. Weird?
ahenderson's Avatar
Junior Member with 8 posts.
 
Join Date: May 2008
22-May-2008, 01:17 PM #5
Thankyou! I will do what you said here. Also, do I need to change Passwords and stuff? I am not familiar with Viruses, does this look like could do damage?
Elvandil's Avatar
Computer Specs
Moderator with 48,924 posts.
 
Join Date: Aug 2003
Location: Vermont
Experience: "Been through the mill."
22-May-2008, 01:25 PM #6
It's hard to say what the virus may do, but getting rid of it as soon as possible will limit any damage.

Here is some info:

http://www.sophos.com/security/analy...lgenerica.html
with instructions for removal.

More:

http://www.trendmicro.com/vinfo/viru...&id=MAL_EMESEN

Norton, besides being a resource hog, is so popular that many viruses inactivate it to protect themselves. The free AV's are as good (I think better).

Free online virus scan:

http://housecall.trendmicro.com/

The virus has a "low" risk rating, so I wouldn't worry about passwords and such yet. But often, when there is one, there is more.

You might want to go to the Malware forum, post a log according to the instructions there, and get expert help with cleaning.
__________________
Microsoft MVP
異驚の界世 ˇpןɹoʍ ǝɥʇ ɟo sɹǝpuoʍ ǝɥʇ ɟo ǝuo sı ǝpoɔıun ʞuıɥʇ ı

Last edited by Elvandil; 22-May-2008 at 01:35 PM..
gr277's Avatar
Computer Specs
Member with 49 posts.
 
Join Date: Jan 2008
Location: Kent, UK
Experience: Home User
22-May-2008, 01:30 PM #7
Quote:
Originally Posted by Elvandil View Post

Norton, besides being a resource hog, is so popular that many viruses inactivate it to protect themselves. The free AV's are as good (I think better).
I wouldn't touch Norton with a barge pole.....
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
22-May-2008, 02:07 PM #8
Since it says that the infection is not cleaned, maybe it is still running. Try booting into Safe Mode with Networking ( hit F8 after the memory counting bios screen when booting) and run the online scan that way.
valis's Avatar
Computer Specs
Moderator with 48,702 posts.
 
Join Date: Sep 2004
Location: as above
Experience: so below
22-May-2008, 02:55 PM #9
just for kicks and grins, you may want to post a hjt log to have an expert parse it as well. As follows:

CLICK HERE to download the HijackThis Installer:
1. Save HJTInstall.exe to your desktop.
2. Double-click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5. Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
8. Come back here to this thread and paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
__________________
Microsoft M.V.P. - Windows IT Professional | M.C.S.A. | M.C.P. - MS Server 2k3 | blog | rate me

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that". - Gary Kildall
ahenderson's Avatar
Junior Member with 8 posts.
 
Join Date: May 2008
22-May-2008, 04:33 PM #10
Thanks SO much for the advice, words of wisdom
valis's Avatar
Computer Specs
Moderator with 48,702 posts.
 
Join Date: Sep 2004
Location: as above
Experience: so below
22-May-2008, 06:05 PM #11
well, seeing as how I see these every day on another site, I'd kinda recommend it.

But if you choose not to do so, it is, after all, your pc.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 02:32 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.