On Monday I got a clients computer that was suspected to be infected with a virus. The client took it to someone else first to try and fix the problem they ended up installing AVG with Symantec (not a good Combo). Any case, when I got the pc I tried to get to the bottom of the problem to find the type of virus infection resulting in infecting my own computer after I used my memory stick to transfer a tool to the client pc and then inserting it into my pc.
As it may, the closeted I could get to obtain information about the virus, is a description: VCAB.dll. Generic2.OEH. W32.bacalid.
Doing a search on the internet I concluded that to remove the virus would be easy as just to run a virus scan with the latest definitions or the removal tool (Symantec, Stinger tools)
Problem. The client computers explorer does not even allow running programs as they get terminated. Opening things like control panel gets terminate.
My computer experience the same behavior but not in such a big way. I managed to run the AV, Anti Spy, Registry Cleaner, Removal tool, but to no avail..
I noticed that there are some processes running that are suspect. When terminated the just return.
Process example: hole.zip, untitled.doc, I can not remember the other one.
Sometime Avg Scan detects the virus and moves it to the vault, but the computer is still corrupt and the virus just returns. The VCAB.dll file in the Local settings Temp Directory just returns, and cannot be deleted manually??
Well I am stuck here and am in desperate need of help. As times goes on to clean the my pc it seems to get worse, the clients pc is even worse, as I can not even run add remove programs to uninstall Symantec AV (out dated subscription)
No other viruses or threads are detected on my pc, maybe some other virus is also hiding??
System restore is disabled. I did run all the scanners as suggested; I even ran hijack this and told it to delete/fix all the threads.... Most probably should not have done that...
I cannot run any system activity on the computer as it terminates, and on the clients pc almost every thing terminates.
Melt van Niekerk
MVN SYSTEMS, South Africa