I discovered a virus/malware call Mal/Generic-A on my computer a few days ago but have had no success in clearing it. My system has become very sluggish. Sophos kindly tells me of the presence of Generic-A at least 1,000 times an hour. I have search for information, but there is very little and none of it seems to help.
Sophos continually tells me the file is in the system32 folder and is called xxyvstRh.dll and every time it attempts to delete it fails due to an unknown error 0x80070020.
The location details according to Sophos are: -
C:\Windows\system32\xxyvstRh.dll
HKCR\CLSID\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf}
HKLM\SOFTWARE\Microsoft\CurrentVersion\Explorer|BrowserHelpObjects\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf}
C:\Windows\Temp\SMI1.tmp
C:\Windows\Temp\SMI6.tmp
C:\Windows\system32\xxyvstRh.dll: pid:000003c0:file
C:\Windows\system32\xxyvstRh.dll: pid:00000634:file
HKLM\SOFTWARE\Microsoft\CurrentVersion\Explorer\ShellExecuteHooks\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf}
I have installed AVG Anti-Spyware, I have updated it and it does not picked up Generic-A.
I have installed HijackThis and asked it to remove the entries but as yet nothing seems to want to shift it.
Is there someone that could offer some advice on removing this subborn virus/spyware.
Many thanks.
HG
Sophos continually tells me the file is in the system32 folder and is called xxyvstRh.dll and every time it attempts to delete it fails due to an unknown error 0x80070020.
The location details according to Sophos are: -
C:\Windows\system32\xxyvstRh.dll
HKCR\CLSID\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf}
HKLM\SOFTWARE\Microsoft\CurrentVersion\Explorer|BrowserHelpObjects\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf}
C:\Windows\Temp\SMI1.tmp
C:\Windows\Temp\SMI6.tmp
C:\Windows\system32\xxyvstRh.dll: pid:000003c0:file
C:\Windows\system32\xxyvstRh.dll: pid:00000634:file
HKLM\SOFTWARE\Microsoft\CurrentVersion\Explorer\ShellExecuteHooks\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf}
I have installed AVG Anti-Spyware, I have updated it and it does not picked up Generic-A.
I have installed HijackThis and asked it to remove the entries but as yet nothing seems to want to shift it.
Is there someone that could offer some advice on removing this subborn virus/spyware.
Many thanks.
HG