We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

I have a Trojan called Trojan.Brisv.A!inf and it won't leave me alone!!!!!

2456789

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    haha

    Sorry Jack :p
    :idea:
  • GunJack
    GunJack Posts: 11,880 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ...no probs :D just suprised I ALMOST beat you to it ;)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    Got the same virus, though from a different source, not sure where. Read from my searches that there is a lot of it going around. I'm generally good at cleaning my pc like you say you are, but this one is stubborn and comes i'm sure with friends.

    I've removed it (or most of it) but I know its still around. Also found trojan.vundo on my pc. Might be worth checking for both.

    Have you tried this?

    http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2008-072215-0522-99


    I've now got the problem of hijacked search engines and Windows security alerts error. In reg edit it's messed about with the windows security centre.

    I have scanned with CC Cleaner, Ad-Aware, Spybot search and destroy, Malware Bytes and Norton.

    -Don't worry! I'm not using all of these simultaniously! I only install one at a time and run scan then take it away. Some not uninstalled, but also not active.

    Any ideas on what to do next?

    IE also crashing, prob linked to my dodgy google search results
    Saving and spending in equal measure
  • GunJack
    GunJack Posts: 11,880 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    try superantispyware.....install, update and full scan if t'others don't do it...
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    Almost went to google it! Always forget that when it shows the result and I click, that aint where I'm goin!! -little bar stewards!

    Doesn't seem intrusive or dangerous (my my little knowledge) just irritating
    Saving and spending in equal measure
  • GunJack
    GunJack Posts: 11,880 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ..trouble is you can never be too sure what else it's doing in the background....exterminate !!....EXTERMINATE !! :D
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    My Malware bytes doesn't seem to be making reports. Noticed that when I scanned the other day. Trying again now, as previously I'd done it and left it over night.

    Coincidence that AVG also stopped scanning all together? that and the windows security centre?
    Saving and spending in equal measure
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    0james0 wrote: »
    My Malware bytes doesn't seem to be making reports. Noticed that when I scanned the other day. Trying again now, as previously I'd done it and left it over night.

    Coincidence that AVG also stopped scanning all together? that and the windows security centre?


    run HIJACK THIS (Link in my first post (ish))
    :idea:
  • 0james0
    0james0 Posts: 527 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker
    Malwarebytes' Anti-Malware 1.33
    Database version: 1663
    Windows 6.0.6001 Service Pack 1

    03/02/2009 21:56:06
    mbam-log-2009-02-03 (21-56-06).txt

    Scan type: Quick Scan
    Objects scanned: 55947
    Time elapsed: 4 minute(s), 13 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 3
    Folders Infected: 0
    Files Infected: 4
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Windows\System32\ntdll64.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    C:\Windows\System32\warning.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\Windows\System32\ahtn.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    C:\Users\home\SETUP.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
    Saving and spending in equal measure
  • GunJack
    GunJack Posts: 11,880 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    aliEnRIK wrote: »
    run HIJACK THIS (Link in my first post (ish))

    yup, and post the log.....if scans aren't working properly as they should may have to try the old "download them and save under a different name before installing" trick....good luck !!
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245K Work, Benefits & Business
  • 600.6K Mortgages, Homes & Bills
  • 177.4K Life & Family
  • 258.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.