Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
TROJ_BISPY.B virus help!!!
ran a scan an found this virus: TROJ_BISPY.B
Stupid pop-ups keep coming up and this weird program is running that I can't delete. Anyways I found it using TrendMicro's online scan.
I followed the solutions {LINK
but I couldn't find any of the entries that I was supposed to be deleting.
Anyone that has sucessfuly deleted this virus. help.
Also is it wise to delete internet explorer folders from registry if I don't even use it?? I'm a firefox user.
___________________
You ain't no daisy, no daisy at all
Feb-28-2005 05:27
digitalbreach
the sky is falling
Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
anyone??
this virus is pissing me off. help plz.
___________________
You ain't no daisy, no daisy at all
Feb-28-2005 06:55
Orbax
Supreme tranceaddict
Registered: Apr 2002
Location:
do pandasoft as well. Just delete the file if its uncleanable dude.
Feb-28-2005 06:56
digitalbreach
the sky is falling
Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
pandasoft??
I've cleaned the sys32 cache folder and all the temp files. tried looking in sys registry for entries but couldn't find any. Will try just deleting the acual files but I doubt that works.
Also forogot to mention:
my OS is booting up much faster now...it skips all the initial boot up that is controlled by the motherboard and a weird screeen flashes before the WinXP screen comes up.
prog: Webtools is running along w/ other minor processes.
orbax: would you delete all explorer entries in registry if explorer is not used???
___________________
You ain't no daisy, no daisy at all
Feb-28-2005 07:03
A83
Suspended User
Registered: Jan 2005
Location:
Uhh...boot into safe mode
I think thats done by pressing f8 or f10 really fast at start up
then delete the file or run virus protection
Feb-28-2005 07:09
Orbax
Supreme tranceaddict
Registered: Apr 2002
Location:
did you do their free scan and they showed you all the infected files? and pandasoft has an online virus scan as well that is quite effective
Feb-28-2005 07:12
digitalbreach
the sky is falling
Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
follow the link in my first post and see if any of those entries are in your registry.
The think is this trojan replicates and creates other .exe files that causes lots of pop-ups and fucks w/ windows player.
next I downloaded AVG antivirus from grisoft
ran in safemode and caught all of the replicas.
I think I got it.
thanx orbax
___________________
You ain't no daisy, no daisy at all
Feb-28-2005 08:03
digitalbreach
the sky is falling
Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
f@ck me!!
I think its a boot sector virus.
cause when I booted back in regular mode AVG caught it again. Cannot delete it >> Temp Internet Files\Content.IE5\..\ei.exe
Going to sleep for now..have class tomorrow.
anyone else w/ good leads to this virus?
~digital
___________________
You ain't no daisy, no daisy at all
Feb-28-2005 08:12
Orbax
Supreme tranceaddict
Registered: Apr 2002
Location:
once you have identified the file names copy and paste them into notepad. close down every single IE process and window. Then shut down every non essential process. Delete all of the files in your notepad now.
I know processes well so when i had something that id close like
"C:\doc set\temp\ie\8435\wowser1.exe"
in processes a wowser2.exe would start running and they kept switching off. just did a windows search for wowser2 and it was in a sys32 file. so deleed that as well.
rebooted, everything was fine, then virus scanned again and I had gotten them all. You have to close the process its using before you can delete the file. Cheers
Feb-28-2005 18:09
digitalbreach
the sky is falling
Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
Each time AVG finds it says it can't delete cause it's still in use in memory.
Orbax: will try this when I get home tonite.
Need to study cause midterms are before spring break.
___________________
You ain't no daisy, no daisy at all
Feb-28-2005 18:19
digitalbreach
the sky is falling
Registered: Oct 2002
Location: TX TA #3 5p4c3 C!ty
tried it seems to have gotten rid of it.
also deleted any files created during the time of the infection.