Does autoprotect use cache
Needing some assistance. Whenever this computer starts, the autoprotect shows that a file is infected with Trojan.brisvA!inf and then states that it was successfully cleaned. However, whenever you restart again, it pops back up with the same message. I try to manually go to the location that is specified and the infected file does not exist. I've even moved and renamed the folder that the infected file is in but on the next reboot autoprotect still says the file is in the original location. Is Symantec using a file cache or is it Vista?
Tried the fix brisva tool from symantec and it did not find any problems. Also tried a live boot cd and ran clamAV and again nothing. I've ran AVG, Malware Bytes, SuperAntispyware and Spybot and none of those report a problem. I am STUCK!
Thanks!
Comments
Sounds like some rootkit.
Did you try to find that file after boot from LiveCD?
But best decision IMO would be reinstall OS on that computer. I guess you already spend more time trying to fix that than it would take to rebuild system from scratch.
So true! And yes, re-imaging is still an option. I did try to find the file from the liveCD with no luck. Auto protect still says the file is in a location that no longer exists! I have completely removed the folder containing the virus yet symantec thinks it is still there. I have even completely (as completely as you can anyways) removed symantec using the cleanwipe utility. Right after the reinstall, the autoprotect picks up the virus again in the same old location.
Also, if I try to "delete permantly" the file throuh Symantec I get a message stating that the action cannot be done because it can't find the file!
Start in safe mode with networking and install Trojan Remover from Simply Super Software, let it update and scan.
Do the same for MalwareBytes' AntiMalware software - install, update, scan.
Safemode allows much easier cleaning.
I suspect even SEP can do a manual scan in safemode......
My sites - http://theamcpages.com & http://antique-engines.com
Toy:
Shadow:
I have tried all but Simply Super Software in safe mode already. I'll try the Simply Super one this weekend. Also, another bit of info, the auto protect pops up in safe mode too on that same virus. Thanks Bill.
Symantec have a tool by the name NSS which I think is very efficient as its consumer based. It uses the same definition store as that of SEP\SAV. It's kept somethere there at their FTP.
No go. Simply Super Software does not find it and neither does Malwarebytes. Symantec still is saying it is cleaning the risk on every reboot.
Would you like to reply?
Login or Register to post your comment.