It looks like you're using an Ad Blocker.

Please white-list or disable AboveTopSecret.com in your ad-blocking tool.

Thank you.

 

Some features of ATS will be disabled while you continue to use an ad-blocker.

 

Help with virus removal pls.

page: 1
2

log in

join
share:

posted on Nov, 19 2012 @ 11:22 PM
link   
On my pc I am infected with the Trojan Horse downloader generic12.bsu virus.
I found a website to manually remove it, but I don't see it in the task manager.
I'm on my mac right now, but the pc is in the other room and I can easily get to it.
I also did a scan ( another site telling me how to remove this virus) and it found a
CRAZY number of errors, then it wanted me to buy and register to fix them.

Here's the site I found to manually remove it.
virusremovalhelps.com...

Can someone help me out, please?
I can remove it if I know what to look for in the task manager.

AVG will not remove it, and I could not even do a system restore.



edit on 19-11-2012 by virraszto because: (no reason given)



posted on Nov, 19 2012 @ 11:31 PM
link   
Try going to Trend Micro Housecall Online Scanner and downloading the installer.

It will then install updates from their website and ask you to agree to terms etc, then run a scan. we used to use this at work years ago, it's changed a lot but same idea. It used to run from inside IE, it might still, if you use IE.

It hopefully should find and get rid of it, I've not heard of it before tho..



posted on Nov, 19 2012 @ 11:34 PM
link   
Try Malwarebytes and SUPERAnti-Spyware. Both are free and worth a shot.

PS - Needless to say, but both programs are very effective at finding and getting rid of problems. They get good reviews and are recommended by many.

edit on 2012.11.19 by TravisBickle451 because: PS



posted on Nov, 19 2012 @ 11:34 PM
link   
reply to post by virraszto
 


make a note of the file paths listed in the scan.

Start your PC in SAFE MODE. You can look up how to do this online.

Once your computer is in SAFE MODE, click on the Windows START button (usually in the lower Left corner), click on RUN, and then type:
msconfig

Hit Enter and this will bring up the System Configuration Utility.
Go to the Start Tab and uncheck all the listings for programs starting up on computer start that you don't want, especially those that follow the path of the infection noted in your scan.

After all the unchecking is done, apply and close the System Configuration Utility, but don't restart.

Next, go to Start, then Run, and then type:
Regedit
Hit enter and this will bring up the Registry Editor.

You'll have to expand and scroll down through the tree to
HKEY LOCAL MACHINE -> SOFTWARE -> Microsoft -> Windows -> Current Version -> RUN

Once you click on the RUN folder you'll see some of the similar listings you've unchecked in MSCONFIG listed off to the right hand side of the editor.

Highlight and delete the listings describing paths listed in your virus scan.
Do so for stuff you don't want to start automatically on system start.

Close Registry editor when done.

Next, follow the file paths described in your virus scan, and manually delete the offending infected files.
Empty your trash bin.

Run a full system scan with the latest virus definition updates while you are in SAFE MODE.

When done, you should be clean.

All this takes quite a bit of time, but, if you want to be clean, it will indeed take time.
Nothing worth having should be expected to be easy.

Restart your computer and be happy.

Keep your virus definitions up to date, and stay away from websites that could get you dirty.

If you can't avoid the urge to go to suspect websites, or downloading suspect material, then, boot to an OS on CD like Knoppix Linux, or just use your Mac.





edit on 19-11-2012 by Druscilla because: (no reason given)



posted on Nov, 19 2012 @ 11:34 PM
link   
reply to post by virraszto
 


try spybot worked for me



posted on Nov, 19 2012 @ 11:43 PM
link   
Never mind. Follow Druscilla....
edit on 11/19/2012 by Ex_CT2 because: (no reason given)



posted on Nov, 19 2012 @ 11:49 PM
link   
reply to post by Druscilla
 


Thanks for the reply and info, but I don't see anything in my task manager that I can identify as the virus.
This virus creates filenames that are very similar to system files.

On avg, I see the path
C:/System Volume Information
and
C:/Program Files/Youtube to Mp3converter

I delete the second one yesterday and tried to do system restore, but I don't see the first one, or know where to find it. I don't see
C:/system anywhere.



posted on Nov, 19 2012 @ 11:53 PM
link   
I use Kaspersky... no problem with such things, as of yet... anyway you can try this

KASPERSKY

used by geek-squad...

review the product information... the program is free, and it lists what you should do before and after running the tool.
edit on 11/19/2012 by Shdak because: Review product info...

edit on 11/19/2012 by Shdak because: (no reason given)



posted on Nov, 20 2012 @ 12:04 AM
link   
reply to post by virraszto
 


Disregard AVG. Turn it off.

"System Volume Information" is a hidden folder where your restore files are kept. They're disabled by the virus; the virus also hides pieces of itself in there. That's why AVG is alerting on it. Those will be removed with a good antivirus. Malwarebytes, as mentioned above, is good.

Try to follow Druscilla. If you don't understand an instruction, be specific....

edit on 11/20/2012 by Ex_CT2 because: (no reason given)



posted on Nov, 20 2012 @ 06:14 AM
link   
It might be worth doing a reformat of the computer if the advice given from other members does not work. It's sort of a last resort, but it's an effective one. A successful format will remove all system/personal files and require a clean install of an operating system. Just ensure you have backed up all your important non-infected files (like music, movies, photos, documents etc.) before you do this though.

To do this you will need a genuine non-corrupted operating system disc (including any relevant serial keys), a working external hard drive, an internet connection and a few spare hours.



posted on Nov, 20 2012 @ 08:18 AM
link   
You shouldn't mess with the "registry" in regedit, unless you really know what you're doing.
You CAN damage your PC.

I trust Malwarebytes and Superantispyware as someone else suggested.


Good Luck.



posted on Nov, 20 2012 @ 12:15 PM
link   
reply to post by Shdak
 


I like KASPERSKY so far. I have tried the above listed so far but KASPERSKY has been very effective.



posted on Nov, 20 2012 @ 12:24 PM
link   
Run MRT on you default windows. Type "mrt" on the search and run the program. Full Scan.

Download Malwarebyte or other similar programs. Run Full Scan.

Run you Anti-Virus. Full Scan.


Always best to run multiple Scan.

Do it overnight cause Full Scan takes hours.



posted on Nov, 20 2012 @ 02:14 PM
link   
To the OP : If you really do have generic12.bsu then there are guides that give detailed instructions on how to get rid of it.

Heres one from a site that i trust.

Remov e Trojan Horse Downloader Generic12.BSU (Removal Guide), How To Remove Trojan Horse Downloader Generic12.BSU

I might be better than just randomly trying each virus killer because someone said they like it (especially if they dont know if its even any good at getting rid of the specific infection)



edit on 20-11-2012 by PhoenixOD because: (no reason given)



posted on Nov, 21 2012 @ 04:00 AM
link   
From your first screenshot, it looks like one of your system restore points are infected, so if you are doing system restores you are reinfecting yourself.

I suggest you reboot into safemode then run anti-malwarebytes. When malewarebytes says your clean, remove all your restore points and then create a fresh one.
edit on 21/11/12 by Kr0nZ because: (no reason given)



new topics

top topics



 
2

log in

join