Page 1 of 1

Annoying situation

PostPosted: 03 Nov 2011 00:03
by kmass
I been having an annoying issue since I got an incomplete file that was caught by my Symantec Antivirus and reported as 'Trojan.Brisv.A!inf', then it kept reporting the same file after the start-up scan whenever I started or restarted the computer, therefore I deleted the file from the Quarantine, scan history, events, etc, etc, but it keep reporting like it was still present... to troubleshot I temporarily uninstalled Shareaza and deleted all the files/folders associated with it, downloads, incomplete folder for all users, etc, etc, but the startup scan keep reporting it... where is it scanning it from??, the folder does not exist anymore! And there is not 'Trojan.Brisv.A!inf' in quarantine either! ... The system is Vista and the result that keeps displaying after start-up is as follows:
*********************************************************************************************************
Risk Found!Risk: Trojan.Brisv.A!inf in File: C:\Users\user_\AppData\Local\Shareaza\Incomplete\sha1_DR3M6BNRDAFVADLYDEOMJKRHOLXS4KNC.partial by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
*********************************************************************************************************
To see if it was present I downloaded the 'Trojan.Brisv.A!inf' removal tool from the site, but it was not able to delete anything since it reported as 'Trojan.Brisv.A!inf' not found in the system. and lastly I scanned with 'Malwarebytes' but it did not return anything that appears related to 'Trojan.Brisv.A!inf'.

I will appreciate if anybody can throw some ideas on this one, probably not too complicated to fix, thank in advance.

Re: Annoying situation

PostPosted: 04 Nov 2011 14:45
by taxiboy
Well it seems like you've done the necessary steps, you could try this. Get a file wiper, disable the system restore feature and recycle bin. Reboot then, go into the directories and wipe the system volume folders and the recycle bin folders (if possible). You want to delete the files in those folders. You may need to boot up in safe mode. Then reboot and see if that clears it up. Then re-enable the system restore and recycle bin and reboot. Otherwise, well, clean install.

Re: Annoying situation

PostPosted: 05 Nov 2011 19:47
by ailurophobe
The AppData folder is more than a bit weird, personally I think it is more accurately described as a "bug" rather than a "feature", but the people at Microsoft obviously disagree. Anyway, you can look if Shareaza has a download matching the sha1 hash active, and remove it in Shareaza if present. I suspect the anti-virus just "quarantined" the .partial file and left the matching .sd file alone so Shareaza simply recreated the .partial later. Alternately you can copy the reported path into Windows Explorer and try deleting the files there with Shareaza closed.

Re: Annoying situation

PostPosted: 14 Nov 2011 19:53
by kmass