Overall Risk Level:
Trojan.Brisv.A is a trojan that can infect multimedia files on the computer and utilized Windows Media Players to access malicious websites and download additional threats.
Other Alias: -
Threat Level: Low
Systems Affected: Windows - All
Source: Symantec
103 Responses for "Trojan.Brisv.A"
1. Temporarily Disable System Restore (Windows Me/XP). [how to]
2. Update the virus definitions.
3. Reboot computer in SafeMode [how to]
4. Run a full system scan and clean/delete all infected file(s)
5. Delete/Modify any values added to the registry. [how to edit registry]
Navigate to and delete the following registry subkey:
HKEY_CURRENT_USER\Software\Microsoft\PIMSRV
Navigate to and restore the following registry entries to their previous values, if required:
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences\”URLAndExitCommandsEnabled” = “0″
HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Player\Extensions\.mp3\”Permissions” = “21″
6. Exit registry editor and restart the computer.
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.
Thanks very much
I m using Norton Internet Sec.. I have tried all things what is mentioned above.. doesn’t work at all… i have also tried symantec Trojan.Brisv.A removal tool. This also doesn’t work…
Hey, I am also facing Same problem.. and i have also tried symantac Brisv,a removal tool and i am also getting same problem so did you find any other alternative of it. if u get any other help then let me know also on my email id theketul@yahoo.com
Thanks
Ketul shah
I’m just reencoding more than two thousand MP3s infected by Brisv.A, it’s a horror… This threat appends a header at the beggining of each media file found on the attached drives and makes them unplayable for most of the media player applications in Windows (Winamp plays the infected files discursively, while Windows Media Player does not play them at all). It seems, that infected media files can be cured by reencoding them using GStreamer. The MPEG decoder, that comes with GStreamer seems to be very nice as it can play the corrupted files properly. After reencoding, I can play the files on Windows with any media player application.
It would be nice to find a utility which just deletes the infected parts of the files, but I haven’t found such a utility, yet.
The virus itself may not be dangerous, but if it destroys all of your music files (as in my case), then you probably wish the programmer, who wrote this, a long and painful journey to hell…
I’m working on a small utility, which can heal MP3 files infected by Brisv.A. I need to examine infected files thoroughly, because Brisv.A seems to do something more than just prepending a header.
What Brisv.A Killer already can do:
- Decide if the input file is a valid MP3 music file
- Check if the file is infected by searching a bit pattern on the first 10 kB block of the file
- Locate the first MPEG frame
- Copy everything starting from the first frame
Playing the healed files is possible, but they play like if they’d be seeked all the time while playing. Probably Brisv.A adds something to each or some frames, changes frame headers, or something so. I need to examine files a bit more to determine what this trojan does in fact.
Symantec is really stupid…there antivirus and removal tool for this trojan is not working
Dear NKM & George,
Thanks for posting for this Trojen. This Trojan has enetered in more than 4000 files on my PC. And I have tried all antivirus like symantec, Kaspersky who claims to remove it but all are useless. Si finally i am not getting any solution of it. So if you find any solution or alternate then let me know too. I will be most thankfull to you. You can also contact me on my email id theketul@yahoo.com . If anybody needs that infected file for examination I can provide the same.
Thanks
Ketul Shah
INDIA
My utility has been completed, it is able now to disinfect MP3 files, which have been infected by Brisv.A.
I made a simple GUI for it, so it should not be a problem, to use it for inexperienced users.
Use the link below to download:
http://www.martoncomp.hu/dl/brisvakiller-0.1-gui.zip
The source is available at:
http://www.martoncomp.hu/dl/brisvakiller-0.1-gui-src.zip
There’s a readme in the archive, don’t forget to read it before using the tool.
It is licensed under GPLv2, so you are free to use, copy or modify it. I hope, this tool will help some people out there.
Dear George,
I am really very much thankfull to you for giving so much of personal attention to my matter. I have downloaded the utility created by you and tried to disinfect infected files. But unfortunatly, This utility is not at all detecting any infection of Brisv.a in those files and giving message that “No infection found”. So now what to do ? May I have your email id so I can send you that infected file and then you can understand the infection properly and may create utility to clear this infection.
Waiting for your reply,
Ketul Shah
theketul@yahoo.com
INDIA
Dear Ketul,
I wrote an email to you this morning, check your mailbox to get my address (I don’t want to publicize it because of spams, I hope you understand).
The utility I made is searching for a bit pattern on the first 10 KB block of every MP3 music file it finds in the specified directory. This bit pattern can be different for each variant of Brisv (and certainly it is). Your files may have been infected by another threat, or another variant of Brisv.
The bit pattern Brisv.A Killer looks for is a URL. This URL can be different for each variant of Brisv, so that could be the reason, why Brisv.A Killer doesn’t recognize the infected parts in your files.
It would be nice, if you could send an infected file to me by email (please put it into a zip file before attaching), so I could examine it and improve my utility.
Thank you for downloading my software, it was fun to make it!
Best regards
George
Dear George,
Thanks for quick reply , as you mentioned that you have send an email to me but I haven’t received any email yet. So please send it again or you can also buzz instant message on my yahoo id “theketul” for giving your email id.
Thanks
Ketul Shah
INDIA
Dear George,
You can also send your email id to me at theketul@in.com
Ketul Shah
Ketul, I sent another message to your postbox at in.com. I hope, you will get it this time.
George
In case my email doesn’t reach your mailbox: my address is mail.gery [at] gmail [dot] com.
George
Dear guys,
I have also the same problem. Around my 500 files are infected the same virus. Please help me to solve it.
Shiju
thanks alot George…this realli helped,
i managed to fix almost 150 files.
great tool!!
Dear Shiju,
first of all, run a full virus scan on your system to remove Brisv.A. This is essential, because Brisv.A will infect the healed files right after they get created, if you don’t do so. Once your system is clean, you can safely run my tool to disinfect your music files.
Thanks a lot George. You are a life saver. But i have to delete 45 wma format songs alone. but you have saved me a week work. i appreciate it.
HI george, i already download your link from your post
Use the link below to download:
http://www.martoncomp.hu/dl/brisvakiller-0.1-gui.zip
but i cant use it because it is error, it’s wrote The application failed to initialize properly (0xc00000135).click on ok to terminate the application.
whats wrong with that george,can u send me the antivirus to my email sechiang@yahoo.com
thx a lot before
What annoys me is that this is the second time my MP3 collection has been hosed.
The first time, I started working on a GStreamer repair process (like what George on Aug15 suggested - which is how I found this page actually, I wanted to write a repair utility).
What really annoys me as that Symantec have not properly prevented the attack vector from executing. This issue is months old now, and receives little to no attention from Symantec.
If it weren’t for Warcraft, I’d be on BSD and Linux on *every* system in my now.
Se Chiang, please install Microsoft .NET Framework 2.0, it’s required to run Brisv.A Killer.
George, i really dont know much about IT, can u please guide me form zero how to remove brisv.A maybe u can send me an email. thx george. because i dont understand how can use microsoft net framework.
Hi george, today i ask my company IT to do follow your guidance coz, i already said i dont know much about IT, but this afternoon, my IT said that the program can not be operate because has error in exe file, so george can u email me the program to my email, because i already download the program twice,but still error. Thx george
THANK YOU George!!! Your aplication FUNCTS and now i’m recovering all my Daisuke Ishiwatary, Heins Zimmer and Martin O’Donnel mp3 files I found 2 observations to make, only to keep the other guys warned.
i m not specting george make another version to fix this im not even telling this irrelevant things are someway related to bugs…
1st you may have to copy your Folder&files very close to the “c:” because i found that files very far from the root directory may not be healed but others may… so you would not receive a note for those only if all files are far. result: some files healed and other don’t. Solution: all files you want to heal may be copied first nearest to the root! and 2nd its just something to prevent complainants… You USERS of this spectacular utility shall check first your “mp3 infos” (sometimes very important to someone) before deleting the infected files, cause the healed loses some info that the mp3 leads. THE QUALITY STAYS 100% THE SAME!!!!!!! THANKS GEORGE YOU made my entire MONTH!!!
My utility cannot copy the ID3 tags from the infected files, that’s why artist/title/album.. information don’t get copied to the healed files.
The easiest solution is to use an online music database service, like CDDB, to fill the ID3 tags for the healed files.
The bug, you mentioned seems a bit strange to me, I didn’t experience any problems with long paths. Infection detection is based on the file signature of the ASF file format, so clean files, or files infected by some other threat may not be healed by Brisv.A Killer.
Hmmm, i thought the virus just took the MP3 and put it in an ASF containor, which included the embeded link, so i have just been using the stream dumper in ‘MediaCoder’ to take the MP3 back out of the container without any re-encoding and this has been working fine, the problem i’ve been having is dumping WMA streams as when they are dumped they are not in a playable form, any ideas?
I know you said that your utility can not copy over the ID3 tags, but is there any way you might put out an update that does, or describe how to edit the open source version to make it do so. If you could that would be most helpful because about 5GB of my music is infected and it would take a LONG time to put that all back in. (I tried it on a couple songs and it worked beautifully, just no ID3 tags…)
THANKS SO MUCH!
I made some additions to the code some weeks ago. The new version is available at the following link:
http://www.martoncomp.hu/dl/brisvakiller-0.2-gui.zip
This version automatically copies ID3 information, when available.
(I don’t know what’s going on with this site, but this is about the fourth time I post this message… please don’t play with my nerves. Thanks.)
George,
You are a life saver! my updated Norton security did not pick this infection up somehow and it infected all my *.mp3 files. I only picked this infection up after using ESET NOD32 which could only quarantine the infected files.
Another George
Oh yeah norton symantec Bris.A remover tool does not work.
AnotherGeorge,
I’m happy to hear that you could successfully disinfect your files! Thank you for using Brisv.A Killer!
By the way, the code would need some more development to support ID3 version 2 tags (which are a lot more popular in MP3 files nowadays). Could someone give me a helping hand? ID3v2 specification looks quite complicated and I’m not sure how should it be implemented. The good thing is that most MP3 files contain both versions of tag information, so the lack of ID3v2 support should not be a major shortcoming.
I have already removed the virus using symantec’s fixbrisva tool. But the files were already damaged and they are not fixed. They can only play on wm player, but with a warning. I there anything I can do to restore them?
motseothata,
try to re-encode your files with ffmpeg. Check the following link to download the source code:
ffmpeg.mplayerhq.hu/download.html
You can extract the binaries from the Brisv.A Killer package, as well, if you don’t like compiling.
Use the file “ffmpeg”, if you use Linux or “ffmpeg.exe” if you are on Windows.
Hi George,
I’ve recently found this site. Great! Thank for your time helping so many people. I’m encountering some additional problems:
- no scanner recognizes my infected mp3s
- but they’re! It’s clearly visible when I’m opening the files in hex-view (e.g. trojan-downloading URL isvbr.net ….)
- your tools works without errors, but extracts only a short period of time (around 1 minute), between 200 and 1200 kb. The short piece isn’t working as well. Though it can be played but the strange noise stays.
I would love to donate, if I would have a tool that fixes my library. Most of it is corrupt and I need it ’cause i’m a professional musician.
Kind regards from Germany, kh
Hi George,
I have some addition:
Your tool works fine! But: if the file was changed after the infection (e.g. change in ID3-Tags) it cannot be desinfected. In this case I encounter the problems describes in my previous posting. Before changing ID3-Tags the infected filed can be played in WMP. But after a change they won’t work anymore.
Do you see a solution for that?
Kind regards, kh
Hi kleineheye,
I have a presumption, that changing ID3 tags actually rewrites the file header and cleans up the ASF byte pattern at the beginning of the file. This renders the file clean - at least for my utility. Brisv.A Killer uses file headers to decide whether a file is infected or not. If no valid ASF header is found in the first 10K block of the file, then the file gets ignored.
In your case, you still have infected files, but they seem to be clean to Brisv.A Killer. I’m going to drop a checkbox into the UI, which can be used to disable infection check and re-encode each file immediately. You’ll find a link to the new version, as soon as it is ready. It will take about 2-3 days, I will try to do my best!
Hi George,
sounds great! Is there anything I can do to support you? May some of my infected mp3s help analyzing? Please email me and I’ll do anything possible. I keep on waiting…
Kind regards, kh
Symantec does not care. They tried to blame their software error on me. I demanded a refund on the cost of their junkie product and purchased another scanner but the virus has damaged my ability to update a virus scanner. That part I can not undo no matter what I do to repair it.
The most upsetting part of this whole experience is that when I called Symantec to complain about my malfunctioning virus scanner the phone was forwarded to a call center in a country known to create and release said viruses. I was told I would have to pay an extra fee and I would have to allow these foriegners on foriegn soil access to banking info and my computer to remove the virus. The FBI on the other hand says to never give those call centers your info because they are safe from american law.
Well.. the thing is.. i have a hole bunch of songs healed… but whenever i play them or copy them to itunes only the song’s name is showed, and i lose all the album, artist, etc info…
In windows explorer, winamp, or wmp I can see the artists and everything.. why is this not happening in itunes?
I tried using your removal tool, it said not responding. I was using Frostwire and I stopped a song less than half way thru the download. Unfortunately it’s got this stinking virus. I am unsure what I Can do. I am freaking out that this can do major damage to my machine. I have removed Frostwire from my pc but I can still open folders from Frostwire and that incomplete song is still there. I can’t delete it and I really need help, George Can you Help me??
Hi Devon,
steps you could take to delete that file:
1, Start your system in safe mode and try to delete the file from there.
2, If you still can’t delete the file, use a live CD (Hiren’s bootcd, Ubuntu install CD…) to boot your system and retry deleting the file
3, If nothing helps, run chkdsk from the Recovery console (it can be run using the Windows install CD)
Corrupted files can’t be fixed with my tool, it’s only able to heal infected files.
Ok so I to have this trojan and Symantec-Norton tells me i have to remove manually which i tried to do but the location HKEY_CURRENT_USER\software\microsoft\pimsrv does mot exist.
Also I am using Vista so I keep getting Adminstrator passowrd needed when i try to run their supposed fix. Why do i need a password and who set it.
I got this virus from frostwire as well. I am so dumb when it comes to a computer, Im lucky I can turn it on.I too am running Vista and getting the same message as the above person. If anyone, who has the patience to explain this to me, I would be truely greatful. I know this is said to effect media files, but since I found this trojan, my computer wont load a messenger. And, it is taking FOREVER to shut down and reboot. Is this part of the virus?
Thanks,
Kim
Hi,
to run the Norton removal you have to right click on the tool and click run as administrator, Norton wanted to rip me off and charge £70 to do this!!
But, I still have the blasted virus there, Norton says its been removed then it comes back again!
Can I completly delete all my Frostwire and Limewire applications and then delete all songs?
will it be gone then??
Lisa
I’ve uploaded CCleaner and it has removed Trojan Bris Av. When you finish to install it, you click on the shortcut. Then, you click on OPTIONS so that you can select the file (in which the virus is in) and you clean it up. And it will be erased, it takes a few seconds. I hope I’ve helped.
I also just got the trojan.brisv.a and i found using malwarebytes does get rid of it.. it found 1405 infected files and folders and now my computer is clean… to bad i thought norton was protecting me. i went to malwarebot.bytescan.org… hope this helps anyone
I also got a Trojan.Brisv.A virus and I have norton so how the hell did it get in. I ran the removal tool which said it had been removed but on rescanning with norton the trojan was still there, so upon instruction i removed norton and scanned with avg, no trojan found. Reinstalled norton scanned with that no trojan found scanned it with super antispyware, no trojan found. Scanned again twice with norton no trojan found, scanned with spy bot nor trojan found. So what the hell happened to it. What i would really like to know as norton are of no helpe what so ever is that will this trojan have got into my email files, as i don`t want to email people and send this trojan out. I do have norton on and it scans all incoming and outgoing mail, but feel insecure as it let the trojan in in the first place. Someone please help this is driving me mad many thanks Kath
I got the Trojan.Brisv.A infect my computer. My main concern is if this virus poses any other security threats besides corrupting the music files. I really don’t store personal information in my computer, but I think I may have gone to my bank websites after i got this virus. I already changed all passwords, but is there anything else I should worry about?
Also, I tried the removal tool, but it just says trojan not found, and when i rescan, it says i’m infected. What can I do???!!
Is there any other removal tool I can use? I don’t feel safe even turning on my computer anymore. I also have the Norton antivirus installed, but this didn’t seem to help stop the virus and it cannot delete the Trojan.
It also just showed up on my computer yesterday (feb 4th). I think I will try the CCleaner but will check back again if nothing happened.
I have this virus and like all i have the same issue with the cleaner of Norton or Symantec… The thing is that it have only been detected in 4 files, which i would like to eliminate. A question, After running the Brisv Killer i can eliminate those songs? :l Is this virus dangerous?. Does the CCleaner Works? This is kinda freaking me out.
Thanks, Anny
Use The Removal Tool On Safe Mode, It Works
hi!!! the auto-protect results of symantec keeps on popping uo on my screen stating that there is a trojan.brisV virus in my laptop. i removed the infected file after i found out that it was infected. when i scnned my files with other antivirus like threatfire, it kept on saying that there is no virus in my laptop…but i’m really pissed of with the popping alert of symantec. removing it is also not possble.what will i do to fix it? thanks a lot~.~
hi!!! the auto-protect results of symantec keeps on popping uo on my screen stating that there is a trojan.brisV virus in my laptop. i removed the infected file after i found out that it was infected. when i scnned my files with other antivirus like threatfire, it kept on saying that there is no virus in my laptop…but i’m really pissed off with the popping alert of symantec. removing it is also not possble.what will i do to fix it? thanks a lot~.~
My computer has been infected with the same Trojan virus, and I cant seem to get rid of it or quarantine it. I use Norton 360 and it finds it, tells me to download this removal tool but the removal tool says i dont have the trojan on my comp, but yet when i run the virus scan, it still pops up! What am I to do??
derey01@Yahoo.com
hi same thing happeneing with me im so frustrated i keep removing it with norton tool i have norton 360 but it keeps reappearing please help ?
naughtysandy27@yahoo.co.uk
Hi Anny,
I got the same virus, ran removal tool which told me no virus, scanned again with norton told me still had the virus, removed norton and scanned with various other things eg AVG, Spybot and Super antivirus, reinstalled norton scanned with that and found no virus. I deleted the 4 music files it had infected and scanned with norton again yesterday and it is still showing up with no virus, so something i did must have removed it. I have tech support with PC World, and I rang them this morning as I too am scared of sending mail etc, and they told me that this won`t attach itself to mail as it comes through music downloads, and also if the virus had still been there norton would have picked it up and also norton scans emails going in and going out. I sent an email from my computer and back to it just to check the scanning of it, and it scanned ok, and there was no virus. Hope this has been of some help
Kath
Sandy, the Symantec utility you download does not work on this trojan. The virus alert also tells you what to do if the utility does not work. Try the following, which I got from the symantec notice. It worked for me. I am using Vista
First find the infected file. If Symantec keeps telling you it’s on the computer, hit ‘details’ on the antivirus notice and it will locate your file. That’s true even if the utility says it cannot find the file. If you have been swapping music files on a P2P network, it’s one of your recent MP3 downloads in all likelihood.
When it says sign on as administrator, that’s you usual signon if you are the only user of the PC. Then go to your start button at the lower left of your screen, click it and go to control panel, using classic view. Then click on user account control, and unclick the box on the UAC. Hit OK, restart your computer.
Then go to the start menu, hit all programs, accessories, run. Type in msconfig. (without a period.) Then OK, then on the menu, click on ‘boot’ then click on the ’safe boot’ box. Then restart.
That restarts the computer in safe mode. Then you go to start menu and find the infected file using explorer. Delete it.
Then restart again, (you’ll be in safe mode) then start menu to all programs to accessories to run msconfig again, and uncheck the safe mode boot.
Then restart and you’re home free.
At least that sequence worked for me.
took me all day to sort it out..for sumthing so easy. boot up in safe mode. file with virus in send to recycle bin then empty.. has to be done in safe mode.
I used the trojan.Brisv.A removal tool from Symantec in SAFE MODE and it worked fine. I also ran a second virus scan after restart and only a tracking cookie was found. I did try it the regular way and it said the virus wasn’t there but the instructions clearly say if it fails use SAFE MODE. It took roughly 1 hour to thoroughly scan and locate the virus.
I also got a log file that showed me exactly what files were infected- two music files placed in Itunes by a friend when they charged their Ipod. I have already told everyone of my friends that my computer is no longer a charging station. Itunes has been permanently deleted along with any libraries that it saved in the process.
Before you bash it try it again in SAFE MODE then if it doesn’t work come back and bash it.
If you are having problems with the removal tool, run the scan, then examine the detail of the trojan. It will list the infected files. Boot into safe mode and delete the files from within safe mode. The virus will be gone. Run a final scan to be sure. I must say that Symantec screwed the pooch on this one. Their removal tool sucked. My only saving grace was examining the detail of the trojan found and I just deleted the file. I know you may not want to hear this, but I would not try to save the infected files. Just get them deleted.
Ditto, ditto, ditto on the frustration with Norton . . . that they let the trojan in in the first place, then they detect it for you, then want $100 to fix it . . . I’ve read the whole string here, copied sections that are pertinant . . . heading off to fix my computer now. Thanks to all who have sorted this out ahead of me, can’t thank you enough!
J.
Alan, your method worked great (Alan Rugby post dated Feb. 8, 2009). The Brisv.A trojan is no longer on my computer. Symantec was not as clear as your instruction. Thank you for posting.
Ooops, sorry it was post by Ken dated Feb. 6, 2009 that gave instructions on removing Brisv.A
I have used the CCleaner that someone ment earlier on this forum.
In this program you can click on the folder that is infected and let it delet that special folder.
It worked on my computer and now it’s gone!
So people, download the CCleaner and let it delete your map with the infected files.
Thanks a lot for the post Ken dated Feb. 6th 2009. The Symantech tool failed to work for me too.. I had to boot up in Safe mode and delete the infected files.. and then remove them from the recycle bin..
Norton charged me $99 also to remove it. Their agent did not remove the virus during our session so I called back to schedule another session. I scheduled a call back time and they never called at the time they said they would. At this point I did my own research and figured out how to remove it myself. I don’t remember the exact sequence of steps I used but the solution is outlined here. It basically involved noting what the infected files are, where they are and removing them in safe mode. Also, empty the recycle bin. And now Norton has changed their removal info on their site.
I requested a refund for the agent session and they did refund me. It’s worth trying if you’ve been charged and they haven’t removed the virus.
Just tried to find details of infected file 2 are music files but two others are classified as a ‘Restricted Item’ Permission required.
Norton also state ‘Not Safe to Remove’. What options do I have
If you want the trojan remvoved, just start your computer in safe mode, and run the cymnatec removal tool, and it will be gone ;D
george i am not very computer literal but can u help me fix this my email is baby_ladie89@hotmail.com
Wondering if someone can help me out here. I just got this same problem, and I read all the posts about it just now. That tool by George did not work, and Im going crazy about it here….lol
What can I do if the virus is on my External Hard drive? I tried to rename the file, and it allowed me to do that, but when I try to delete, its doesnt!
Im running Windows Vista 32bit, and Norton picks it up as a threat, but only gives me the option to Reveiw it, and I followed those steps with the Removal tool, and nothing!!!
Please help
a_correa4@yahoo.com
ccleaner worked a treat for me !!!!!!
i am having the same problem with this damn thing. screw norton they are just trying to make a dollar. truth be known i will bet they did this since times are hard with the economy trying to get money. if anyone can help me remove this i will be so happy slipknoteclipse [at] aol [dot] com that is my email pls help me i beg lol
I got the virus off of my comp by removing the infected files in Safe Mode and then the ones that said restricted/permission needed, I just removed them using Norton in regular mode. Good luck!
I have a Trojan Brisv. A!in virus. I have taken multiple steps to remove it with no progress. Nothing can detect it( Beside Norton and it says “needs manual removal” which linked me to the tools that don’t work.)I used ATF, and a number of other cleaners including, AVP Tool. The AVP could not find it I was wondering if you would like me to email you the file that the virus is in. However I wont if you dont say so because i would not want to e mail any one a virus. Note it has not seemed to cause major problems for me yet i don’t know if it is because i use i Tunes as instead of windows Media Player.
here’s what worked for me on 2/9/09: downloaded the removal tool from Symantec, restarted computer in safe mode and ran the removal tool. restarted the computer in normal mode and ran a complete system virus scan which indicated no signs of the virus. subsequent complete system virus scans every night since then have indicated no further signs of the virus.
Prior to 2/9/09 the removal tool didn’t work but i think Symantec has revised the removal tool once they realized the removal tool wasn’t working. Good luck!
I re booted computer in safemode deleted the file and the folder it was in emptied the recycle bin and it was gone. didnt find any thing else have done multiple scans with different tools, and still nothing. Could this really have worked?
I had this same Virus, and i agree with many on his particular thread -
Restart computer in SAFE MODE, locate infected file(s) - and try to manually delete in recycle bin.
Then restart Windows normally - run comprehensive scan - NO VIRUS SHOULD BE FOUND.
If this does not work - Try using the Fix.Brisv.Removal Tool (in normal & safe mode)
If still no luck - reply to this thread, and i’ll get back to you.
p.s. Is it just me, or does everyone who’ had this virus have trouble viewing videos on YOUTUBE.COM???
It states that i don’t have the correct Adobe Flash Player installed - when i already do!!!
And/Or my javascript has been turned off - Which it hasn’t!!
Anyone who had the virus and have now got rid of it, could you be kind enough to let me know if you have the same problem with YOUTUBE etc..
Many Thanks
I managed to get rid of he virus in Safe mode following Danny’s tip. However for some reason I now can no longer access any websites even though the system says I am logged on and have ‘connection’. I have run a windows diagnosic scan for the connection failure and the message appears to imply that some sort if firewall is preventing access to the web. I’m on the verge of calling Internet Heroes!
thanks for the reply danny it worked just fine i cant belive it. i did not have any trouble watching videos. my internet did run slower though. To ruddin: you probably are behind some firewall find it and turn it off
To ruddin i apologize for the last post iwas unclear what i meant was there are many differnt was to configure a firewall and you need to find the port or whatever is blocking your access it is not safe to turn your firewall off but even in default setting it is alot more effective than nothing.
It worked!
I booted in safe mode then ran the Fix.Brisv.Removal Tool from Norton and it removed the virus without a problem.
Thanks!
Symantech tool??/ They’re probably the ones who are propagating this virus-I HAVE (and until now)was paying for a Norton subscription, and they want to charge me $100.00 in fees to remove the trojan.
I’ve got the same problem, so is this a fault with the Norton? I’ve run the Symantec removal tool an it tellsm e there’s no virus there, so then I restart, and Norton tells me there is. So wtf is going on there?
heidi I have the same problem like you I don‘t know what I have to do?
and I want to know if I recavary my computer the problem will solv or not ??
I said before,
if you’re not so computer technical you can download the CCleaner.
It will remove your infected files if you select the map that it must remove. That’s how easy it is!
I just removed this virus from my computer. YOu need to read carefully when removing this virus. Mine told me that I would have to manually remove the virus and it showed me the infected file. Needless to say removing the song it was attached to didn’t work so I had to delete my entire I-Tunes Library and software but that is a small price to pay considering what it could have cost me to have the pc repaired. So make sure Norton’s removal tool for this virus isn’t telling you to manually removed it before going any further.
Holy moly, it takes forever to download George’s removal tool. I’m living in the US and apparently my location only allows me to download at 50 BYTES per second! -_-
If anyone could upload George’s removal tool somewhere or send it as an attachment to my email, I would greatly appreciate it! kevin5953@aim.com
I tried a few times using the FixBrisvA.exe tool to remove Trojan.Brisv.A from my computer. I disconnected from the internet and ran the tool but it kept telling me that Trojan.Brisv.A was not found.
Then after reading some of the posts just now, I decided to try running my laptop in Safe Mode. To do this, I Restarted my computer and when it rebooted I repeatedly pressed the F8 key and when the options came up on the screen, I selected SAFE MODE. From the desktop, I ran the FixBrisvA.exe tool again, this time I was told the virus had been removed. I’ve now restarted my computer and live in hope!!! Worth a try!
dear Mynoona
which system you use vista or XP??
and what the diferent between those systems ??
This works people
Download the FixBrisv of symnatec/norton and save to your desktop, restart your pc under safe mode using F8, thats the bit they dont tell you to do on the how to use,run your scan and there you go virus gone. Your problem is now solved :) Mat
Not so much Mat. My case is different from everyone else’s because I had the infected file, but I used System Restore to get rid of it. Now I’m suffering from very high lag, and cannot find any trace of the trojan, and none of these programs can find it because the file isn’t really here…
Hi Zoran
I’m not very good at the technical differences but I think the major changes in security is that it’s supposed to be improved to stop hackers getting into your hard drive and to prevent spyware getting onto your system. The Windows Defender tool seems to be already present instead of having to download and parental control features.
Having said that I run all of this and Norton regularly and ooops!!! Trojan!!
I have the trojan.brisv.a and i havent a clue how to remove it. Ive done everything symantec has told me but none of it works. Can someone tell me how to be-rid of this virus.
I’m not very good at all the technical things, I have removed the music file to recycle bin, then emptied it. Norton says trojan.brisv.a! is gone i am not sure, i have restarted in safe mode and ran the tool again then back to normal mode and scanned again, i am not sure if it is gone or not. How can i be sure.
hey. i just want to know. does trojan.brisv.a destroys or infect music files ONLY?
george. hello. im shane. in my case,there are only two files infected in my laptop. what should i do? can you help me?
hi george…
i tried to download ur brisv.killer, but i think your site is down or something… could you PLEASE email me your latest version! I had a copy of it but it got deleted by mistake! AWESOME PROGRAM!!
Thanks a lot
Brad
Thanks to all who suggested running the Symantec removal tool in safe mode. I had already run it several times without success in normal mode and was getting quite annoyed (sometimes Norton really does suck!). I am semi-literate technicallly so I know I was doing everything correctly. Finding the solution here helped me to keep my sanity. Again, many thanks! (It would be nice if Norton would tell folks to boot in safe mode to run their tool.)
Reading all of the details from all of you i am so lost… I deleted the 2 files that were infected with the virus - i ran norton who only deteced the stupid files 4 months after they have been nicely sitting on my pc. so got scared and deleted the files (also from the recycle bin). Then i did allthe things you guys were refering to and norton is stating no trojan is left on my pc, but my pc seems to be having problems, including i am getting a hard drive smart error message. can this virus be causing system issues?? What if i do a complete reinstall of my pc - reinstall everything, would that work? If this would work, how do i then clean up all my music which is on an external hard disk??? any help would be appreciated as i also dont want to fund the Norton fund any more as their help is useless… Please
I have this trojan, it prevents my internet browsers from connected to any websites at all and initially I thought I had an internet provider problem. Norton has removed it twice and my laptop appeared to be fixed and working well then again it wont display any pages.
Any ideas?
Any Response?