Trojan.Brisv.A

Trojan.Brisv.A is a threat that can be downloaded from file-sharing networks hiding itself on multi-media file. Files infected with Trojan.Brisv.A may trigger Windows Media Player to connect to contracted web sites and download additional virus. Infected file remarkably increased its size by 1,138 bytes after the Trojan append its own code.

Alias: W32/GetCodec-A

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista

How to Remove Trojan.Brisv.A:

FIRST AID TO STOP Trojan.Brisv.A:
This threat is powerful enough to alter the registry and infect legitimate Windows files. Windows’ built-in tool called System Restore can reinstate clean system files by restoring the configuration to an earlier date. This method is possible only if a restore point was created before you got infected with Trojan.Brisv.A. Proceed and restore Windows to previous configuration.

Trojan.Brisv.A REMOVAL TOOL:
1. Download the FixBrisvA.exe
2. Save it to a desired location.
3. After download completes, disconnect the computer from Internet.
4. Computers who are running under operating system Windows ME and Windows XP must disable System Restore.
5. Reboot Windows in Safe Mode.
- After turning on the power, press F8 on the keyboard.
- Select Safe Mode from the menu.

6. Go to FixBrisvA.exe download location on your hard drive.
7. Double click FixBrisvA.exe to run the tool.
8. Let the tool thoroughly scan the computer and perform another scan after rebooting Windows in normal mode.

MANUAL REMOVAL OF Trojan.Brisv.A:
1. Update installed anti-virus application to have the latest definition file.
2. Reboot Windows in Safe Mode
- After turning on the power, press F8 on the keyboard.
- Select Safe Mode from the menu.

3. Thoroughly scan the system and clean/delete all infected file(s). Please see below.
4. Delete/Modify any values added to the registry if present. Refer to associated Windows Registry Entries.
- Click on Start. Search or Run regedit.exe to begin registry editor.

Note: You may refer to links on sidebar for a complete tutorial on Safe Mode and Registry Editor.

5. Exit registry editor and restart Windows.

ADDITIONAL TOOLS AND PROGRAMS:

Scan with Norton Power Eraser:
A free removal tool from Norton Antivirus was developed to remove virus and unfamiliar threats without using the traditional AV signatures. Download the tool and start scanning with Norton Power Eraser.

Technical Details and Additional Information:

Other functionalities of this Trojan:
- Trojan.Brisv.A will convert .mp2 and .mp3 files to Windows WMA format.
- It searches and infects media files with following extensions: .wmv, .wma, .mp3, .mp2 and .asf.
- Execution of infected files will open Windows Media Player and hook up to malicious web sites.

Associated Windows Registry Entries:
HKEY_CURRENT_USER\Software\Microsoft\PIMSRV