Forum Home
Press F1
 
Thread ID: 105285 2009-11-25 22:52:00 Britannia Malware linw (53) Press F1
Post ID Timestamp Content User
833660 2009-11-25 22:52:00 I suspect I will get a friend's computer with what sounds like the Britannia search redirect trojan in it. It sounds really nasty so am not looking forward to this one. Won't let you run msconfig or regedit etc.

Anyone had to deal with this one?
linw (53)
833661 2009-11-25 23:04:00 Not specifically, but boot into safe mode with networking if possible, disable system restore, install Trojan Remover, update and run it, as well as running all the tools in the Options menu, and then post a Hijackthis log here. nofam (9009)
833662 2009-11-26 00:35:00 Thanks . Will do this but more drastic action seems to be needed . Combofix has been used I note . Main thing is to get data off it and hope my friend has the XP CD (or restore partition) if all else fails!

Anyway, I haven't got the machine yet so no panic at this stage .
linw (53)
833663 2009-11-26 00:43:00 Or boot into safe mode / networking do a full scan with malwarebytes Speedy Gonzales (78)
833664 2009-11-26 01:54:00 Yea, malwarebytes was going to be my starting point.

Cheers.
linw (53)
833665 2009-11-26 03:35:00 You might need to rename the Malwarebytes exe
some of these nasties block it from running.
KarameaDave (15222)
833666 2009-11-28 03:42:00 Thanks for the tip. This one does seem to block exe's. linw (53)
833667 2009-11-28 04:09:00 IF it blocks Every exe ( cleaning software) it may be more of a problem than you think - just finished reinstalling a customers PC, had a virut.56 virus, stopped EVERY cleaner out there, malwarebytes, Comodo etc, even in safe mode, nothing would run.

Hope you dont have this (www.computer-juice.com) - only way to fix it was drag the data from the drive Via a linux Live CD, couldn't use Windows as originally it infected the workshop PC as well and reinstall -- Real nasty piece of work.

Heres an example, when I copied the driver folder to a flash drive (the exe files from Compaq) then scanned with Nod32, it found 45 infected files - guess what ? didn't use those drivers :)
wainuitech (129)
833668 2009-11-28 04:12:00 Could be similar to this post (pressf1.co.nz) the link on the last post is a virut variant. Its in the HJT log that was posted Speedy Gonzales (78)
1