Troj/VB-ABA?

Toby1

Daemon Poster
Messages
1,028
Hey guys... Here is a screen shot to explain what Sophos AV picked up...

trojjvbabako7.jpg


Confuising thing is, no other AV product that I have tested has picked up this virus (Nod32, Kaspersky, Avira, Bit Defender, etc).

And I did a google search and couldn't find anything about this virus.

So do you think it's a false posative?

Thanks in advance for any information anyone can provide.
 
Toby said:
Confuising thing is, no other AV product that I have tested has picked up this virus (Nod32, Kaspersky, Avira, Bit Defender, etc).

Not too sure but it would be worrying that no other Anti-Virus has picked it up... However it could be a new trojan out? Have you tryed to report it or something like that?

To be on the safe side, im guessing you already have gone hunting for it where it says it is? {The location}.

Also it did heal the file(s).

Good luck.
 
Hey GG :)

It's not a new trojan cause' it pickes the same ones up a few months back... so I turned system restore off... didn't work.

I haven't actually searched for the file, will give that a try... thanks.

And no, Sophos couldn't clean the file and it doesn't have any information about it. And there is no way to report it to Sophos.
 
Toby said:
Hey GG :)

It's not a new trojan cause' it pickes the same ones up a few months back... so I turned system restore off... didn't work.

I haven't actually searched for the file, will give that a try... thanks.

And no, Sophos couldn't clean the file and it doesn't have any information about it. And there is no way to report it to Sophos.

Hey,

Was the the same trojan from a while ago, didnt you post on here about it?

Be careful!, if it read it right, it looks like it says the trojan is in 'system volume information'? is that right?
:S i would'nt be going deleting anything just yet, but i dont no..

Also try to clean up/get rid of tempor' internet files like cookies etc you dont need.
 
Hey again,

Nah the other trojan was a different one.

Yeah, it's in the system volume information_restore folder.

And... as for the temp internet files, I clean them out when the computer is shut down... with window washer... maybe I should do a scan in safe mode...
 
Toby said:
Hey again,

Nah the other trojan was a different one.

Yeah, it's in the system volume information_restore folder.

And... as for the temp internet files, I clean them out when the computer is shut down... with window washer... maybe I should do a scan in safe mode...

Hmmm, oh ok then..
*thinks some more*

Yeah, safe mode sounds like a good idea.

Toby said:
It's not a new trojan cause' it pickes the same ones up a few months back... so I turned system restore off... didn't work.
And no, Sophos couldn't clean the file and it doesn't have any information about it. And there is no way to report it to Sophos.

Yeah well it appears/might be that system restore is where the trojan is.. :S
As im sure you might no but system volume information(where the trojan is) is system restore..

Thats stupid that sophos cant help like that, if i was you i would get onto them about that. Thats IMO tho..

It's not a new trojan cause' it pickes the same ones up a few months back...

What do you mean by that :confused: Little confused again by that.

{I'll be editing this to add more, getting confused lil -.-}

http://service1.symantec.com/SUPPORT/nav.nsf/docid/2000092513515106
^ Might help, it does say something about repairing system restore, not sure it it will help tho, most sites say how to disable system restore but you no how to do already so its no use.

http://support.microsoft.com/kb/309531/
^ Again, might or might not help,

(And the link that down V have added)
 
Thanks for the replies...

When I get home I'll do a scan in safe mode and with system restore off and see what happenes... Will report back once done.

I'm just thinking, I know trojans are annoying, but considering this one's been in my system for months, wouldn't my computer have crapped itself by now?

I mean, it's seemed to run fine, even with the trojan on there... just is kind of weird.
 
Back
Top Bottom