answersLogoWhite

0


Best Answer

Is it not allowing you to turn off system restore>? or do you just not know how? Well probably your best bet is to go to www.symantec.com and look in their virus encyclopedia for removal tools or methods.

Another thing you can do is run avg antivirus and find the root it is at just follow the path it gives on avg right to the file then delete the file. Eg: C:/documents and settings/user/temp/ etc etc so start by clicking start, then click C:/drive, then documents and settings folder etc etc till you come to the file that is the culprite then delete it. After you delete it press ctrl f click search all files and folders, put psw.bispy in search field, then put search all drives. Delete all the files it finds with that name. Then empty your recycle bin. Now restart your computer and try to search for it again hopefully this got it :)

AVG has special removal tool on their site. I used it to remove the pest. Then I ran TDS-3 anti-Trojan scanner, traced all and any remains of the bugger, including the temporary file with which it had come, and removed them.

You can get rid of this Trojan by following these steps .

1 Download and intall the Malwarebytes on your computer .

2 Update your Malwarebytes .

3 Scan your computer for all the malwares in your computer .

4 Remove all the malwares , found while scanning with the malwarebytes .

5 Restart your computer .

You need to run these 3 essential programs to remove all the spyware on your computer.

If you do not have an internet security suit and only an anti virus

1. Run Malwarebytes Anti-Malware

2. Run a complete scan with free curing utility Dr.Web CureIt!

3. Run the anti spyware removal programs spybot or Superantispyware

Browsers

Use Mozilla firefox or the Google chrome browser for browsing unsafe websites

Install ThreatFire

ThreatFire, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

Run an online virus scan like

Trend Micro HouseCall

Kaspersky free online virus scanner

Windows Live OneCare safety scanner

BitDefender Online Scanner

ESET Online Antivirus Scanner

F-Secure Online Virus Scanner

avast! Online Scanner

update your software by running

Secunia Online Software Inspector

Install a good antivirus in your computer.

Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them.

Keep your permanent antivirus protection enabled at all times.

User Avatar

Wiki User

8y ago
This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: How do you get rid of Trojan psw bispy if you can't turn off the restore feature in Windows XP?
Write your answer...
Submit
Still have questions?
magnify glass
imp
Related questions

How do you get rid of Trojan horse PSW Bispy A?

I found the same Trojan on my computer. AVG was able to detect and clean it with the latest update. I suggest using that. I Had this Trojan Horse Virus and it installed itself as a programme Bridge.exe, so i uninstalled it using the Add/Remove programme.Then I turned off System Restore and ran Trend Micro free scan which showed the files bi.dll and biprep so i ran Adaware and it picked these files as spyware, so i deleted them. Ran Adaware again , this time all clear. Then I ran AVG that was all clear. Than finally Trend Micro free scan. All clear. Trojan Gone.Turned System Restore back on and ran AVg and Trend Micro free scan once more. Still all clear. Hope this helps someone. you can get rid of this virus by downloading pestpatrol from pestpatrol or you can also use the hijackthis program it will clean all kinds of virus on your computer I also have AVG and it could not take it off either even though it was updated. I, however, did find an alternative given by grisoft/AVG at the following URL: grisoft.com I would suggest following its instructions to the letter. If you do, you can then run AVG again and the Virus will have disappeared. Good Luck! You can get rid of Trojan horse PSW Bispy A , by following these steps . 1 Download and intall the Malwarebytes on your computer . 2 Update your Malwarebytes . 3 Scan your computer for all the malwares in your computer . 4 Remove all the malwares , found while scanning with the malwarebytes . 5 Restart your computer .


How do you get rid of the Trojan bispy?

With AVG virusscanner Good Luck, Jahewi :-) Bispy might be in a directory that has a .exe extension on it, with a colon (:) on the end, which screws up Windows' ability to see that directory. Scan the computer with AVG (Norton and Symantec won't even find Bispy), and AVG will tell you what directory the virus is in. In my case, it was in c:\windows\system32\biview.exe:\ Because of the weird name for that directory, Windows Explorer couldn't even see that directory, and so couldn't remove it. Record the path to the virus on a piece of paper, then boot into Safe Mode. Start up a DOS box (Start >> Run >> type 'Command' >> Click 'OK') Change the directory in the DOS box to the directory directly above the directory holding the virus (in my case, it'd be C:\windows\system32\), then rename the weirdly named folder so it no longer has the .exe extension or the colon (:) on it. After that, remove the directory to get rid of the virus, and do another virus scan with AVG. You need to run these 5 essential steps to remove all the spyware on your computer. 1. Run Deckard's System Scanner (DSS) 2. Run Malwarebytes Anti-Malware 3. Run the anti spyware removal programs spybot 4 Run Superantispyware 5. Run a complete scan with free curing utility Dr.Web CureIt! Install threat fire which will enhance your antivirus protection


How do you get rid of psw bispy E?

I couldn't find very much on the E-strain of bispy, so i don't know if AVG will help this time. However because it's of the same 'family', i think it's a save bet to say it does …. If Avg doesn't eliminate this bispy.E-pest, try a online scan with the pestscanner of PestPatrol at pestpatrol.com Good luck, Jahewi


How do you get rid of PSW Bispy D?

Try this link: grisoft.com Follow the instructions (rename file, run computer in safe mode, then run executable).


How do you delete PSW Bispy D from folder 'system Volume Information' when you can not access this folder?

you can get access to the system volume information folder. follow the steps on this site -


What is PSW Bispy D and how do you remove it?

You need to run these 5 essential steps to remove all the spyware on your computer.1. Run Deckard's System Scanner (DSS)2. Run Malwarebytes Anti-Malware3. Run the anti spyware removal programs spybot4 Run Superantispyware5. Run a complete scan with free curing utility Dr.Web CureIt!Install threat fire which will enhance your antivirus protectionPSW Bispy DHere are opinion and answers from FAQ Farmers: It's a Trojan password stealing virus. The Free version of AVG by Grisoft removed it from my computer. They also have a free removal tool.I downloaded the trial version of AVG and it found PSW.Bispy.A and B. Then I downloaded a tool, but when I scanned with the tool it removed PSW.Bispy.D. I'm kinda confused now as my PC is still showing I have A and B.Try this link: grisoft.com. Change the file name, restart the computer in safe mode and then run executable file.


How do you remove Bispy A and B if nothing seems to work?

Hi Julie I managed to get rid of Bispy B by running SpyBot Search and Destroy. My AVG proffessional version picked up on the fact I had this darn thing but for some reason just leaves if in the system. Hope this helps. I also have AVG and it could not take it off either even though it was updated. I, however, did find an alternative given by grisoft/AVG at the following URL: grisoft.com I would suggest following its instructions to the letter. If you do, you can then run AVG again and the Virus will have disappeared. Good Luck!


How do you remove bispy A and B from windows 98se?

You need to run these 5 essential steps to remove all the spyware on your computer. 1. Run Deckard's System Scanner (DSS) 2. Run Malwarebytes Anti-Malware 3. Run the anti spyware removal programs spybot 4 Run Superantispyware 5. Run a complete scan with free curing utility Dr.Web CureIt! Install threat fire which will enhance your antivirus protection


How do you remove Trojan Bispy in windows BTGRAB.DLL file?

Reboot your computer When windows starts press F8 Choose "safe mode" then the windows version hit enter When asked if you want to run your PC in safe mode say "yes" Once in safe mode go to the folder where BTGrab is stored Delete the file and then remove it from recycle bin Go to start/run and type in "regedit Once that opens click on my computer and then file/find Type in BTGrab Delete any key that comes up Repeat the find next option or press f3 until it says "finished searching the registy" Reboot You need to run these 5 essential steps to remove all the spyware on your computer. 1. Run Deckard's System Scanner (DSS) 2. Run Malwarebytes Anti-Malware 3. Run the anti spyware removal programs spybot 4 Run Superantispyware 5. Run a complete scan with free curing utility Dr.Web CureIt! Install threat fire which will enhance your antivirus protection


How do you get rid of bispy Trojan virus that is embedded?

This is the free Microsoft anti-virus line. This is a totally free service that will walk you through the virus removal steps: For support within the United States and Canada, call toll-free (866) PCSAFETY (727-2338). You need to run these 5 essential steps to remove all the spyware on your computer. 1. Run Deckard's System Scanner (DSS) 2. Run Malwarebytes Anti-Malware 3. Run the anti spyware removal programs spybot 4 Run Superantispyware 5. Run a complete scan with free curing utility Dr.Web CureIt! Install threat fire which will enhance your antivirus protection


How do you get rid of Trojan horse PSW Bispy B?

You have a very formiadble infection. good thing you know the name. PSW Bispy B has infected many computers. The problem is that that most antivirus programs don't detect it. The only ones that do is AVG and windows live onecare. However AVG detects but it can't do anything about it. Go to this link http://onecare.live.com/standard/en-us/3/communications/trytoday.htmIt will allow to download live onecare with a free 90 day trial.You need to run these 5 essential steps to remove all the spyware on your computer.1. Run Deckard's System Scanner (DSS)2. Run Malwarebytes Anti-Malware3. Run the anti spyware removal programs spybot4 Run Superantispyware5. Run a complete scan with free curing utility Dr.Web CureIt!Install threat fire which will enhance your antivirus protectionGo to GriSoft and download their AVG anti-virus software. Be sure to get the free version. Run the program. It will automatically isolate & remove the Trojan horses PSW.Bispy.A and PSW.Bispy.B, as well as most other viruses and Trojan horses.On Win 2000:After AVG picked up the instances of BIspy.A and .B in my users /Local Settings/Temp folder, I deleted the 6 files associated (cab, ini, exe and some others that started with BI)then went into the registry (start > Run > Regedit), searched for "BI.dll" and deleted the registry entry for the program when i found the correct string.If you are not keen on editing the registry yourself, get hold of Spybot - Search and DestroyAfter I restarted the machine, and was able to delete the /winnt/BI.dllim running AVG too, same problem with virus vault. To get rid of it (using winXP) this is what i did.ran command prompt.CD 'local settings'\tempdel bi*seemed to work for me.I too had the virus that my avg would not remove. what I did was move the infected file to the recycle bin and then ran the avg scan again. This time it healed it and put it into the vault. ..I too had the PSW.Bispy.A and PSW.Bispy.B viruses on my C- Drive.AVG anti-virus software detected and removed the bi.dll file but was not able to delete the virus contained in a file in the C:\_restore\temp folder. I am running Windows ME and I think the files in the folder cannot be accessed because they are used by the RESTORE function. To get around this, I downloaded a windows bootfile from www.bootfile.com, copied the files to a floppy and then booted from the floppy. At the A> prompt, I changed the drive and directory to C:\_restore\temp. Since I booted from the floppy, I was able to delete the infected file. I then rebooted from the hard drive and ran AVG anti-virus software again. This time it found the virus in another file in the same folder. I then rebooted from the floppy, erased the infected file and rebooted from the hard drive. AVG was rerun and the virus has been removed completely. It took two iterations to remove it completely.Two online virus programs did not detect the virus before it was removed. AVG was the only one that did.I have XP Home Edition and ran AVG. The program detected and removed the virus just easily.Finally after a day of trying to clean it, I turned off my system restore, then rebottted ...ran AVG. it stuck them in virus vault and I was able to delete them...have scanned 3 times now and they are all gone...this got rid of it for me.download WINPATROL and then run it it will come up with a screen pretty much straight away click on ie helpers tab and you will now see a file bi dll.delete file,it will say that it wont delete it but it will stop it running by doing this it enables avg or your own virus software to delete it cos its not running.run your virus software and it will heal it problem solved.For those with PSW.Bispy.B or A or C AVG now has a small executable program on their homepage to deal with these and 60 others..simply boot up in safe mode(I'm running Windows ME) click on the downloaded file,and it removes all 3 files associated with the virus..reboot normal and Voila! Worked on my version A.If you can move them to your recycle bin then delete them and your problem is solved.All Trojan horses are hidden files so you would need to go to the Files Option (click the View tab)at Control Panel and uncheck both the *Hide file extension for known file types & *Hide protected operating system files (Recommended)-boxes, then OK yourself out. You will then need to restart your computer and go into SafeMode by HOLDING the F8 key DOWN -(at bootup - after the first screen info - be quick!). [You have to use your keyboard when you're in SafeMode - the keys to use are Ctrl/Alt/Delete (to exit the Help and Support screen) - Tab/Arrow keys/ Pageup/Pagedown/ the Window key(between Ctrl & Alt) & Enter] So, from the DeskTop screen press the Window key to get Start/ arrow up to Search/ arrow right to For Files or Folders and type up the NAME OF THE FILE & EXT (not Horse PSW.Bispy.B) but the actual name of the file, which would have shown up on your anti-virus software. To delete this file from here just press Page Up to highlight the file and then delete. To get out of Search -Alt F/ arrow down to Close and press Enter.It will be safe to empty your Recycle Bin in the Normal mode where you can use your mouse.I have had 4 Trojan horses on my C drive and kinda figured out the above method a week ago. I deleted the Temp file (as these keep putting the same files back into your system) from the _Restore folder after unchecking the hidden files boxes, then went to SafeMode to delete what virus files that were still there. My computer is now absolutely FREE of these pests!PS. I also have AVG 6.0 (the free one) & also the Ad-aware 6 and I use them every day as my kids love to play games from the Internet.The AVG cannot get rid of it because it is locked into your system as a hidden file. The way to get at it is to unlock the file by going to Start/Settings/Control Panel/Folder Options/View tab and uncheck the Hide file types...etc. as I mentioned above. Then all you would need to do is to go to Search and delete it. If not in the Normal mode, then Search and delete it in SafeMode.the problem with the virus in the restore folder is that AVG cant delete/modify files in there. you need to disable system restore. I also had this virus in a backup of my accounts. I tried running the removal tool from Grisoft but it didnt work. I disabled system restore, deleted the files associated with the virus then rebooted. I also searched the registry for any "bi" or"bispy" entries. there were none, so i guess im all good now. what ever you do just remember to disable system restore. if you don't you will continue to get the AVG extension message and if you ever need to restore to an earlier date you will reinfect your puter.I have AVG and it could not take it off even though it was updated. I, however, did find an alternative given by grisoft/AVG at the following URL: grisoft.comI would suggest following its instructions to the letter. If you do, you can then run AVG again and the Virus will have disappeared.You can get rid of the Trojan horse , by following these steps .1 Download and intall the Malwarebytes on your computer .2 Update your Malwarebytes .3 Scan your computer for all the malwares in your computer .4 Remove all the malwares , found while scanning with the malwarebytes .5 Restart your computer ,--To remove this thing from your computer , download and install the SuperAntiSpyware on your computer . update your computer and scan the computer with this. You can get rid of the Trojan horse , by following these steps .1 Download and intall the SuperAntiSpyware on your computer .2 Update your SuperAntiSpyware .3 Scan your computer for all the malwares in your computer .4 Remove all the malwares , found while scanning with the SuperAntiSpyware.5 Restart your computer .


What does Trojan Horse downloader PSW Bispy A do?

On further reading, this appears to be spyware. Did your virus scanning software by any chance Quarantine a file named "BI.DLL"? If so, see this: WinPatrol Spyware Alert BI.DLL Direct from source: Bi.dll installs as a newer variant of a spyware program called Transponder. This variant is released by a company called "Better Internet". This BHO (browser helper object) monitors the URLs you visit and the data you type into web forms and send that info back to it's home servers (currently stop-popup-ads-now.com and abetterinternet.com). It also generates popup ads and can download updates or other programs to your hard drive without your permission. We'd recommend removing this file. You can do so using WinPatrol or you can find manual removal instructions at www.doxdesk.com/parasite/Transponder.h... I, however, removed the virus with a virus remover found at: grisoft.com {I did not take any chances. I ran it in safe mode (for Win XP, F8 pushed while restarting) and renamed the file, leaving it on my desktop. It did not say the file was gone after it ran; But when I ran AVG Virus Scan again, it did not detect the virus}. Good Luck! I don't know how I got it. I assume I got it on the Internet somehow (probably in a popup while using IE) because my emails are scanned before they are even delivered to me and again before I open them. The question I have is how to prevent getting the darn virus again. PS... Please do not edit or change this response. Here are more answers and opinions from FAQ Farmers: * As far as I can tell "Bispy" attempts to install ads etc on a computer. It also tried to delete files on my computer. A friend of mine got it by just browsing the Internet, so watch out this one is sneaky. I use AVG and it detected it and healed it along with WinXP witch did a system recovery. * I think it's all to do with AVG myself. I kept getting the warning popping up and it was really bugging me, I had more popups than usual, too. I found the file BI.DLL and just deleted it. Since then I haven't had any warnings of the virus or as many popups. * PSW/BiSpy.A, as far as I'm aware, falls under the Spyware/Password Logger category of viruses. It doesn't have a payload per se, but is reknowned for allowing much more than the normal few pop ups through, especially if the website is sponsored. It doesn't allow other viruses to bypass a PC's firewall, like a Trj.Downloader, but instead opens other ports and protocols that allow pop-ups that can seek out these openings. That's why the PC's report more advertising than normal. Also, bi.dll, the link library that allows PSW/BiSpy to run has a link that writes itself into a random area of Windows Explorer (like a Dial-Up connection does) which makes it so hard to dispose of. Grisoft's vcleaner (http://www.grisoft.com/us/us_remtext.php?id=bagbugnet) tool removes the link to bi.dll (which is the reason that it needs to be run in safe mode, as it can't delete an active link). The best way of not contracting PSW/BiSpy variants is just not to use anything that is ad-funded. Or you can just be vigilant in what you download. AVG (www.grisoft.com), and SpyBot: Search and Destroy (security.kolla.de) can help. * I think i picked this one up from xoftspy, once downloaded i had 5 of these.good tips here on removal. avg 7 is recomended. Answer You can get rid of the Trojan horse , by following these steps . 1 Download and install the Malwarebytes on your computer . 2 Update your Malwarebytes . 3 Scan your computer for all the malwares in your computer . 4 Remove all the malwares , found while scanning with the malwarebytes . 5 Restart your computer , You need to run these 3 essential programs to remove all the spyware on your computer. If you do not have an internet security suit and only an anti virus 1. Run Malwarebytes Anti-Malware 2. Run a complete scan with free curing utility Dr.Web CureIt! 3. Run the anti spyware removal programs spybot or Superantispyware Browsers Use Mozilla firefox or the google chrome browser for browsing unsafe websites Install ThreatFire ThreatFire, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware. Run an online virus scan like Trend Micro HouseCall Kaspersky free online virus scanner Windows Live OneCare safety scanner BitDefender Online Scanner ESET Online Antivirus Scanner F-Secure Online Virus Scanner avast! Online Scanner update your software by running Secunia Online Software Inspector Install a good antivirus in your computer. Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them. Keep your permanent antivirus protection enabled at all times.