Lowyat.NET Forums

Welcome Guest ( Log In | Register )

LYN wins Intel-Lenovo-Tangs Blogathon challenge. Thank you everybody!
27 Pages < 1 2 3 4 5 > »  
RSS feedBump TopicReply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> W32.Rontokbro Worm, updated : removal tools

Hungry_Wolf
post Mar 27 2006, 02:53 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #41


Enthusiast
*****

Group: Senior Member
Posts: 813
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Sep 2004
From: CyBerJaYa





QUOTE(low yat 82 @ Mar 27 2006, 02:32 AM)
my gf pc is infected wit WORM/Brontok.C, is there any proven ways and d easiset way to remove d worms...?
*


ur is variant C mine is variant N....
cant find any solution, now back up the file through network....
i think if u dare, unplug the hdd and plug to ur current system and run virus scan...

i backup al; the file throught network, and scan it with my comp and it can remove the virus....hopefully is 100% remove...
i'm using avg...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 27 2006, 09:27 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #42


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(Hungry_Wolf @ Mar 27 2006, 01:59 AM)
guys, need help...
my is brontok.N ur solution cant work in my laptop...
restart whenever a removal tool or antivirus run..
it disabled my AVG...
*


try using system restore...
restart using safe mode n use any restore point..
hope it might helps thumbup.gif

QUOTE(low yat 82 @ Mar 27 2006, 02:32 AM)
my gf pc is infected wit WORM/Brontok.C, is there any proven ways and d easiset way to remove d worms...?
*


what antivirus software ur using? sweat.gif

QUOTE(Hungry_Wolf @ Mar 27 2006, 02:53 AM)
ur is variant C mine is variant N....
cant find any solution, now back up the file through network....
i think if u dare, unplug the hdd and plug to ur current system and run virus scan...

i backup al; the file throught network, and scan it with my comp and it can remove the virus....hopefully is 100% remove...
i'm using avg...
*


err..
ur AVG didn detect brontok? sweat.gif
ur using the latest definition rite? sweat.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Mar 27 2006, 10:19 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #43


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,932
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




Anybody got any infector files for Brontok?

I'm trying to make a removal tool for it. I already have a beta unit but would like to test it further before release.

If you have any, please zip it up with WinZip/Rar & send it to submitals[at]yahoo.com

sUBs


This post has been edited by sUBs: Mar 27 2006, 10:20 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 27 2006, 10:23 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #44


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(sUBs @ Mar 27 2006, 10:19 AM)
Anybody got any infector files for Brontok?

I'm trying to make a removal tool for it. I already have a beta unit but would like to test it further before release.

If you have any, please zip it up with WinZip/Rar & send it to submitals[at]yahoo.com

sUBs

*


my friend's pc got infected with it..
i`ll try to copy the virus and send it to u..
i dunno if its the X@mm or U@mm since X@mm is the latest version of brontok... sweat.gif
i`ll check with u later biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Mar 27 2006, 10:28 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #45


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,932
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




QUOTE(eggy @ Mar 27 2006, 10:23 AM)
my friend's pc got infected with it..
i`ll try to copy the virus and send it to u..
i dunno if its the X@mm or U@mm since X@mm is the latest version of brontok...  sweat.gif
i`ll check with u later biggrin.gif
*



ANY & ALL versions of Brontok is welcomed.

Thanks
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 27 2006, 10:30 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #46


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(sUBs @ Mar 27 2006, 10:28 AM)
ANY & ALL versions of Brontok is welcomed.

Thanks
*


copied that biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Hungry_Wolf
post Mar 27 2006, 12:44 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #47


Enthusiast
*****

Group: Senior Member
Posts: 813
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Sep 2004
From: CyBerJaYa





QUOTE(eggy @ Mar 27 2006, 09:28 AM)
err..
ur AVG didn detect brontok?  sweat.gif
ur using the latest definition rite?  sweat.gif
*


avg just delete those infected files...
latest definition can detect it...

QUOTE(sUBs @ Mar 27 2006, 10:28 AM)
ANY & ALL versions of Brontok is welcomed.
Thanks
*


ic...may try my best to send it to u...
but what email address?

the brontok i have is too dangerous...my laptop got infected and no way to cure it...
even in safe mode, it will restart when it detect those AV name...
wen search in windows dir...cant even find the .exe that u guy mention...

This post has been edited by Hungry_Wolf: Mar 27 2006, 12:47 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 27 2006, 02:36 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #48


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(sUBs @ Mar 27 2006, 10:19 AM)
Anybody got any infector files for Brontok?

I'm trying to make a removal tool for it. I already have a beta unit but would like to test it further before release.

If you have any, please zip it up with WinZip/Rar & send it to submitals[at]yahoo.com

sUBs

*




QUOTE(Hungry_Wolf @ Mar 27 2006, 12:44 PM)
avg just delete those infected files...
latest definition can detect it...
ic...may try my best to send it to u...
but what email address?

the brontok i have is too dangerous...my laptop got infected and no way to cure it...
even in safe mode, it will restart when it detect those AV name...
wen search in windows dir...cant even find the .exe that u guy mention...
*


already mentioned there the email address...
submitals[at]yahoo.com sweat.gif

QUOTE(Hungry_Wolf @ Mar 27 2006, 12:44 PM)
avg just delete those infected files...
latest definition can detect it...
ic...may try my best to send it to u...
but what email address?

the brontok i have is too dangerous...my laptop got infected and no way to cure it...
even in safe mode, it will restart when it detect those AV name...
wen search in windows dir...cant even find the .exe that u guy mention...
*


have u restored ur system? unsure.gif

QUOTE(sUBs @ Mar 27 2006, 10:19 AM)
Anybody got any infector files for Brontok?

I'm trying to make a removal tool for it. I already have a beta unit but would like to test it further before release.

If you have any, please zip it up with WinZip/Rar & send it to submitals[at]yahoo.com

sUBs

*


i sent u a copy of brontok infected file..
did u receive it? unsure.gif

This post has been edited by sUBs: Mar 27 2006, 05:07 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Hungry_Wolf
post Mar 27 2006, 03:27 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #49


Enthusiast
*****

Group: Senior Member
Posts: 813
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Sep 2004
From: CyBerJaYa





QUOTE(eggy @ Mar 27 2006, 02:53 PM)
have u restored ur system?  unsure.gif
*


system restore is disabled.... sweat.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 27 2006, 03:31 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #50


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(Hungry_Wolf @ Mar 27 2006, 03:27 PM)
system restore is disabled.... sweat.gif
*


u dont have any restore point?? sweat.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Hungry_Wolf
post Mar 27 2006, 04:59 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #51


Enthusiast
*****

Group: Senior Member
Posts: 813
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Sep 2004
From: CyBerJaYa





QUOTE(eggy @ Mar 27 2006, 03:31 PM)
u dont have any restore point??  sweat.gif
*


yes...

so my solution:
transfer all the important file to another pc throught network...
using thumbdrive also can...
if u dare, unplug the infected hdd and and plug to your pc and run AV scan...
scan every file that transferred...
scan what ever file that transferred to ur pc...don open 1st...
reformat the pc...
don open any file from infected hdd while scanning...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Mar 27 2006, 05:19 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #52


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,932
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




QUOTE(eggy @ Mar 27 2006, 02:58 PM)
i sent u a copy of brontok infected file..
did u receive it?  unsure.gif
*


I checked my email & there was a 0kb rar attachment. Looks like a corrupted attachment sad.gif
If you don't mind, please use Winzip & assign a password -> 1234 - to it. This will prevent any scanners from corrupting it.

Thanks

Ps.. Does anybody else have any more samples? If so, kindly send them to submitals[at]yahoo.com

This post has been edited by sUBs: Mar 27 2006, 05:21 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 27 2006, 09:28 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #53


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(sUBs @ Mar 27 2006, 05:19 PM)
I checked my email & there was a 0kb rar attachment. Looks like a corrupted attachment  sad.gif
If you don't mind, please use Winzip &  assign a password -> 1234 - to it. This will prevent any scanners from corrupting it.

Thanks

Ps.. Does anybody else have any more samples? If so, kindly send them to submitals[at]yahoo.com
*


i`ll resend back tomorro... smile.gif

QUOTE(number8 @ Mar 27 2006, 06:07 PM)
whoa!! a lot of news and happening regarding this virus.... keep us all updated guys...
*


yeah..
the virus become smarter and smarter... sweat.gif
even MYCert received lots of reports on it... MyCert Special Alert
i tried the removal tool from sophos but it aint working... after i run the tool it will be shut down by the virus sweat.gif

This post has been edited by eggy: Mar 27 2006, 09:40 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
low yat 82
post Mar 28 2006, 12:35 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #54


X-Hardware Lover->X-Clubber->Swing Trader-> TNL Tech.
*******

Group: Senior Member
Posts: 2,805
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: tmn seri sentosa, off jln klang lama






QUOTE(sUBs @ Mar 27 2006, 05:19 PM)
I checked my email & there was a 0kb rar attachment. Looks like a corrupted attachment  sad.gif
If you don't mind, please use Winzip &  assign a password -> 1234 - to it. This will prevent any scanners from corrupting it.

Thanks

Ps.. Does anybody else have any more samples? If so, kindly send them to submitals[at]yahoo.com
*




okie.. will try my best...
but..this vworm is vry s***... coz evertime i plug my pendrive to my gf pc... it will infected my pendrive... rclxub.gif so fast.... vry scare..... blink.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Mar 28 2006, 12:41 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #55


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,932
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




QUOTE(low yat 82 @ Mar 28 2006, 12:35 AM)
okie.. will try my best...
but..this vworm is vry s***... coz evertime i plug my pendrive to my gf pc... it will infected my pendrive... rclxub.gif  so fast.... vry scare..... blink.gif
*



So far, I have received a few samples. Thanks to everyone who sent.
Unfortunately, everyone sent me txt files. Txt files aren't malicious. sad.gif

I'm looking for samples of executables .. with these file extensions - exe, dll, bat, com, cmd.

Preferbaly some of the following files...

\Local Settings\Application Data\csrss.exe
\Local Settings\Application Data\inetinfo.exe
\Local Settings\Application Data\lsass.exe
\Local Settings\Application Data\services.exe
\Local Settings\Application Data\smss.exe"
\Local Settings\Application Data\winlogon.exe
\Start Menu\Programs\Startup\Empty.pif
\Templates\Brengkolang.com
\Windows\eksplorasi.exe
\Windows\ShellNew\sempalong.exe
\Windows\ShellNew\ElnorB.exe
\Application Data\smss.exe
Kangen.exe

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 28 2006, 10:58 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #56


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(sUBs @ Mar 28 2006, 12:41 AM)
So far, I have received a few samples. Thanks to everyone who sent.
Unfortunately, everyone sent me txt files. Txt files aren't malicious.  sad.gif

I'm looking for samples of executables .. with these file extensions - exe, dll, bat, com, cmd.

Preferbaly some of the following files...

\Local Settings\Application Data\csrss.exe
\Local Settings\Application Data\inetinfo.exe
\Local Settings\Application Data\lsass.exe
\Local Settings\Application Data\services.exe
\Local Settings\Application Data\smss.exe"
\Local Settings\Application Data\winlogon.exe
\Start Menu\Programs\Startup\Empty.pif
\Templates\Brengkolang.com
\Windows\eksplorasi.exe
\Windows\ShellNew\sempalong.exe
\Windows\ShellNew\ElnorB.exe
\Application Data\smss.exe
Kangen.exe

*



i dont have those files but only the infected files...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
aaronlbs
post Mar 28 2006, 11:35 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #57


Getting Started
**

Group: Junior Member
Posts: 235
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jun 2005
From: Setapak





i sent Brontok infected file to this email address submitals[at]yahoo.com
hope this help
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 28 2006, 11:36 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #58


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






mr suBs..
i re-sent u the infected files..
hope it doesnt corrupt again...

btw.. when i try to send it with my gmail account it found virus attached to it.. sweat.gif
but when i send it with my yahoo account which has the NORTON ANTIVIRUS 2006 that will scan ur attachment didnt detect it..
wtf with NAV yeah?? vmad.gif

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
aaronlbs
post Mar 28 2006, 11:38 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #59


Getting Started
**

Group: Junior Member
Posts: 235
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jun 2005
From: Setapak





QUOTE(eggy @ Mar 28 2006, 11:36 AM)
mr suBs..
i re-sent u the infected files..
hope it doesnt corrupt again...

btw.. when i try to send it with my gmail account it found virus attached to it..  sweat.gif
but when i send it with my yahoo account which has the NORTON ANTIVIRUS 2006 that will scan ur attachment didnt detect it..
wtf with NAV yeah??  vmad.gif
*



maybe yahoo NAV not updated
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 28 2006, 11:52 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #60


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(aaronlbs @ Mar 28 2006, 11:38 AM)
maybe yahoo NAV not updated
*


i dunno..
but i dun think like tat since my attachment is not the latest brontok version sweat.gif

QUOTE(sUBs @ Mar 28 2006, 12:41 AM)
So far, I have received a few samples. Thanks to everyone who sent.
Unfortunately, everyone sent me txt files. Txt files aren't malicious.  sad.gif

I'm looking for samples of executables .. with these file extensions - exe, dll, bat, com, cmd.

Preferbaly some of the following files...

\Local Settings\Application Data\csrss.exe
\Local Settings\Application Data\inetinfo.exe
\Local Settings\Application Data\lsass.exe
\Local Settings\Application Data\services.exe
\Local Settings\Application Data\smss.exe"
\Local Settings\Application Data\winlogon.exe
\Start Menu\Programs\Startup\Empty.pif
\Templates\Brengkolang.com
\Windows\eksplorasi.exe
\Windows\ShellNew\sempalong.exe
\Windows\ShellNew\ElnorB.exe
\Application Data\smss.exe
Kangen.exe

*


all files u mentioned are there inside my attachment.. tongue.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

27 Pages < 1 2 3 4 5 > » 
Bump TopicReply to this topicTopic OptionsStart new topic
 



----debug section please ignore----
Lo-Fi Version Time is now: 25th November 2009 - 05:00 AM
All Rights Reserved 2003-2009 Vijandren Ramadass (~living on a prayer~)