Lowyat.NET Forums

Welcome Guest ( Log In | Register )

LYN wins Intel-Lenovo-Tangs Blogathon challenge. Thank you everybody!
27 Pages « < 2 3 4 5 6 > »  
RSS feedBump TopicReply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> W32.Rontokbro Worm, updated : removal tools

Kamling
post Mar 28 2006, 12:03 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #61


Not KambinG
****

Group: Senior Member
Posts: 629
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2006
From: Somewhere On Selangor






yes maybe yahoo NAV 2005 S its no detect the virus that old skool ma...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 28 2006, 12:08 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #62


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(Kamling @ Mar 28 2006, 12:03 PM)
yes maybe yahoo NAV 2005 S its no detect the virus that old skool ma...
*


as i stated i was NAV 2006 not 2005 sweat.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Xonius
post Mar 28 2006, 02:13 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #63


BS Meter 100%
******

Group: Senior Member
Posts: 1,008
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005
From: AYAM KAMBING!!!!






this virus is really FARK, FARK MAN, i couldnt even open the folder options or initiate any anti-virus programs, GOD BLESS Windows System Restore.

i wonder how i got this virus, can anyone tell me how? izit just when ppl click on an .exe application then it happens?

EDIT: oh yea, the biggest question, how do i prevent this shit from ever happening again? using AVG free antivirus is good enough?

This post has been edited by sUBs: Mar 28 2006, 04:21 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 28 2006, 04:23 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #64


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(Xonius @ Mar 28 2006, 02:13 PM)
this virus is really FARK, FARK MAN, i couldnt even open the folder options or initiate any anti-virus programs, GOD BLESS Windows System Restore.

i wonder how i got this virus, can anyone tell me how? izit just when ppl click on an .exe application then it happens?

fark the indons man, seriously, causing me headache.

EDIT: oh yea, the biggest question, how do i prevent this shit from ever happening again? using AVG free antivirus is good enough?
*


yeah...
if u got a infected pendrive and plug to ur pc and click the *.exe files..
ur pc are most capable to get infected...
but if u copied the infected files into ur hdd and leave it alone u wont get infected...
BUT depends on the brontok version itself.. the latest version of it will jst get itself freely into ur system at the same time when u plug in ur pendrive eventho u didn browse ur pendrive sweat.gif
which really pain in d A**!! mad.gif
rite now with the latest virus updates i think AVG can detect the virus and secure ur pc... thumbup.gif

This post has been edited by eggy: Mar 28 2006, 04:27 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mr.Q
post Mar 28 2006, 05:28 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #65


Getting Started
**

Group: Junior Member
Posts: 131
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Mar 2006





the latest the virus type that you get.. the smartest the virus will be. it will try to block everything that is need to clean it, install an executable file that run on startup, and hide itself in certain folder. usually it spread through usb drive. install avg antivirus and its updates and scan all the usb drive that is connected to your computer.

but if already infected.. the first thing to do is run hijackthis to delete all things that is related to antivirus software name with connection to localhost 127.0.*.* which is the virus command to block your access to your antivirus and your antivirus website.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 28 2006, 05:31 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #66


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(mr.Q @ Mar 28 2006, 05:28 PM)
the latest the virus type that you get.. the smartest the virus will be. it will try to block everything that is need to clean it, install an executable file that run on startup, and hide itself in certain folder. usually it spread through usb drive. install avg antivirus and its updates and scan all the usb drive that is connected to your computer.

but if already infected.. the first thing to do is run hijackthis to delete all things that is related to antivirus software name with connection to localhost 127.0.*.* which is the virus command to block your access to your antivirus and your antivirus website.
*


if only u can run hijackthis tool sweat.gif
i think if u run hijackthis after few secs sure it automatically shutdown.. sweat.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
fuchai
post Mar 28 2006, 10:43 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #67


Newbie
*

Group: Junior Member
Posts: 11
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Mar 2006




QUOTE(eggy @ Mar 28 2006, 05:31 PM)
if only u can run hijackthis tool  sweat.gif
i think if u run hijackthis after few secs sure it automatically shutdown..  sweat.gif
*



ya.. it will automatic shutdown all the antivirus program.. any new solution about this?? my fren pc(in same LAN) is inflicted by an unknown virus, it will automatic shutdown it browser or sth else , it is it call brontok?? my com is inflict by i-worm-bronktok.n , just use AVG delected 3000+ of the trojan. restart pc it come back again. any solution for this both virus?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
theng_ye
post Mar 29 2006, 12:13 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #68


Getting Started
**

Group: Junior Member
Posts: 229
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2005
From: son of melak@ but nw in KL..





if i plug in a pendrive tat hv this virus into my pc n scan it, will it detected??
o the virus attack my pc at the 1st moment i plug it to the pc??

walau...my gf hp oso kena d...
kong ar....
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lykuan82
post Mar 29 2006, 06:41 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #69


Newbie
*

Group: Junior Member
Posts: 32
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jul 2005
From: Kuching/Penang





my pc get affected in feb, i google out some solution but seem difficult to work out, then i try system restore & it work! now, my fren pc get affected (through pen drive) and he try to install a new anti virus to remove it, on the half way of installation, the system shut down itself. The worst thing is now the pc can boot anymore even in safe mode. any suggestion? thanks
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mr.Q
post Mar 30 2006, 01:43 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #70


Getting Started
**

Group: Junior Member
Posts: 131
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Mar 2006





i have read articles at http://www.vaksin.com/ where thay said that there are many varians of Rontokbro but it is devided into 3 generation.

first generation of Rontokbro has size around 80KB atau more. these can easily be clean because it only active at "Normal mode" but it will already start blocking to certain windows function of registry editor, msconfig, task manager and folder options. the good news is it doesn't block other useful tools software such as HijackThis, ProceeXp or Pocket Killbox. the virus will duplicate into file in every folder and subfolder where it has the same name with the folder or subfolder with the extention .EXE. then it will try to establish Ddos connection attack to certain website. it also can update itself through internet by downloading virus from the spesific site that it has determine.

the second generation has size around 42KB or more. at this level, it has the ability to be active in safe mode and start blocking the useful tools of HijackThis, ProceeXp and Pocket Killbox. it has the same ability as the previous generation with addtional action of adding a command on file HOST [C:\Windows\System32\Driver\ETC] to block access to antivirus websites.

the third generation has size around 45KB or more. it has the same ability of all the previous generation with additional ability to active even safe mode and safe mode with command prompt.

if you are infected with the second generation where you starting to cannot use HijackThis, ProceeXp and Pocket Killbox tools and entering safe mode, you need to do these steps.

a. Restart computer and enter "safe mode with command prompt", by pressing button key [F8] while the computer restart.

b. When you have enter into "Command Prompt" mode press button key [CTRL] + [ALT] + [Del] altogether. next, choose [Task Manager]. when the Task Manager appear, click menu [File] choose [New Task (Run..)], then type [explorer] at [create new task file] window. after that, click enter.

c. then the desktop appear (by means that you have enter into "safe mode" mode)

d. write this script below and save in notepad with the name repair.inf, and run the file by right click [repair.inf] choose [install]). this is to activate registry editor function, enable [folder option] and delete the string that has been created by the virus.


[Version]
Signature="$Chicago$"
Provider=Vaksincom

[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del

[UnhookRegKey]
HKLM, SOFTWARE\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, SOFTWARE\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"

[del]
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System,DisableCMD
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer,NoFolderOptions
HKCU, Software\Microsoft\Windows\CurrentVersion\Run,Tok-Cirrhatus
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run,Bron-Spizaetus


e. run msconfig, go to tab [startup] and delete option [Smss], [Empty] and [Sempalong]

f. restart the computer and follow instruction a. and b. again in order to make the "Folder option" in windows explorer appear.

g. go into folder options, tab [view], advanced settings.. choose [show hidden files and folders]

h. delete file at

- C:\Windows\, with the name eksplorasi.exe (hidden)
- C:\Windows\shellnew\, with the name sempalong.exe(hidden)
- C:\Windows\system32\, with the name %username"s Setting.scr (hidden)
- C:\Windows\pss\, with the file name [Empty.pifStartup]
- C:\Documents and Settings\%user%\Local Settings\Application Data\, with file name
01. Bron.tok-[x]-[y], where [X] and [Y] shows number
02. Loc.Mail.Bron.Tok
03. Ok-SendMail-Bron-tok
04. csrss.exe
05. inetinfo.exe
06. Kosong.Bron.Tok.txt
07. lsass.exe
08. NetMailTmp.bin
09. services.exe
10. smss.exe
11. Update.3.Bron.Tok.bin
12. winlogon.exe
13. smss.exe

i. Edit file autoexec.bat in directoty C:\ and delete command line [pause]

j. delete scheduled tasks that has been made by Rontokbro (click [Start], [Settings], [Control Panel], double click menu [scheduled tasks].

k. delete files that has been made by the virus by using search function.
- click [Start]
- click [Search], click [For Files or Folders]
- choose [All files or Folders]
- click option [What size is it ?]
- choose option [Specify Size (in Kb)]
- in combo box, choose [At most] fill file size [43], click [Search]
- delete all icon folder that has extention .EXE (application) that are 42KB in sized

l. restart your computer. install anti-virus with updates such as avg antivirus and scan all drive in your computer.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
loki
post Mar 30 2006, 01:50 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #71


Enthusiast
*****

Group: Senior Member
Posts: 951
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: Damansara Damai, PJ






Just go look for Hiren's BOOT CD 7.7 and create a boot cd. boot up with this cd and scan your system with the option to delete infected files...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 30 2006, 09:18 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #72


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(fuchai @ Mar 28 2006, 10:43 PM)
ya.. it will automatic shutdown all the antivirus program.. any new solution about this?? my fren pc(in same LAN) is inflicted by an unknown virus, it will automatic shutdown it browser or sth else , it is it call brontok?? my com is inflict by i-worm-bronktok.n , just use AVG delected 3000+ of the trojan. restart pc it come back again. any solution for this both virus?
*


AVG rules weh thumbup.gif
norton???!! whistling.gif

QUOTE(theng_ye @ Mar 29 2006, 12:13 AM)
if i plug in a pendrive tat hv this virus into my pc n scan it, will it detected??
o the virus attack my pc at the 1st moment i plug it to the pc??
*


depends on ur antivirus software...
if it can detect the virus so u dont need to worry bout to get infected biggrin.gif
jst plug it in and if theres any brontok it sure tells you... thumbup.gif

QUOTE(theng_ye @ Mar 29 2006, 01:44 AM)
walau...my gf hp oso kena d...
kong ar....
*


whoaah..
this is my first time i heard brontok infected hs... ohmy.gif

QUOTE(mr.Q @ Mar 30 2006, 01:43 AM)
i have read articles at http://www.vaksin.com/ where thay said that there are many varians of Rontokbro
*



nice infos..
thanx fo sharing... biggrin.gif
btw the script is same as mine thumbup.gif

QUOTE(loki @ Mar 30 2006, 01:50 AM)
Just go look for Hiren's BOOT CD 7.7 and create a boot cd. boot up with this cd and scan your system with the option to delete infected files...
*


maybe u can share with us where can we find it...
have u tried it before and is it working? smile.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lokgotz
post Mar 31 2006, 11:44 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #73


hehehe
*******

Group: Senior Member
Posts: 2,428
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: In front of my computer





My computer also kena this virus.....

and i tried to use Mr. Q's method of removing it but cannot also...

when i boot in safemode with command prompt....the virus is also active there as well...

i tried burn my data out and wanna format but cannot burn coz nero said cannot find the path for the file that i am burning....but the files are there....

i have a lot of stuff in my computer.....

my norton 2005 is up to date but y still cannot detect and delete arr???

now cannot even startup norton.

please help...

thanks...

any one can help???

AVG and norton can seem to detect the virus......

coz i tried scanning the infected thumbdrive....
User is online!Profile CardPM
Go to the top of the page
+Quote Post
Xonius
post Mar 31 2006, 02:14 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #74


BS Meter 100%
******

Group: Senior Member
Posts: 1,008
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005
From: AYAM KAMBING!!!!






QUOTE(lokgotz @ Mar 31 2006, 02:05 PM)
any one can help???

AVG and norton can seem to detect the virus......

coz i tried scanning the infected thumbdrive....
*



the easiest way is to go to safe mode and activate system restore, and restore your system to the date that your pc wasnt infected yet. It worked like a charm for me. To actually remove it manually takes quite alot of tasks which are daunting. shakehead.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lokgotz
post Mar 31 2006, 02:48 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #75


hehehe
*******

Group: Senior Member
Posts: 2,428
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: In front of my computer





i disabled system restore......so i can't restore back.....
User is online!Profile CardPM
Go to the top of the page
+Quote Post
bin_hustler
post Mar 31 2006, 06:25 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #76


Newbie
*

Group: Junior Member
Posts: 10
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Dec 2005
From: ipoh






aiyark....cannot kill process maaa....
when run ProcessExplorer.exe also cant...this prog will automatically close...
anyone help...any idea...

cry.gif cry.gif cry.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 31 2006, 08:49 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #77


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






sry fo d late reply..being bz lately sweat.gif


QUOTE(lokgotz @ Mar 31 2006, 02:48 PM)
i disabled system restore......so i can't restore back.....
*


hav u tried it before?
my friend who disabled the system restore have no problem with restoring back his system...

QUOTE(bin_hustler @ Mar 31 2006, 06:25 PM)
aiyark....cannot kill process maaa....
when run ProcessExplorer.exe also cant...this prog will automatically close...
anyone help...any idea...

cry.gif  cry.gif  cry.gif
*


the best method rite now is restoring ur pc using any restoring points available...

QUOTE(lokgotz @ Mar 31 2006, 02:05 PM)
any one can help???

AVG and norton can seem to detect the virus......

coz i tried scanning the infected thumbdrive....
*


ur AVG is up 2 date is it? unsure.gif
coz mine can detect it just fine... biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Mar 31 2006, 09:33 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #78


Watashiwa Watashini Nareta
*******

Group: Senior Member
Posts: 8,309
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: Lurking In The Forum Status: 1+3+3=7





If really cannot, DL the symantec cooperate edition!
I say symantec! not norton. Then update it.
No sweat, last time I let my friend scan my HDD with it, after 1 day[coz late @ night tat time], it removed all the viruses, but still need some minor tweaking in the folder option and the startup loading sux virus... doh.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eggy
post Mar 31 2006, 09:37 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #79


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(eXPeri3nc3 @ Mar 31 2006, 09:33 PM)
If really cannot, DL the symantec cooperate edition!
I say symantec! not norton. Then update it.
No sweat, last time I let my friend scan my HDD with it, after 1 day[coz late @ night tat time], it removed all the viruses, but still need some minor tweaking in the folder option and the startup loading sux virus... doh.gif
*


haha tongue.gif
its gud to try something new thumbup.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
low yat 82
post Mar 31 2006, 09:39 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #80


X-Hardware Lover->X-Clubber->Swing Trader-> TNL Tech.
*******

Group: Senior Member
Posts: 2,805
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: tmn seri sentosa, off jln klang lama






can i use antivirus program in a pendivre to scan? i mean i extract it to pendrive..

User is offlineProfile CardPM
Go to the top of the page
+Quote Post

27 Pages « < 2 3 4 5 6 > » 
Bump TopicReply to this topicTopic OptionsStart new topic
 



----debug section please ignore----
Lo-Fi Version Time is now: 22nd November 2009 - 09:07 PM
All Rights Reserved 2003-2009 Vijandren Ramadass (~living on a prayer~)