Lowyat.NET Forums

Welcome Guest ( Log In | Register )

LYN wins Intel-Lenovo-Tangs Blogathon challenge. Thank you everybody!
27 Pages « < 3 4 5 6 7 > »  
RSS feedBump TopicReply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> W32.Rontokbro Worm, updated : removal tools

eggy
post Mar 31 2006, 09:49 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #81


Question authority; but, raise your hand 1st
******

Group: Senior Member
Posts: 1,733
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Kajang | Shah Alam Mood: Confused -_-"






QUOTE(low yat 82 @ Mar 31 2006, 09:39 PM)
can i use antivirus program in a pendivre to scan? i mean i extract it to pendrive..
*


u have antivirus program in ur pendrive?
kinda confused what ur trying to say here sweat.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Mar 31 2006, 10:00 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #82


Watashiwa Watashini Nareta
*******

Group: Senior Member
Posts: 8,310
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(eggy @ Mar 31 2006, 10:37 PM)
haha  tongue.gif
its gud to try something new  thumbup.gif
*


Yeah... SYMANTEC cooperate edition... My friend BT it back lolx... laugh.gif

QUOTE(low yat 82 @ Mar 31 2006, 10:39 PM)
can i use antivirus program in a pendivre to scan? i mean i extract it to pendrive..
*


Dun understand... Try to rephrase it... wink.gif

QUOTE(eggy @ Mar 31 2006, 10:49 PM)
u have antivirus program in ur pendrive?
kinda confused what ur trying to say here  sweat.gif
*


Lolx... whistling.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lokgotz
post Mar 31 2006, 10:02 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #83


hehehe
*******

Group: Senior Member
Posts: 2,428
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: In front of my computer





i used symantec corporate edition 10.0, norton 2006, AVG7.1, panda.....everything....

still cant detect.....an cant delete....

haih.....i backuped my data, formated my hdd....then the hdd which i backup my data got smell when plugged into my computer.....it was working fine this afternoon.....

haihh.....die liow this time....i have 35GB of data inside......pure data....no mp3, no video.....
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Mar 31 2006, 10:05 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #84


Watashiwa Watashini Nareta
*******

Group: Senior Member
Posts: 8,310
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(lokgotz @ Mar 31 2006, 11:02 PM)
i used symantec corporate edition 10.0, norton 2006, AVG7.1, panda.....everything....

still cant detect.....an cant delete....

haih.....i backuped my data, formated my hdd....then the hdd which i backup my data got smell when plugged into my computer.....it was working fine this afternoon.....

haihh.....die liow this time....i have 35GB of data inside......pure data....no mp3, no video.....
*


SWT! Mine can wor...
Try reboot safe mode n scan. Hav u update def?
U can also find approx 45kb files to delete... icon_rolleyes.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ryan7
post Mar 31 2006, 10:14 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #85


Newbie
*

Group: Junior Member
Posts: 29
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Penang






got this virus 4 days ago (W32.Rontokbro@mm) my NAV 2006 able to detect it but unable to clean it, i go to symantec site to search for this virus and follow the step by step guide to clean it, and it works, lucky for me i guess wink.gif

try running the .exe virus file and plant the virus on my laptop with AVG installed, and AVG does a better job than NVA 2006, AVG can delete it rclxms.gif

This post has been edited by ryan7: Mar 31 2006, 10:15 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lokgotz
post Mar 31 2006, 11:52 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #86


hehehe
*******

Group: Senior Member
Posts: 2,428
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: In front of my computer





mine was updated.....

reboot in safemode also cannot scan.....

coz the virus is active in safe mode also....

now my computer formatted....brand new liow....

but my data all hilang......coz the hdd i backup burnt already........30gb of data hilang........

this is just not my day......
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
PCcrazy
post Apr 1 2006, 03:08 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #87


Milanista
*******

Group: Senior Member
Posts: 3,224
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: B.B.Bangi






QUOTE(lokgotz @ Mar 31 2006, 11:52 PM)
mine was updated.....

reboot in safemode also cannot scan.....

coz the virus is active in safe mode also....

now my computer formatted....brand new liow....

but my data all hilang......coz the hdd i backup burnt already........30gb of data hilang........

this is just not my day......
*



You shoud try using Live CD to remove the viruses. Trinity live CD or Linux live CD should be good. Or perhaps BartPE live CD.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
low yat 82
post Apr 1 2006, 04:27 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #88


X-Hardware Lover->X-Clubber->Swing Trader-> TNL Tech.
*******

Group: Senior Member
Posts: 2,805
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: tmn seri sentosa, off jln klang lama






QUOTE(eggy @ Mar 31 2006, 09:49 PM)
u have antivirus program in ur pendrive?
kinda confused what ur trying to say here  sweat.gif
*




wat im tryin to say is i instal an antivirus software into d pendirve and ask it to scan d hdd... can or not this way? can it delete it? or i need to follow d script u type?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sam85
post Apr 1 2006, 06:25 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #89


Getting Started
**

Group: Junior Member
Posts: 286
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Nov 2005
From: Kepong






I have some suggestion here... to avoid from activating the virus, with terms ur pc haven't kena yet.

Usually this virus spread via pen drive, PC user mistakely activate the virus by clicking d folder which is a APPLICATION file type, having same name as created previously (trackable if u check it with PROPERTIES).

Although maybe u plug and play the pen drive in ur OS, once u never click d APPLICATION file(virus), it wun affect ur OS, since it never neen activated.
In this case, if ur PC doesn't deffected, d VIRUS folder in thumd drive is deletable, vice if ur OS kena, deled files will appear again.

So to ensure u wun mistakely click d application file which is BRONTOK and activate it, install a ICON PACKAGER.
After install a ICON PACKAGER, u will see d different things.
EX: if ur folder's icon change to a blue color 1 by using ICON PACKAGER, u will discover SAME FOLDER WITH SAME NAME INSIDE THAT FOLDER, BUT WITH ORIGINAL YELLOW WINDOW FOLDER ICON.
Delete it, cause 100 % is BRONTOK.

That works in my PC, thats how i prevent BRONTOK hacking into my PC.

Secondly, i hv some opinion y some times same virus in pen drive is scanable and some r not.
From my experience, if d BRONTOk in a pen drive had been activated, it is scannable and removable.
Vice, mayb u k see it and know it is a BRONTOK, but no results after scanning. in this case, remove it manually, by using DELETE, then it wun appear again.

So, pls give me some feedback, wheter this is useable to prevent.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ryan7
post Apr 1 2006, 08:23 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #90


Newbie
*

Group: Junior Member
Posts: 29
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Feb 2006
From: Penang






QUOTE(sam85 @ Apr 1 2006, 06:25 PM)
I have some suggestion here... to avoid from activating the virus, with terms ur pc haven't kena yet.

Usually this virus spread via pen drive, PC user mistakely activate the virus by clicking d folder which is a APPLICATION file type, having same name as created previously (trackable if u check it with PROPERTIES).

Although maybe u plug and play the pen drive in ur OS, once u never click d APPLICATION file(virus), it wun affect ur OS, since it never neen activated.
In this case, if ur PC doesn't deffected, d VIRUS folder in thumd drive is deletable, vice if ur OS kena, deled files will appear again.

So to ensure u wun mistakely click d application file which is BRONTOK and activate it, install a ICON PACKAGER.
After install a ICON PACKAGER, u will see d different things.
EX: if ur folder's icon change to a blue color 1 by using ICON PACKAGER, u will discover SAME FOLDER WITH SAME NAME INSIDE THAT FOLDER, BUT WITH ORIGINAL YELLOW WINDOW FOLDER ICON.
Delete it, cause 100 % is BRONTOK.

That works in my PC, thats how i prevent BRONTOK hacking into my PC.

Secondly, i hv some opinion y some times same virus in pen drive is scanable and some r not.
From my experience, if d BRONTOk in a pen drive had been activated, it is scannable and removable.
Vice, mayb u k see it and know it is a BRONTOK, but no results after scanning. in this case, remove it manually, by using DELETE, then it wun appear again.

So, pls give me some feedback, wheter this is useable to prevent.
*


thumbup.gif i guess u are right, any expert to clarify
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
2uk3y
post Apr 1 2006, 08:32 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #91


\,,/(^_^)\,,/
******

Group: Senior Member
Posts: 1,948
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Oct 2005
From: 2°18' | 102°23'





for me no problem since i always scan thumbdrive or disket b4 open it using Bitdefender....
i set to clean and then delete files if infected...... biggrin.gif

but at my office some pc already infected.....so what i do is reformat it n install deep freez software to protect it..... thumbup.gif
so far still repairing the Rontokbro pc ...... rclxub.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
NeophyteHeaven
post Apr 1 2006, 09:11 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #92


UnseenEyes
******

Group: Senior Member
Posts: 1,021
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: Kuching, Sarawak






icon_rolleyes.gif im using Bit Defender 9 Pro here, the virus easyly removed using this..just keep your AV updated sure safe

btw, ya guys can try using this 1st...useable for me removing my office pc before..

http://www.saberkas.net/downloads/20051201...tox_cleaner.exe

cheers
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lokgotz
post Apr 1 2006, 09:57 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #93


hehehe
*******

Group: Senior Member
Posts: 2,428
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: In front of my computer





i identified a thumb drive with the virus.......

so i scanned it using all the AV i mentioned above.......

but none of them worked.....all said that there where no viruses.......and i ended up with 30gb lost files.........
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Apr 1 2006, 11:10 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #94


Watashiwa Watashini Nareta
*******

Group: Senior Member
Posts: 8,310
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(lokgotz @ Apr 1 2006, 10:57 PM)
i identified a thumb drive with the virus.......

so i scanned it using all the AV i mentioned above.......

but none of them worked.....all said that there where no viruses.......and i ended up with 30gb lost files.........
*


This is not ur day... laugh.gif
Other forumers can detect the RONTOKBRO virus...
Well, at least now ur PC is clean rite??
Install deep freeze software lor... icon_rolleyes.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
lokgotz
post Apr 2 2006, 04:26 AM
Show posts by this member only |This post's rating (0+, 0-) | Post #95


hehehe
*******

Group: Senior Member
Posts: 2,428
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: In front of my computer





yeah....my pc is VERY clean now....

too clean in fact....heheh....
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mr.Q
post Apr 2 2006, 12:23 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #96


Getting Started
**

Group: Junior Member
Posts: 131
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Mar 2006





the simple method is go to this site http://jeruk.padinet.com/~ertanto/bw.php and download brontok washer. it is a zip file. unzip the file and run brontok washer. if you cannot run the file.. that means you got a big brontok virus problem.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Apr 2 2006, 09:07 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #97


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,932
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




QUOTE(mr.Q @ Apr 2 2006, 12:23 PM)
the simple method is go to this site http://jeruk.padinet.com/~ertanto/bw.php and download brontok washer.
*



QUOTE(NeophyteHeaven)
can try using this 1st...useable for me removing my office pc before..
http://www.saberkas.net/downloads/20051201...tox_cleaner.exe
cheers


Both of the above tools use pre-defined filenames/paths & registry entries. They are for the older 80KB variant of Brontok which are much easier to remove. Brontox Cleaner does not do a complete job & leaves files & autorun entries which may trigger a re-infection.

None of them will work for the 43KB variant.
This variant of Brontok will autoclose both these applications the moment you try to use them. You can identify the 43KB variant by the presence of this file in the root of drive C - Baca Bro !!!.txt

Does anyone have the 45KB variant? I need a sample.

This post has been edited by sUBs: Apr 2 2006, 09:11 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
low yat 82
post Apr 2 2006, 09:29 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #98


X-Hardware Lover->X-Clubber->Swing Trader-> TNL Tech.
*******

Group: Senior Member
Posts: 2,805
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Aug 2005
From: tmn seri sentosa, off jln klang lama






QUOTE(sUBs @ Apr 2 2006, 09:07 PM)
QUOTE(NeophyteHeaven)
can try using this 1st...useable for me removing my office pc before..
http://www.saberkas.net/downloads/20051201...tox_cleaner.exe
cheers


Both of the above tools use pre-defined filenames/paths & registry entries. They are for the older 80KB variant of Brontok which are much easier to remove. Brontox Cleaner does not do a complete job & leaves files & autorun entries which may trigger a re-infection.

None of them will work for the 43KB variant.
This variant of Brontok will autoclose both these applications the moment you try to use them. You can identify the 43KB variant by the presence of this file in the root of drive C - Baca Bro !!!.txt

Does anyone have the 45KB variant? I need a sample.
*



my gf pc is infected wit brontok.c will it able to repair it?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
vX-2
post Apr 2 2006, 09:35 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #99


Immortality of Beauty
******

Group: Senior Member
Posts: 1,123
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2003
From: KL






Hmm... i dont know if I should says this publicly........ nearly all (Inti College Subang Jaya) lab PC, is infected with brontok (and its variant)... sweat.gif kuidos to them...

This post has been edited by vX-2: Apr 2 2006, 09:35 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
sUBs
post Apr 2 2006, 10:48 PM
Show posts by this member only |This post's rating (0+, 0-) | Post #100


RIP
Group Icon
Retired Tech Support mod

Group: VIP
Posts: 3,932
Ratings earned: 0+, 0-
Ratings given: 0+, 0-

Joined: Jan 2005




QUOTE(low yat 82)
my gf pc is infected wit brontok.c will it able to repair it?

My tool was built using infected files from the Brontok.C[22] variant. It should be able to deal with your infection.

QUOTE
nearly all (Inti College Subang Jaya) lab PC, is infected with brontok (and its variant).

You should get the admin to try my tool on ONE of the machines first. If he's satisfied with it, he can use it on ALL the other machines.

I would still like for you guys to continue sending me samples of infected files so that I may update the tool to be more comprehensive. The email addy is - subsmitals[at]yahoo.com
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

27 Pages « < 3 4 5 6 7 > » 
Bump TopicReply to this topicTopic OptionsStart new topic
 



----debug section please ignore----
Lo-Fi Version Time is now: 24th November 2009 - 09:28 AM
All Rights Reserved 2003-2009 Vijandren Ramadass (~living on a prayer~)