Guide Version 1.3
1.1 What is bro_act.exe?
Bro_act.exe is either virus or trojan that collects your information and will transfer it to a server.
It is currently undetectable by any anti-virus software on press time...
1.2 How do I get infected?
basically, it will spread through thumb drive and through LAN.
1.3 How do I know either I get infected? (check through thumb drive.)
right click your thumb drive in My Computer and if you see bolded "Auto", do not click it. Instead you click explore.
Go to tools->folder options. Click view and check advanced settings.
Click "show hidden files and folders" and untick "hide protected operating system files. (Recommended)". You might see a warning window but just leave it. Click ok.
If you were to see a filename called bro_act.exe, that is the excutables that will affect your PC when you double click your thumb drive or right click and click the bolded "auto".
1.4 How do I know either I get infected? (check through PC)
Go to tools->folder options. Click view and check advanced settings.
Click "show hidden files and folders" and untick "hide protected operating system files. (Recommended)". You might see a warning window but just leave it. Click ok.
Go to your local hard disk eg. c:
Go to WINDOWS\system32\(your PC's name)\
look for system.exe
if it's there, means your PC is infected.
1.5 How do I clean the virus? (infected thumb drive)
Make sure--> Go to tools->folder options. Click view and check advanced settings.
Click "show hidden files and folders" and untick "hide protected operating system files. (Recommended)". You might see a warning window but just leave it. Click ok.
1. start Windows Task Manager, click process.
2. Look for bro_act.exe and end the process.
3. Now right click your thumb drive and click explore.
4. Find these filenames, bro_act.exe, autorun.inf
5. Shift + Delete and delete the file.
6. Now... Go to tools->folder options. Click view and check advanced settings. Untick "hide extensions for known file types". Click ok.
7. Click Search, "All files and folders", put a word or phrase in the file "exe", Change the what file is it criteria to "less than 1 mb", change more advanced option criteria to search for system folders and search hidden files and folders.
8. Click search.
9. Delete every single "exe" that contains the name exactly like your folder. and delete the similar icon exe.
10. Now your thumb drive is clean.
1.6 How do I clean the virus? (infected PC)
Make sure--> Go to tools->folder options. Click view and check advanced settings.
Click "show hidden files and folders" and untick "hide protected operating system files. (Recommended)". You might see a warning window but just leave it. Click ok.
1. download this file: http://download.sysinternals.com/Files/Autoruns.zip
2. unzip it and open autoruns.exe
3. Click logon and wait it loads finish.
4. look for this filename, bro_act.exe
5. untick it and restart your PC in safe mode. Hold F8 when you reboot again to access boot menu. click safe mode.
6. Login and look for c:\Windows\system32\bro_act.exe
7. delete the file. and look for c:\Windows\system32\(Your PC's name)\system.exe
8. Delete that file also.
9. Remember to disable and re-enable your System Restore.
10. Delete everything in the Recycle Bin too.
1.7 Why do I scan with any anti-virus and get no results?
This virus is undetectable by anti-virus and it's new virus which had not been in Anti-Virus softwares "Virus Encyclopedias".
1.8 How did you get the solution?
I think and think for 1 whole day for solution.
I used to detect antivermins as fraud anti-virus software.
1.9 Why would you want to create this guide?
As usual, I am one of the victims.
All credits goes to me as I am the person who create this guide.
Automated guide: RM10 per license. Consider ok lo...
The webmaster of this site told me his capability of his software.
He asked me to link to his website...
http://www.kaer-media.org/penawar-brontok
Version Update:
Version 1.1
Guide set up.
Version 1.2
Updated branch 1.5
Version 1.3
Added branch 1.8
Regards,
HeHeHunter
Note: I do not warranty this guide is up-to-date as the creator of the virus might get smarter by changing in and out of the virus.
Note: Dear ami_kidz125 from cari.com.my, please link http://forum.cari.com.my/viewthread.php?ti...&extra=page%3D1 here...
This post has been edited by HeHeHunter: Mar 2 2007, 04:45 PM
V1.3 - Bro_act.exe, Another nightmare for me...
Jan 29 2007, 08:19 PM, updated 19y ago
Quote
0.0166sec
0.74
5 queries
GZIP Disabled