Computing.Net > Forums > Security and Virus > Infected with the win32.brontok virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Infected with the win32.brontok virus

Reply to Message Icon

Name: lyric
Date: June 5, 2009 at 14:08:57 Pacific
OS: Microsoft Windows XP Professional
CPU/Ram: 1.828 GHz / 502 MB
Subcategory: Viruses
Comment:

Hi, the win32.brontok thing downloaded onto my computer and I closed the browser, only to find that I couldn't open it up again. When I opened it it would change the home page to a warning and it asked me to download security protection. Then a few seconds later it shut down. (I didn't click anything or download anything) AVG Free did not find anything, but Malwarebytes did and I have a log if you want me to post it.

Also, every few minutes a warning would pop up saying that Windows Firewall detected win32.brontok and it could not fix the problem but I could download something that did. (I didn't download it.)

Now it's been about 2 hours and I've just been doing scans, I can get online fine now for some reason, but I want to make sure this thing is gone.



Sponsored Link
Ads by Google

Response Number 1
Name: jdk (by neoark)
Date: June 5, 2009 at 14:21:11 Pacific
Reply:

Post malwarebtyes log.

-------------------------------------------------


0

Response Number 2
Name: lyric
Date: June 5, 2009 at 14:23:53 Pacific
Reply:

Malwarebytes' Anti-Malware 1.37
Database version: 2234
Windows 5.1.2600 Service Pack 2

6/5/2009 4:54:57 PM
mbam-log-2009-06-05 (16-54-57).txt

Scan type: Quick Scan
Objects scanned: 85831
Time elapsed: 12 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Documents and Settings\Rose H\Application Data\Google\Shell32.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nah_Shell (Trojan.Hanam) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\Rose H\application data\Google\Shell32.dll (Trojan.FakeAlert) -> Delete on reboot.
c:\documents and settings\Rose H\application data\Google\afuya1119762.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\Rose H\nah_itvd.exe (Trojan.Hanam) -> Quarantined and deleted successfully.


0

Response Number 3
Name: jdk (by neoark)
Date: June 5, 2009 at 14:34:58 Pacific
Reply:

1) Can you please post your AVZ log:
Note: Run AVZ in windows normal mode. If avz.exe doesn't start, then try to rename the file avz.exe to something else and try to run it again. Make sure you have your web browser open in background before following the steps below.

i) To create the logfile, download AVZ by clicking HERE. Please save this file to your desktop or "My Documents" folder.

ii) Next, unpack the file to a new folder using the Compressed (zipped) folders wizard built into Windows XP/Vista, or a zip utility of your choice.

iii) Once you have unpacked the contents of the zip archive, please launch the file AVZ.exe by double clicking on it or right clicking and selecting Open.
Note: If you are running Windows vista launch AVZ.exe by right clicking and selecting Run as Administrator.

You should now see the main window of the AVZ utility. Please navigate to File->Custom Scripts. Copy the script below by using the keyboard shortcut CTRL+C or the corresponding option via right click.

begin
ExecuteStdScr(3);
RebootWindows(true);
end.


Paste the script into the execution window by using CTRL+V keyboard shortcut, or the "paste" option via the right click menu. Click on Run to run the script, the PC will reboot. After the reboot the LOG subfolder is created in the folder with AVZ, with a file called virusinfo_syscure.zip inside. Upload that file to rapidshare.com and paste the link here.

Image Tutorial

2) Can you also make a new HijackThis log and upload it to rapidshare.com. HijackThis: Here

-------------------------------------------------


0

Response Number 4
Name: lyric
Date: June 6, 2009 at 07:22:53 Pacific

Response Number 5
Name: jdk (by neoark)
Date: June 6, 2009 at 08:18:04 Pacific
Reply:

Follow these Steps in order numbered. Don't proceed to next step unless you have sucessfully completed previous step:

1) Run this script in AVZ like before, your computer will reboot:

begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
 QuarantineFile('C:\Documents and Settings\Rose H\Application Data\Google\afuya1119762.exe','');
 DeleteFile('C:\Documents and Settings\Rose H\Application Data\Google\afuya1119762.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

2) After Reboot. Attach a Combofix log, please review and follow these instructions carefully.

Download it here -> http://download.bleepingcomputer.co...

Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows and pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) until after the scanning and removal process has taken place.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please upload that file to rapidshare.com and paste the link here.

-------------------------------------------------


0

Related Posts

See More



Response Number 6
Name: lyric
Date: June 6, 2009 at 08:49:04 Pacific

Response Number 7
Name: jdk (by neoark)
Date: June 6, 2009 at 09:03:24 Pacific
Reply:

Follow these Steps in order numbered. Don't proceed to next step unless you have sucessfully completed previous step:

1) Run this script in AVZ. Your computer will reboot.

begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('c:\documents and settings\Rose H\Application Data\BearShare\kern.dll','');
DeleteFile('c:\documents and settings\Rose H\Application Data\BearShare\kern.dll');
QuarantineFile('c:\documents and settings\Rose H\Application Data\acccore\shalom.exe','');
DeleteFile('c:\documents and settings\Rose H\Application Data\acccore\shalom.exe');
QuarantineFile('c:\documents and settings\Rose H\Application Data\Azureus\msgdi.dll','');
DeleteFile('c:\documents and settings\Rose H\Application Data\Azureus\msgdi.dll');
QuarantineFile('c:\documents and settings\Rose H\Application Data\Adobe\rengo.dll','');
DeleteFile('c:\documents and settings\Rose H\Application Data\Adobe\rengo.dll');
QuarantineFile('c:\documents and settings\Rose H\Application Data\Apple Computer\nomad.exe','');
DeleteFile('c:\documents and settings\Rose H\Application Data\Apple Computer\nomad.exe');
QuarantineFile('c:\documents and settings\Rose H\Application Data\ArcSoft\lego.exe','');
DeleteFile('c:\documents and settings\Rose H\Application Data\ArcSoft\lego.exe');
QuarantineFile('c:\documents and settings\Rose H\Application Data\Amazon\socks1.exe','');
DeleteFile('c:\documents and settings\Rose H\Application Data\Amazon\socks1.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

2) After reboot. Run this script in AVZ:

begin
CreateQurantineArchive('c:\quarantine.zip');
end.

2) A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\quarantine and upload both it and C:\quarantine.zip to a filehost such as http://rapidshare.com/ Then, Private Message me the Download link to the uploaded file.

3) Lastly, uninstall Combofix by: pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) > Start > run > type combofix /u > ok. Or Start > run > type 123 /u > ok.

-------------------------------------------------


0

Response Number 8
Name: lyric
Date: June 6, 2009 at 19:29:58 Pacific
Reply:

Ok, PM sent.


0

Response Number 9
Name: jdk (by neoark)
Date: June 6, 2009 at 19:46:15 Pacific
Reply:

PS: Seems like you have caught something rare.

Thanks for the files. Please follow these steps in order numbered and post summary log after each step.

1) If you use Windows System restore, turn it off > reboot. How to turn it off/on: http://support.kaspersky.com/faq/?q... Run a full scan with:

Download and run Kaspersky AVP tool: http://devbuilds.kaspersky-labs.com...
Once you download and start the tool:

# Check below options:

    * Select all the objects/places to be scanned. 
    * Settings > Customize > Heuristic analyzer > Enable deep rootkit search

# Click Scan
# Fix what it detects
# Attach Scan log/Summary to your next message.

Illustrated tutorial: http://img32.imageshack.us/img32/76...

2) Run a full scan with http://www.eset.eu/online-scanner

# Check the box next to YES, I accept the Terms of Use.
# Click Start
# When asked, allow the activex control to be installed.
# Click Start
# Check below options:

    * Remove found threats
    * Scan archives
    * Scan for potentially unwanted applications (Advance Settings).
    * Enable Anti-Stealth technology (Advance Settings).

# Click Scan
# Wait for the scan to finish
# When it finishes it will create a log file here: C:\Program Files\EsetOnlineScanner\log.txt
# Attach this logfile to your next message.

Illustrated Tutorial: http://img155.imageshack.us/img155/...

Note: Turn system restore back on, if you wish; this to remove malware from system volume information files.

3) Scan with SuperAntispyware : http://www.superantispyware.com/dow... . Fix what it detects and post summary scan log.

-------------------------------------------------


0

Response Number 10
Name: lyric
Date: June 7, 2009 at 21:26:34 Pacific
Reply:

Okay, Kaspersky did not find any threats, but ESET did, here's the link to the log:
http://rapidshare.com/files/2421103...

I'll do the superantispyware scan when I wake up and I'll post it in another reply.


0

Response Number 11
Name: jdk (by neoark)
Date: June 8, 2009 at 05:39:58 Pacific
Reply:

Seems your malware free just run the last scan and post results.

-------------------------------------------------


0

Response Number 12
Name: lyric
Date: June 10, 2009 at 20:18:24 Pacific
Reply:

I did the Quick scan and fixed the problems, here's the log.
http://rapidshare.com/files/2432120...
Should I have done the Complete scan instead? I can still do that if it would help.


0

Response Number 13
Name: jdk (by neoark)
Date: June 10, 2009 at 20:25:07 Pacific
Reply:

Is your original problem fixed? You malware free just some adware lying around.

If I'm helping you and I don't reply within 24 hours send me a PM.


0

Response Number 14
Name: lyric
Date: June 12, 2009 at 07:52:01 Pacific
Reply:

Yes, the original problem is fixed. I do however think I have a new virus which I will post in a separate thread.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Infected with the win32.brontok virus

Infected with the b.exe virus!!!! www.computing.net/answers/security/infected-with-the-bexe-virus/26832.html

Win32.nimda virus removal? www.computing.net/answers/security/win32nimda-virus-removal/4301.html

Infected with Trojan.Win32.Agent2.g www.computing.net/answers/security/infected-with-trojanwin32agent2g/25363.html