Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Anyone know how to get rid of this?
Found a file on root C: called
7668-NendangBro, googled that and foundhttp://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RONTOKBR.AC&VSect=T
First step is to reboot in safe mode and run the reg fix, I am rebooting in safe mode and the virus is still active?! Not letting me run the fix!
Help me!!!

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.
Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

thanks for your responses
but this worm/virus does not let any .exes etc run at all, both hjsetup.exe and msconfig will restart the computer automatically even in safe mode.

Go to this file association fix site . http://dougknox.com/xp/file_assoc.htm
Click ".reg" first>in the save-in box choose "desktop" then click save. Open the .zip file and drag it to your desktop>open it >click merge. Do the same for the ".exe fix". Then try the registry edit.

this did the trick
http://securityresponse.symantec.com/avcenter/venc/data/tool.to.reset.shellopencommand.registry.keys.html

![]() |
Recovery and Malware Clea...
|
AIM myspace virus
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |