Computing.Net > Forums > Security and Virus > Rontokbr worm?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Rontokbr worm?

Reply to Message Icon

Name: nachos
Date: June 26, 2006 at 18:30:17 Pacific
OS: xp
CPU/Ram: 512
Comment:

Anyone know how to get rid of this?
Found a file on root C: called
7668-NendangBro, googled that and found

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RONTOKBR.AC&VSect=T

First step is to reboot in safe mode and run the reg fix, I am rebooting in safe mode and the virus is still active?! Not letting me run the fix!

Help me!!!



Sponsored Link
Ads by Google

Response Number 1
Name: don2006
Date: June 26, 2006 at 18:45:44 Pacific
Reply:

Look at my answer to Sylvia's post. AIM Myspace.


0

Response Number 2
Name: jabuck
Date: June 26, 2006 at 18:58:37 Pacific
Reply:

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.

Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.


0

Response Number 3
Name: nachos
Date: June 26, 2006 at 19:04:49 Pacific
Reply:

thanks for your responses
but this worm/virus does not let any .exes etc run at all, both hjsetup.exe and msconfig will restart the computer automatically even in safe mode.


0

Response Number 4
Name: jabuck
Date: June 26, 2006 at 19:32:07 Pacific
Reply:

Go to this file association fix site . http://dougknox.com/xp/file_assoc.htm

Click ".reg" first>in the save-in box choose "desktop" then click save. Open the .zip file and drag it to your desktop>open it >click merge. Do the same for the ".exe fix". Then try the registry edit.


0

Response Number 5
Name: nachos
Date: June 29, 2006 at 19:00:05 Pacific
Reply:

this did the trick
http://securityresponse.symantec.com/avcenter/venc/data/tool.to.reset.shellopencommand.registry.keys.html


0

Related Posts

See More



Response Number 6
Name: jabuck
Date: June 29, 2006 at 20:11:16 Pacific
Reply:

Thanks for the excellent info.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Recovery and Malware Clea... AIM myspace virus



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Rontokbr worm?

New Bagle Worm www.computing.net/answers/security/new-bagle-worm/13525.html

Worm/KLEZ.E.....What the......? www.computing.net/answers/security/wormklezewhat-the/2025.html

Klez, worm, trojan, backdoor trojan www.computing.net/answers/security/klez-worm-trojan-backdoor-trojan/3809.html