Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » Anti-Virus
Register for a Free Account

Anti-Virus - [Fixed] removing brontok.ee worm and vbs sasan posted in the Security & Safety forums; Running windowsXP SP2, I've had an infection with the worm brontok.ee and vbs sasan. I've run AVG free and NOD32 to clean up, but I still can't open the C: ...


Reply
Free PC Performance Scan
Old 03-05-2007   #1
Bronze Member
 
Join Date: Feb 2006
Location: brighton uk
Posts: 15
Default [Fixed] removing brontok.ee worm and vbs sasan

Running windowsXP SP2, I've had an infection with the worm brontok.ee and vbs sasan. I've run AVG free and NOD32 to clean up, but I still can't open the C: drive with a double click - I get an error msg saying windows can't find .MS32DLL.dll.vbs (this was infected and thus quarantined by AVG, but can't be healed apparently), and folder options have been made unavailable (so I can't view hidden files and folders). The whole things going slow (I've run two spyware scanners on it too). Any one got any ideas? I'd be very grateful.
modernape is offline   Reply With Quote
Advertisement - Register to Remove

Old 03-05-2007   #2
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default

Hello.

Please download RegSupreme Pro:
Macecraft Software - Download Windows Maintenance and Registry Cleaning utilities

Run it. It will want to make a backup of your cache, let it. Click on the Registry Cleaner tab, and select Aggressive. When it has finished, click on Select, and choose All. Click on Fix, and let it fix everything that it finds.


Next run Panda ActiveScan.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Attach the ActiveScan report in your next reply.
chiaz is offline   Reply With Quote
Old 03-11-2007   #3
Bronze Member
 
Join Date: Feb 2006
Location: brighton uk
Posts: 15
Default panda scan only on IE

Thanks for the speedy reply - installed the regsupreme and it found hundreds of old entries - all good so far, however panda active scan won't work on firefox, it says you must use IE, but I've uninstalled IE from my PC - any alternatives to suggest?
modernape is offline   Reply With Quote
Old 03-11-2007   #4
Bronze Member
 
Join Date: Feb 2006
Location: brighton uk
Posts: 15
Default active scan log

Activescan.txt ok, ignore that last one, I put IE back on so here's the Panda log:

It seems to say that brontok is still in my pictures, but it's not appearing in the folder, even with hidden files and folders displayed.

Thanks again
modernape is offline   Reply With Quote
Old 03-12-2007   #5
Senior Security Analyst
 
chiaz's Avatar
 
Join Date: Jun 2006
Location: Singapore
Posts: 5,176
PC Experience: PC Guru
Default

Download ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


Next:
1) Please download the Killbox.
Save it to the desktop and run it.

2) Select "Delete on Reboot", and then select "All files".

3) Copy the file name below to the clipboard by highlighting it and pressing Control-C:
C:\Documents and Settings\Chachy\My Documents\My Pictures\about.Brontok.A.html

4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

5) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.


Note: Killbox may report that the file could not be found, since Panda ActiveScan had already disinfected it.



Now, please restart the computer before running a new scan with Panda ActiveScan.
chiaz is offline   Reply With Quote
Old 03-24-2007   #6
Bronze Member
 
Join Date: Feb 2006
Location: brighton uk
Posts: 15
Default Thanks, that fixed it

Did what you suggested with killbox etc. re-ran panda activescan, now everything's clean and smooth (just how we like 'em huh?)

Thanks for your help.
modernape is offline   Reply With Quote
Old 04-24-2007   #7
New Poster
 
Join Date: Apr 2007
Posts: 1
Default

I´ve still problems. This is my report:


Incident Status Location

Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Programme\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
Potentially unwanted tool:Application/MyWay Not disinfected C:\Programme\MyWay\myBar\1.bin\MYBAR.DLL
Virus:W32/Brontok.C.worm Disinfected Operating system

Can you help me?
Maki is offline   Reply With Quote

Reply

Bookmarks

Tags
brontokee, fixed, removing, sasan, vbs, worm

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 12:39 PM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2