![]() |
|
|||||||
| Anti-Virus - [Fixed] removing brontok.ee worm and vbs sasan posted in the Security & Safety forums; Running windowsXP SP2, I've had an infection with the worm brontok.ee and vbs sasan. I've run AVG free and NOD32 to clean up, but I still can't open the C: ... |
|
|
|
#1 |
|
Bronze Member
![]() Join Date: Feb 2006
Location: brighton uk
Posts: 15
|
Running windowsXP SP2, I've had an infection with the worm brontok.ee and vbs sasan. I've run AVG free and NOD32 to clean up, but I still can't open the C: drive with a double click - I get an error msg saying windows can't find .MS32DLL.dll.vbs (this was infected and thus quarantined by AVG, but can't be healed apparently), and folder options have been made unavailable (so I can't view hidden files and folders). The whole things going slow (I've run two spyware scanners on it too). Any one got any ideas? I'd be very grateful.
|
|
|
|
| Advertisement - Register to Remove | |
|
|
|
#2 |
|
Senior Security Analyst
![]() Join Date: Jun 2006
Location: Singapore
Posts: 5,176 PC Experience: PC Guru
|
Hello.
![]() Please download RegSupreme Pro: Macecraft Software - Download Windows Maintenance and Registry Cleaning utilities Run it. It will want to make a backup of your cache, let it. Click on the Registry Cleaner tab, and select Aggressive. When it has finished, click on Select, and choose All. Click on Fix, and let it fix everything that it finds. Next run Panda ActiveScan.
|
|
|
|
|
|
#3 |
|
Bronze Member
![]() Join Date: Feb 2006
Location: brighton uk
Posts: 15
|
Thanks for the speedy reply - installed the regsupreme and it found hundreds of old entries - all good so far, however panda active scan won't work on firefox, it says you must use IE, but I've uninstalled IE from my PC - any alternatives to suggest?
|
|
|
|
|
|
#4 |
|
Bronze Member
![]() Join Date: Feb 2006
Location: brighton uk
Posts: 15
|
Activescan.txt ok, ignore that last one, I put IE back on so here's the Panda log:
It seems to say that brontok is still in my pictures, but it's not appearing in the folder, even with hidden files and folders displayed. Thanks again |
|
|
|
|
|
#5 |
|
Senior Security Analyst
![]() Join Date: Jun 2006
Location: Singapore
Posts: 5,176 PC Experience: PC Guru
|
Download ATF Cleaner
Next: 1) Please download the Killbox. Save it to the desktop and run it. 2) Select "Delete on Reboot", and then select "All files". 3) Copy the file name below to the clipboard by highlighting it and pressing Control-C: C:\Documents and Settings\Chachy\My Documents\My Pictures\about.Brontok.A.html 4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard". 5) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. Note: Killbox may report that the file could not be found, since Panda ActiveScan had already disinfected it. Now, please restart the computer before running a new scan with Panda ActiveScan. |
|
|
|
|
|
#6 |
|
Bronze Member
![]() Join Date: Feb 2006
Location: brighton uk
Posts: 15
|
Did what you suggested with killbox etc. re-ran panda activescan, now everything's clean and smooth (just how we like 'em huh?)
Thanks for your help. |
|
|
|
|
|
#7 |
|
New Poster
Join Date: Apr 2007
Posts: 1
|
I´ve still problems. This is my report:
Incident Status Location Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Programme\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL Potentially unwanted tool:Application/MyWay Not disinfected C:\Programme\MyWay\myBar\1.bin\MYBAR.DLL Virus:W32/Brontok.C.worm Disinfected Operating system Can you help me? |
|
|
|
![]() |
| Bookmarks |
| Tags |
| brontokee, fixed, removing, sasan, vbs, worm |
«
Virus: won't allow me to stay on one site for more than 5 seconds.
|
[Answered]New PC, Will Need Protection
»
| Thread Tools | |
| Display Modes | |
|
|


























Linear Mode

