We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Help removing win32 brontok- im stuck.

Hi all,
opened up my desktop pc on saturday to find a windows security message advising me that my pc was infected with win32 brontok virus and to click on the link to remove it.
I have had a variant of this before so i knew not to click on it. Last time i used super-antispyware which removed it however this time it would not find it and remove it. Second try i used Norton which again didnt find it.
By this time the virus was shutting down the internet window every 20 seconds or so.
I managed to download malware bytes and tried this but i kept getting a pop up to inform me that 'administrator' would not let it install correctly which i read is a trait of this particular virus.
Tried to do system restore but it wont let me do this either. Tried in safe mode but again it wont let me get on certain security sites like Kapersky.
Im at my wits end with this thing now and short of getting a hammer out im at a loss.
Has anyone experienced this virus and if so how did they get rid of it.
As a footnote i run norton all the time and it still bypassed it.

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Nortons still not very good no matter what others may claim

    anyways ~
    Bring up TASK MANAGER and attempt to identify the dodgy .exe file and "end process"
    Rename the malwarebytes.exe to something else (eg - mjsabfjkefg.exe), RIGHT click and atempt to install as admin

    Failing that reboot and keep pressing F8 to get into SAFE MODE WITH NETWORKING
    Try malwarebytes from there (Post the log here if you do get it running)
    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    reboot into NORMAL mode
    Click DO A SCAN AND SAVE A LOGFILE (Takes seconds) then post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    :idea:
  • Strider590
    Strider590 Posts: 11,874 Forumite
    edited 1 June 2009 at 8:05AM
    Look for the removal tool, here's a quick find.

    http://www.bitdefender.com/VIRUS-157247-en--Win32.Brontok.A@mm.html

    That's some 2005 version of the virus, I doubt yours is the same.

    If its that one you could go in and pick those files out, nothing should be running from those directories.
    “I may not agree with you, but I will defend to the death your right to make an a** of yourself.”

    <><><><><><><><><<><><><><><><><><><><><><> Don't forget to like and subscribe \/ \/ \/
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    When its gone I would also suggest using FIREFOX with the NOSCRIPT plugin. Had you done so then you wouldnt have gotten infected
    :idea:
  • dearboy289
    dearboy289 Posts: 30 Forumite
    Thanks all will give those a try.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.8K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.2K Spending & Discounts
  • 246.8K Work, Benefits & Business
  • 603.3K Mortgages, Homes & Bills
  • 178.2K Life & Family
  • 260.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.