PDA

View Full Version : Win32.Brontok is killing my computer



antvillan
2009-06-06, 00:16
Hi,
I'm hoping someone can help me. I was browsing the web as usual and my computer just rebooted itself.
When it loaded back up Windows Firewall advised me it was blocking a virus win32.Brontok. Everytime I now try to go onto the internet I get an Insecure Internet message. When I try to download the windows virus solution it explorer just vanishes. I go back in and try and browse unsecurely and explorer also vanishes then. Basically anything I can't use teh internet at all as it just vanishes.

I've looked on the using a different computer in the house (as I'm using now) and found out a bit about the virus. It is usually spread via email, but I did not get this via email. I was lucky enough after many attempts to quickly log onto the sophos website an try their win32.Brontok removal software which has done nothing. I attemped to go into safe mode, however now my keyboard is no longer abled.

I then started to have problems shutting down anything I opened, even my documents, so I tried loading any old thing to see if it was happening with everything and quicktime opened an advised me a buffer overrun had corrupted the program.

So basically I can't access the internet, or any exe files by the look of it and my keyboard is not working. As I moved countries a few times int he last few years I no longer have any of the original discs so I can't even restore the computer. Although my mate did say he had an XP disc, will that work? Is there anyway I can salvage my computer? I'd be loath to lose all my programmes, music and movies and a particularly good game of football manager!

I'm fairly clueless when it comes to computers also.

pskelley
2009-06-07, 14:57
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance) http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

You must have read and followed the "Before you Post" instructions.
To tell you the truth, it does not look good, expecially since you don't have the important CD's that come with the computer. I will see what I can do but can make no promises.

1) Make sure you read and the directions first.

2) On the clean computer see if you can post a HijackThis log, this self-installer is the easiest.


Note: If you have lost your Internet connection on the infected computer, or otherwise cannot post from that machine; you can download HJT to a clean PC if you have one.

Do not use a usb/external hard drive that has been connected to the infected machine to transfer media!

You can also try this if malware is blocking your access to security forums and tools. Then,

Upload HJT to infected machine
Place HJT into own folder
Run HJT on the infected PC and post the log you produce using the clean PC.

Download Trend Micro Hijack This™ to your Desktop
http://download.bleepingcomputer.com/hijackthis/HJTInstall.exe
Doubleclick the HJTInstall.exe to start it.
By default it will install HijackThis in the Program Files\Trendmicro folder and create a desktop shortcut.
HijackThis will open after install. Press the Scan button below.
This will start the scan and open a log.
Copy and paste the contents of the log in your next reply.

It might be the infection looks for .exe's from malware programs, so try changing the name to:
antvillan.exe when you save it on the Desktop.

pskelley
2009-06-13, 13:58
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.