PDA

View Full Version : Help with supposed Win32:Brontok-CE infection



Ploink
2011-11-08, 06:57
Hi all,

I do not currently have SSD (or HJT) installed (though I have previously considered using them). I am currently using Avast! AV. Pardon the absence of a DDS log. I needed some advice on a supposed Win32:Brontok infection that I have.

Avast popped up with a "Virus Detected" message yesterday, and moved a lot of suspicious .exe files (.../$FOLDER$/"$FOLDER$ .exe") to its quarantine region, saying that the infection was Win32:Brontok-CE [Wrm]. The threats were apparently "detected and blocked when the file was created or modified". I am not experiencing any unusual behaviour (apart from the creation of the .exe's), and am able to access my registry, view hidden/system files etc.. I also ran a full system scan, which turned up no infected files, but today, Avast again popped up with ~40 threats detected in .exe files.

Since I have not experienced any symptoms at all (and from what I've googled up, I gather that Brontok is normally quite debilitating), and because I am rather wary/weary of installing additional AV tools, I have not run any of the Brontok searches/removers out there. Can anyone advise me on how to proceed here?

Blade81
2011-11-11, 10:35
Hi,

Download DDS and save it to your desktop from here (http://download.bleepingcomputer.com/sUBs/dds.com) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds file to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.

Blade81
2011-11-17, 06:49
Due to inactivity, this thread will now be closed.

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.