Avast found a win32:Brontok[wrm] on my computer

Avast found a win32:Brontok[wrm] on my computer

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Avast found a win32:Brontok[wrm] on my computer casioculture 03-31-2006
Posted by on March 31, 2006, 3:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


I found it on an SD card that I used a couple of weeks ago to test a
camera in a store. I took pictures with it and brought the SD card
back. Strangely, I looked at the pictures back then and had no problem.
Now that I looked at the SD card again I clicked on some folder on it
and it seems to have ran something that avast/prevx/kerio didn't like.
I don't exactly remember what was going on in detail, I was literally a
"moron in a hurry" trying to get this cheap mp3 player to work to
listen to an podcast. Anyhow, I allowed it to do one thing and then
blocked the rest when I noticed that it wasn't normal (prevx does get
frustrating in normal usage, so I acquired a habit of allowing without
much thinking unless I'm on guard). I then ran avast, it said reboot, I
rebooted, it ran on reboot and moved 9 files to its virus chest.

Any permanent harm done? Should I reinstall windows? Thanks.


Posted by David H. Lipman on March 31, 2006, 5:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

|
| I found it on an SD card that I used a couple of weeks ago to test a
| camera in a store. I took pictures with it and brought the SD card
| back. Strangely, I looked at the pictures back then and had no problem.
| Now that I looked at the SD card again I clicked on some folder on it
| and it seems to have ran something that avast/prevx/kerio didn't like.
| I don't exactly remember what was going on in detail, I was literally a
| "moron in a hurry" trying to get this cheap mp3 player to work to
| listen to an podcast. Anyhow, I allowed it to do one thing and then
| blocked the rest when I noticed that it wasn't normal (prevx does get
| frustrating in normal usage, so I acquired a habit of allowing without
| much thinking unless I'm on guard). I then ran avast, it said reboot, I
| rebooted, it ran on reboot and moved 9 files to its virus chest.
|
| Any permanent harm done? Should I reinstall windows? Thanks.

OK, so Avast found a worm (?) on a SD card. The question is, in what form was
it and what
was done with it ?
Was it an EXE file ?
Was it deleted ?
Was it quarantined ?
Was it executed ?
Have you scanned your computer to see if the computer OS was infected ?

The following can be used to see if the system was infected
* * * NOTE: You should disable Avast if you run the Trend module in the below
tool as it
falsely declares the Trend Micro Sysclean utility as being infected with the
VBS/RedLof.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://harrisonrj.home.comcast.net/step_by_step_pc_cleaning_process.htm#Step_3_%96_Getting_Help


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on March 31, 2006, 6:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

David H. Lipman wrote:

>
> |
> | I found it on an SD card that I used a couple of weeks ago to test a
> | camera in a store. I took pictures with it and brought the SD card
> | back. Strangely, I looked at the pictures back then and had no problem.
> | Now that I looked at the SD card again I clicked on some folder on it
> | and it seems to have ran something that avast/prevx/kerio didn't like.
> | I don't exactly remember what was going on in detail, I was literally a
> | "moron in a hurry" trying to get this cheap mp3 player to work to
> | listen to an podcast. Anyhow, I allowed it to do one thing and then
> | blocked the rest when I noticed that it wasn't normal (prevx does get
> | frustrating in normal usage, so I acquired a habit of allowing without
> | much thinking unless I'm on guard). I then ran avast, it said reboot, I
> | rebooted, it ran on reboot and moved 9 files to its virus chest.
> |
> | Any permanent harm done? Should I reinstall windows? Thanks.
>
> OK, so Avast found a worm (?) on a SD card. The question is, in what form was
it and what
> was done with it ?
> Was it an EXE file ?
> Was it deleted ?
> Was it quarantined ?
> Was it executed ?
> Have you scanned your computer to see if the computer OS was infected ?

Hi, sorry I havne't been clear.

The files on the card looked either like a folder or an archive file in
thumnail view. I clicked on it and it ran an exe. prevx alarmed me but
because I was messing with a new mp3/card reader thing that wasn't
working well I allowed it once or twice, then suspected things weren't
right after a second or two, so I denied further attempts to modify.

Wait, I just had a look at the virus chest. Okay, it seems the virus
had used the names of the folders and made them EXEs.
http://i2.tinypic.com/somgxi.jpg

See those top three? Those used to be folders on the SD card. Each
folder stood for a camera and contained the pictures from that camera.
Like I said, I took this card to a camera store and used it there in
cameras I was testing before I buy one.

I don't remember if Avast alarmed me about the files or not, but it
didn't while they were active. If it did it sure took its time and I
was dealing with prevx and kerio popping up first. I then ran it
afterwards and it told me that there was a virus in memory and it was
better to reboot and do a boot-time-scan. So I did that. I told it to
move everything to its virus chest (that's a quarantine I think) rather
than delete.

I'm running another Avast scan now and it's not showing up anything
new.

Do you suggest I don't use any passwords until I'd reinstalled the OS?

Thanks.





>
> The following can be used to see if the system was infected
> * * * NOTE: You should disable Avast if you run the Trend module in the below
tool as it
> falsely declares the Trend Micro Sysclean utility as being infected with the
VBS/RedLof.
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot
the PC.
>
> You can choose to go to each menu item and just download the needed files or
you can
> download the files and perform a scan in Normal Mode. Once you have downloaded
the files
> needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to
run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file. http://www.ik-cs.com/multi-av.htm
>
> Additional Instructions:
>
http://harrisonrj.home.comcast.net/step_by_step_pc_cleaning_process.htm#Step_3_%96_Getting_Help
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm


Posted by David H. Lipman on March 31, 2006, 7:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

|
| David H. Lipman wrote:
|
>>
|>> I found it on an SD card that I used a couple of weeks ago to test a
|>> camera in a store. I took pictures with it and brought the SD card
|>> back. Strangely, I looked at the pictures back then and had no problem.
|>> Now that I looked at the SD card again I clicked on some folder on it
|>> and it seems to have ran something that avast/prevx/kerio didn't like.
|>> I don't exactly remember what was going on in detail, I was literally a
|>> "moron in a hurry" trying to get this cheap mp3 player to work to
|>> listen to an podcast. Anyhow, I allowed it to do one thing and then
|>> blocked the rest when I noticed that it wasn't normal (prevx does get
|>> frustrating in normal usage, so I acquired a habit of allowing without
|>> much thinking unless I'm on guard). I then ran avast, it said reboot, I
|>> rebooted, it ran on reboot and moved 9 files to its virus chest.
|>>
|>> Any permanent harm done? Should I reinstall windows? Thanks.
>>
>> OK, so Avast found a worm (?) on a SD card. The question is, in what form
was it and
>> what was done with it ? Was it an EXE file ? Was it deleted ? Was it
quarantined ? Was it
>> executed ? Have you scanned your computer to see if the computer OS was
infected ?
|
| Hi, sorry I havne't been clear.
|
| The files on the card looked either like a folder or an archive file in
| thumnail view. I clicked on it and it ran an exe. prevx alarmed me but
| because I was messing with a new mp3/card reader thing that wasn't
| working well I allowed it once or twice, then suspected things weren't
| right after a second or two, so I denied further attempts to modify.
|
| Wait, I just had a look at the virus chest. Okay, it seems the virus
| had used the names of the folders and made them EXEs.
| http://i2.tinypic.com/somgxi.jpg
|
| See those top three? Those used to be folders on the SD card. Each
| folder stood for a camera and contained the pictures from that camera.
| Like I said, I took this card to a camera store and used it there in
| cameras I was testing before I buy one.
|
| I don't remember if Avast alarmed me about the files or not, but it
| didn't while they were active. If it did it sure took its time and I
| was dealing with prevx and kerio popping up first. I then ran it
| afterwards and it told me that there was a virus in memory and it was
| better to reboot and do a boot-time-scan. So I did that. I told it to
| move everything to its virus chest (that's a quarantine I think) rather
| than delete.
|
| I'm running another Avast scan now and it's not showing up anything
| new.
|
| Do you suggest I don't use any passwords until I'd reinstalled the OS?
|
| Thanks.
|

At this point I don't think you need to reinstall the OS.

Scan with Avast and scan with the Multi AV Scanning Tool using the McAfee,
Sophos and/or
Trend module.

So far it looks like Avast protected you. The additional scans will affirm or
deny that.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by * * Chas on April 1, 2006, 3:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
<snip>
> Any permanent harm done? Should I reinstall windows? Thanks.
>

Reinstalling ANYTHING is the LAST recourse when ALL else fails.

Reinstalling is what unskilled, overworked, underpaid "tech support"
people recommend just to get you off of the phone!

You did the right thing by seeking help in this NG. People like David
Lippman are very knowledgeable and can usually walk you through a
problem.

Good luck,

Chas.



Similar ThreadsPosted
NYB-F virus found on a XP2 computer won't harm anything. Is this right? I have spent all day ... November 7, 2007, 4:40 pm
Avast antivirus has taken control of my computer! June 4, 2008, 7:15 am
Pinging all the experts here -->Zone Alarm anti-spyware just found 2 trojans that Avast/Ad-Aware/Spybot S&D didn't August 1, 2006, 4:30 pm
win32/i-worm/stration - E-mail-worm.win32.warezov or? October 13, 2007, 10:41 am
Warning! Spyware detected on your computer? Install an antivirus or spyware remover to clean your computer. Bugs crawling on desktop June 4, 2008, 2:59 pm
What is Win32.Clspring.BI May 27, 2005, 11:53 am
Win32 services July 10, 2005, 9:53 am
Win32.beovens January 1, 2006, 1:45 pm
Win32/Crypted - Help please January 31, 2006, 10:37 am
win32.small.ciw February 16, 2006, 6:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy