Win32.Brontok

Win32.Brontok

Secure Home | Search | About

Anti-Virus Software - Computer security - anti-virus software 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Win32.Brontok Heather 06-21-2009
---> Re: Win32.Brontok David H. Lipman06-21-2009
Posted by Heather on June 21, 2009, 1:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Got the following from a friend.......and she is not a novice. From
what I see on Google, this is either a rogue spyware or a real
virus.....can someone tell me which one??

She has 2 or 3 computers and I suggested she download MBAM and give it a
go.

Thoughts, anyone?? I haven't seen it mentioned on here.

Thanks...Heather
------------------------

Been having virus problems - got a pop up re: Win32.Brontok being
blocked by the firewall. Have run all the virus software, done a
clean, etc, and can't get the firewall popup about disabling this to
go away and stay away.

Any thoughts? Is the "firewall" popup actually the virus?



Posted by 1PW on June 21, 2009, 6:05 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Heather wrote:
> Got the following from a friend.......and she is not a novice. From
> what I see on Google, this is either a rogue spyware or a real
> virus.....can someone tell me which one??
>
> She has 2 or 3 computers and I suggested she download MBAM and give it a
> go.
>
> Thoughts, anyone?? I haven't seen it mentioned on here.
>
> Thanks...Heather
> ------------------------
>
> Been having virus problems - got a pop up re: Win32.Brontok being
> blocked by the firewall. Have run all the virus software, done a
> clean, etc, and can't get the firewall popup about disabling this to
> go away and stay away.
>
> Any thoughts? Is the "firewall" popup actually the virus?

Hello Heather:

Using MBAM /would/ be one of the first suggested actions. In addition
to MBAM, you may also wish to use SAS in the safe mode.

<http://www.superantispyware.com/index.html>

What is the complete version of the OS, and how was the malware
originally identified?

Please update this thread with your progress.

HTH

Pete
--
1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]

Posted by Heather on June 21, 2009, 2:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Heather wrote:
>> Got the following from a friend.......and she is not a novice. From
>> what I see on Google, this is either a rogue spyware or a real
>> virus.....can someone tell me which one??
>>
>> She has 2 or 3 computers and I suggested she download MBAM and give
>> it a
>> go.
>>
>> Thoughts, anyone?? I haven't seen it mentioned on here.
>>
>> Thanks...Heather
>> ------------------------
>>
>> Been having virus problems - got a pop up re: Win32.Brontok being
>> blocked by the firewall. Have run all the virus software, done a
>> clean, etc, and can't get the firewall popup about disabling this to
>> go away and stay away.
>>
>> Any thoughts? Is the "firewall" popup actually the virus?
>
> Hello Heather:
>
> Using MBAM /would/ be one of the first suggested actions. In addition
> to MBAM, you may also wish to use SAS in the safe mode.
>
> <http://www.superantispyware.com/index.html>
>
> What is the complete version of the OS, and how was the malware
> originally identified?

Hi Pete.......heard from her this morning but she is now away for the
day. I would assume XP and I also assume that she and her husband have
at least 4 computers which have their own servers and both of them are
IT people. (aka geeks, according to her, grin)

They ran a couple of a-v programs after I posted this and found some
other things, but not this one. See my reply to David for the warning
from the Firewall. And the fact that she doesn't run an active
antivirus because of the alleged protection from her servers.

Thanks.......Heather (Figgs)



Posted by David H. Lipman on June 21, 2009, 8:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Got the following from a friend.......and she is not a novice. From
| what I see on Google, this is either a rogue spyware or a real
| virus.....can someone tell me which one??

| She has 2 or 3 computers and I suggested she download MBAM and give it a
| go.

| Thoughts, anyone?? I haven't seen it mentioned on here.

| Thanks...Heather
| ------------------------

| Been having virus problems - got a pop up re: Win32.Brontok being
| blocked by the firewall. Have run all the virus software, done a
| clean, etc, and can't get the firewall popup about disabling this to
| go away and stay away.

| Any thoughts? Is the "firewall" popup actually the virus?


Hi Figgs:

This is worm that propogates throught email and net shares and can perform a DoS
on hard
coaded tragets.

As a worm it is trageted by anti virus software. I can't speak of MBAM and SAS
working on
it as they tend to traget trojans and not viruses and worms. Albeit they may
target some
worms.

You said your friend "Have run all the virus software..."
Plaese have her/him define WHAT anti virus software had been used.

Note that the McAfee and Sophos modules of my Multi AV should do well to remove
this
threat.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Heather on June 21, 2009, 1:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | Got the following from a friend.......and she is not a novice. From
> | what I see on Google, this is either a rogue spyware or a real
> | virus.....can someone tell me which one??
>
> | She has 2 or 3 computers and I suggested she download MBAM and give
> it a
> | go.
>
> | Thoughts, anyone?? I haven't seen it mentioned on here.
>
> | Thanks...Heather
> | ------------------------
>
> | Been having virus problems - got a pop up re: Win32.Brontok being
> | blocked by the firewall. Have run all the virus software, done a
> | clean, etc, and can't get the firewall popup about disabling this to
> | go away and stay away.
>
> | Any thoughts? Is the "firewall" popup actually the virus?
>
>
> Hi Figgs:
>
> This is worm that propogates throught email and net shares and can
> perform a DoS > on hard coaded tragets.
>
> As a worm it is trageted by anti virus software. I can't speak of
> MBAM and SAS working on it as they tend to traget trojans and not
> viruses and worms. Albeit they may target some worms.
>
> You said your friend "Have run all the virus software..."
> Plaese have her/him define WHAT anti virus software had been used.
>
> Note that the McAfee and Sophos modules of my Multi AV should do well
> to remove > this threat.

Thanks David. I heard from her early this morning and they have run a
couple more a-v programs, but she didn't name them. Both she and her
husband are IT professionals (how embarrassing) and she alone has 2
servers that she downloads her mail from. Unfortunately, because the
servers have virus and malware protection, she is not running an active
antivirus proggie.

She sent a pic of the warning and it is the "Security Centre Alert" box
naming the subject worm and asking her if she wants to block it and/or
download and run protection.

She is away for the day, but I will hear from her this evening. I sent
her your explanation and she will see that. I told her to d/l and run
MBAM and Superantispyware last night, so not sure if those are the
programs that her husband ran, along with antivirus ones.

I will get back to you once I know, but it was late last night when she
wrote me and I couldn't see what I considered "valid information" on
Google other than what I said. I assumed it was the rogue
program....wrong. But I hadn't noticed any mention of it on here or the
MS group.

Don't know if it is the worm or just server things I am not aware of,
but often our emails are held up for hours. Perhaps it is the latter.
I only proofread a couple of websites for her......she does the hard
stuff. (G)

Cheers....Figgs




Similar ThreadsPosted
Avast found a win32:Brontok[wrm] on my computer March 31, 2006, 3:49 pm
Brontok infects Windows Calculator? January 29, 2007, 5:47 pm
win32/i-worm/stration - E-mail-worm.win32.warezov or? October 13, 2007, 10:41 am
What is Win32.Clspring.BI May 27, 2005, 11:53 am
Win32 services July 10, 2005, 9:53 am
Win32.beovens January 1, 2006, 1:45 pm
Win32/Crypted - Help please January 31, 2006, 10:37 am
win32.small.ciw February 16, 2006, 6:41 pm
win32.oneraw.AS July 10, 2006, 1:41 am
Win32.Swen - Help? October 7, 2007, 8:15 am

The site map in XML format XML site map

Contact Us | Privacy Policy