Brontok worm & windows desktop not working

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jab0lo, Feb 10, 2010.

  1. Jab0lo

    Jab0lo Private E-2

    Hi,
    I'm having some serious problem with my laptop and i'm using someone'sw else's laptop to send this message now. Would be very grateful if someone could help.. So here goes:
    It started when i noticed some duplicate NewFolder.exe files in nearly all of my folders. But the machine still worked albeit slower than normal, until 4days earlier.
    Everything starts as normal until after I logon to windows(Windows starting logo etc..). Then my screen is blank, although i can move the mouse.
    I found that by doing CTRL ALT DEL and running taskmanager and then do File->Run any one of the many files that the worm created (eg My documents.exe), my desktop appeared again and i had access to windows as usual.
    I wanted to get rid of the worm and installed Avast antivirus(yes i didn't have one in the first place, i know not smart at all). It did a lengthy scan and found about 5000 files created by Brontok. I also ran a BitDefender program that apparently didnt do anything. I decided to stop the antivirus scan and restart the PC as i thought the files were being re-created whilst they were being deleted by Avast.
    Now i'm back to square one, worse i can't do the 'trick' above to access windows as the Brontok files i used to run from taskmanager don't exist anymore. So here i am using someone else's laptop.
    I also read your 'how to' manual before posting questions related to malware - unfortunaltely i cannot do anything other than the CTL ALT DEL and then run a program from there (that's also very limited).
    Thanks in advance for your help.
    Ja.
    Can anyone help please?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to get into task manager and start a new process by typing in explorer.exe

    If you get your desktop back, then using a different computer, transfer our tools to your machine.

    You can always use task manager to run any programs you have installed. You can also use it to install programs from either a thumb drive or the cd drive.

    Tell me what you can do and not do.

    We need as many logs as you can get.
     
  3. Jab0lo

    Jab0lo Private E-2

    Hi,
    Thx for the reply. Since I last posted this, I ran avast on task mgr and now the pc is clean. I can even obtain my desktop back when i run explorer.exe on task mgr.
    I still have 2 problems though:

    1. I dont get my desktop directly on starting up the pc.
    2. I get the following msg each time I start it up, even though I guess the problems are related:
    c:/Users/Me/AppData/Roaming/ulvpj.dll
    The specified module cannot be found.

    Can you hlp me plz? Did i delete anything important while cleaning up my pc?
    thx for ur help.
    Ja
     
    Last edited: Feb 12, 2010
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. Jab0lo

    Jab0lo Private E-2

    Hi,
    i couldn't figure out what to do after i followed ur step by step guide n still had the same problem caused like u said probably by the remnants of the brontok thing. So i just reset it to factory settings (Pressing a specific key, mine:f11, during startup) - I got my laptop running as smoothly as when i first got it :D
    Which made me think - why don't ppl just do this? provided they have the option or the DVD, and have backed up their information already? it's so simple and u've got a 'new' machine afterall.... is there any drawback in resetting ur laptop?
    In any case, i followed the guide again n got 1 AV, 1 spyware and the CCleaner as prescribed. Plus i update everything whenever i'm prompted to.
    Thanks again for ur help, u're doing a great job, specially for free! :)
    J.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some can't access their cd drive, some don't have a recovery option, some don't want to loose data and personal settings. Some are so infected that they can't do anything. Just depends. :)

    Good to hear your reset was easy. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds