Read & Run Me First/ Read but unable to run

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Arnoldgenes, Sep 6, 2008.

  1. Arnoldgenes

    Arnoldgenes Private E-2

    Ok guys this isnt your regular "run of the mill" type of problem, Im an experienced user who fixes the averge users computers as a side job. That being said I am running Vista Home and picked up a trojan of some kind while retrieving a torrent; more specifically Lock Folder 9.0.
    This trojan unlike any Ive seen before. Safe mode will run and show the desktop for about a minute or so and then abrubtly shut itself down. So this is the time frame im allowed in safe mode...thus you see my problem. Ive tried a few other tricks with no avail. I can get the command prompt up but rstrui.exe wont execute...any suggestions guys? I really dont want to fresh install.
     
  2. Arnoldgenes

    Arnoldgenes Private E-2

  3. Arnoldgenes

    Arnoldgenes Private E-2

    Solution

    Ive found a solution and I would like to pass it on to others that may be reading and having the same problem. With tenacious research ive come to believe that I have contracted a Brontok virus (root-kit). Since the rootkit crippled the OS kernel and took it over, restarting when in safe mode, disabling msconfig etc. there is no other option but to use another OS or a BootCD to scan and clean the drive. Knoppix Linux and UBCD4Win or even Hiren's BootCD are invaluble tools for this case. A quick seach with the afforementioned names should bring up some mirrors for you, so thanks for the help?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Thanks for letting us know what you have discovered.

    There are quite a few forms of Brontok around. There are also a few removal tools too that were created and work on various forms. Here is some additional info (there is much more out there too):

    http://www.bitdefender.com/VIRUS-157247-en--Win32.Brontok.A@mm.html

    Sophos BRONTGUI

    Kaspersky Brontok Removal Tool

    http://www.sophos.com/security/analyses/viruses-and-spyware/w32brontokl.html

    http://www.sophos.com/security/analyses/viruses-and-spyware/w32brontokn.html


    NOD32 and AVG have been know to clean up at least some forms of Brontok.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds