Rontokbro....

Discussion in 'Malware Help (A Specialist Will Reply)' started by Phallius, Nov 4, 2009.

  1. Phallius

    Phallius Private E-2

    I was helping someone clean their virus infested machine recently and in the process managed to infect my own. Rontokbro is quite sneaky and I got fooled. Pretty embarassing, but it has happened now and I am trying to cure it. It was Adaware that located the Rontokbro worm, and a read of the Rontokbro symptoms confirmed that this is exactly what I have. Adaware (nor any other virus software for that matter) can actually remove the worm itself, since access to the registry is denied.

    Has anyone actually had any success removing the Rontokbro worm? I spent the entire day yesterday scouring the net for solutions and none of them work.

    Specs: Brand new Toshiba Satellite A500, Vista Ultimate.

    Most of these net solutions are really bad, such as "simply stop these processes" (stopping csrss.exe causes Vista to blue screen). And then "remove these registry entries" (Rontokbro denies access to the registry, that's sort of the point of it).

    I have tried looking for tools that reset the shell and allow access to the registry again, but Rontokbro doesn't like them, and so reboots you.

    I have tried running suggested tools such as Hijackthis. I renamed the files so that they would bypass Rontokbro's scrutiny, but Rontokbro reads window headings, and reboots my machine.

    It seems that nothing out there is able to outsmart this one. Has anyone out there had any luck with this, or is anyone good enough to try and take this one on?
     
  2. Phallius

    Phallius Private E-2

    I am running through your start guide (all in safe mode):

    -I cannot edit folder options, rontokbro hides extensions and hidden files, and then removes the folder options icon from control panel. I know you can run 'control folders' from the command line, but Rontokbro does not allow command prompt. It reboots the machine.

    - I am not allowed to run msconfig. Reboots the machine.

    Switching to normal mode to install recommended apps. Will update when complete:
     
  3. Phallius

    Phallius Private E-2

    Ok I have run all the software recommended and attached all the log files.

    Will reboot soon and see if the infection has cleared, but I doubt it.
     

    Attached Files:

  4. Phallius

    Phallius Private E-2

    The final requested log, since I can only upload 4.
     

    Attached Files:

  5. Phallius

    Phallius Private E-2

    .....and at first glance it looks ok!

    It never used to start windows properly. It used to stall at the logging in screen. I used to have to ctrl-alt-del, task manager, file, run, explorer.exe

    Now it starts up as normal.

    I am also able to open regedit!

    Looks good so far guys. I might go through all those scans again to see if anything was missed but it certainly looks good so far.

    I hope this will post will be useful for others out there who have themselves a Brontok worm like this one.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are running this PC with no protection. No wonder you got so badly infected.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds