Mr. Brontok disabled my regedit!

A worm disabled my regedit by adding a key to it. Can anyone tell me

  • (2 Pages)
  • +
  • 1
  • 2

23 Replies - 1444 Views - Last Post: 20 April 2008 - 05:13 PM

#1 wiko  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 21
  • Joined: 15-April 08

Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 08:44 AM

Yesterday was a hard day for me. My laptop was attacked by a worm called RONTOKBRO.A aka Brontok which attacks Win32 devices. This virus is very famous in Egypt, especially with Flash Drives. It creates a copy of itself everywhere on your computer, and it hides in an icon of a folder. I have Windows Vista, but no antiviral software was installed. This worm restarts the PC whenever Windows Explorer is loaded. So fortunately, it initially prevents explorer from loading at startup. So you will have to open Explorer, and then it will restart :D However, you can ignore explorer, and use your computer without explorer.. just load the program you want from the task manager ;) If you start from SafeMode, you can close the three programs that restart your machine using taskman, and load explorer safely. But in Normal mode, there's another program that does this job if you close the other three programs. So, I used the safe mode to run the explorer, and try to install Kaspersky and AVG Antivirus, but failed to do so because Windows Installer cannot start in safemode :S and since I cannot run explorer in Normal mode, I thought it is impossible to install any antiviral software to remove this worm. I decided to hunt for it my self. I started from MsConfig, disabled the unwanted applications such as lsass.exe, smss.exe and winlogon.exe. The files that I disabled should be run as part of windows startup components, and not as a part of the user components. In addition to that their path was not in system32 where they normally should be, it was in my user profile folder. I found another file that is called Empty.pif, an MS-DOS shortcut which I failed to know where it points to. I simply deleted all these files from my hard drive, but when I restarted my machine, they were recreated!!! Here I knew there are still some other files that create these files and add them to startup. I must find these files! Anyway, I was able to find all files, and delete them, and now the machine starts up normally. But my problem now is that this worm has its files hidden, and for you to find these files you have to go through programs that run through taskmgr. Why? because the worm makes the OS not to show hidden files and folders. You will tell me, ok.. enable them from folder options.. , uh uh.. the worm disables folder options from control panel, and windows explorer view menu. Ok.. enable it from the registry.. again.. the worm disables regedit. so I cannot enable folder options.

I tried to search for solutions for this virus, but all what I found is pages that tell me that the virus does the following:
- It disables regedit by adding the following key to the registry. blablabla
and then in the solution it says: To enable registry editing open regedit.exe, and remove the key that the worm added.. what the f**k!!! How would I delete it if I cannot open regedit!!! and the worse thing is that they continue telling the solution based on regedit.exe you will have to do all the fixing through regedit!!

Now that my Windows loads peacefully, i cannot make it show hidden files or folders, however, I can access them if I know their names. And the regedit is disabled.

Today, I installed Kaspersky, updated its database, and scanned my computer. It found 7334 instances of Win32.Rontokbro.A hidden in my folders. OMG, if I run any of these files by mistake, the movie will start form the beginning.

Can anyone tell me how to enable regedit, ie remove the key that the worm added??

Is This A Good Question/Topic? 0
  • +

Replies To: Mr. Brontok disabled my regedit!

#2 Nykc  Icon User is offline

  • Gentleman of Leisure
  • member icon

Reputation: 725
  • View blog
  • Posts: 8,638
  • Joined: 14-September 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 08:55 AM

Why would he do that?
Was This Post Helpful? 0
  • +
  • -

#3 axel  Icon User is offline

  • Bug Juice Doesn't Come in a Jar
  • member icon

Reputation: 2
  • View blog
  • Posts: 1,944
  • Joined: 31-December 06

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 08:56 AM

I didn't read the post...but isn't this probably in the wrong section?
Was This Post Helpful? 0
  • +
  • -

#4 BenignDesign  Icon User is offline

  • holy shitin shishkebobs
  • member icon




Reputation: 5755
  • View blog
  • Posts: 10,078
  • Joined: 28-September 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:05 AM

Yeah... wrong section.... he's looking for help on getting rid of a worm.
Was This Post Helpful? 0
  • +
  • -

#5 Nykc  Icon User is offline

  • Gentleman of Leisure
  • member icon

Reputation: 725
  • View blog
  • Posts: 8,638
  • Joined: 14-September 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:07 AM

My dog had worms once.
Was This Post Helpful? 0
  • +
  • -

#6 BenignDesign  Icon User is offline

  • holy shitin shishkebobs
  • member icon




Reputation: 5755
  • View blog
  • Posts: 10,078
  • Joined: 28-September 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:11 AM

ewww.... did he smear them on your carpet?
Was This Post Helpful? 0
  • +
  • -

#7 wiko  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 21
  • Joined: 15-April 08

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:13 AM

no guys.. I already got rid of the worm, but now I want to restore my "regedit" access to normal, and read the post before replying :)
Was This Post Helpful? 0
  • +
  • -

#8 Nykc  Icon User is offline

  • Gentleman of Leisure
  • member icon

Reputation: 725
  • View blog
  • Posts: 8,638
  • Joined: 14-September 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:14 AM

Post in the right place. We are talking about animals with worms in this thread. If you want help with computer support use that forum please.

Gracias
Was This Post Helpful? 0
  • +
  • -

#9 wiko  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 21
  • Joined: 15-April 08

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:27 AM

View PostNykc, on 19 Apr, 2008 - 09:14 AM, said:

Post in the right place. We are talking about animals with worms in this thread. If you want help with computer support use that forum please.

Gracias


:S
Was This Post Helpful? 0
  • +
  • -

#10 capty99  Icon User is offline

  • i am colt mccoy
  • member icon

Reputation: 97
  • View blog
  • Posts: 10,081
  • Joined: 26-April 01

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:35 AM

its the lounge. it happens. just re-post over there, its not even worth a mod moving it cause theres a lot of crap.
Was This Post Helpful? 0
  • +
  • -

#11 BenignDesign  Icon User is offline

  • holy shitin shishkebobs
  • member icon




Reputation: 5755
  • View blog
  • Posts: 10,078
  • Joined: 28-September 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 09:40 AM

The real Kya is hotter than me? Damn. Way to boost my self-esteem!
Was This Post Helpful? 0
  • +
  • -

#12 Mikhail  Icon User is offline

  • Bastard Operator From Hell
  • member icon

Reputation: 58
  • View blog
  • Posts: 1,378
  • Joined: 26-October 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 12:43 PM

I eat chocolate covered worms
Was This Post Helpful? 0
  • +
  • -

#13 PsychoCoder  Icon User is offline

  • Google.Sucks.Init(true);
  • member icon

Reputation: 1633
  • View blog
  • Posts: 19,853
  • Joined: 26-July 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 01:10 PM

Question #1: Why in the blue hell are you running Windows without an anti-virus software? N00b!
Was This Post Helpful? 0
  • +
  • -

#14 wiko  Icon User is offline

  • New D.I.C Head

Reputation: 0
  • View blog
  • Posts: 21
  • Joined: 15-April 08

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 01:23 PM

View PostPsychoCoder, on 19 Apr, 2008 - 01:10 PM, said:

Question #1: Why in the blue hell are you running Windows without an anti-virus software? N00b!

Answer#1: coz I have been using it for 5 years without antivirus, and not being attacked once!! and I dont access websites that could harm me ;)
Was This Post Helpful? 0
  • +
  • -

#15 Mikhail  Icon User is offline

  • Bastard Operator From Hell
  • member icon

Reputation: 58
  • View blog
  • Posts: 1,378
  • Joined: 26-October 07

Re: Mr. Brontok disabled my regedit!

Posted 19 April 2008 - 01:24 PM

Hehe

#2 Do you Have Sp2? do you ever update your system?
Was This Post Helpful? 0
  • +
  • -

  • (2 Pages)
  • +
  • 1
  • 2