Author Topic: Help.....Brontok, Rontok Worms  (Read 7020 times)

0 Members and 1 Guest are viewing this topic.

coolsam

  • Guest
Help.....Brontok, Rontok Worms
« on: February 19, 2006, 04:43:29 AM »
does avast cure brontok.. rontok.. worm??? i am infected!!!!!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89224
  • No support PMs thanks
Re: Help.....Brontok, Rontok Worms
« Reply #1 on: February 19, 2006, 02:42:02 PM »
What is your OS ?
What AV are you using ?

avast's virus database has 19 entries for Brontok/Rontok variants, so unless you have a different variant or a new variant then avast should detect it. I assume you aren't using avast or yours isn't fully up to date (4.6.763 and VPS 0607-2).

If you haven't already got avast installed, ensure you remove (not just disable) your existing AV, otherwise conflicts can occur.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

coolsam

  • Guest
Re: Help.....Brontok, Rontok Worms
« Reply #2 on: February 19, 2006, 03:16:37 PM »
thanks bro... after reading the past posts i have learned to scan in safe mode.... its great... it removed the virus.. but let me ask again.. is it when i have just cleaned my pc and i opened a network pc which is infected do i get/catch the virus again? even if the avast is on-access protection?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89224
  • No support PMs thanks
Re: Help.....Brontok, Rontok Worms
« Reply #3 on: February 19, 2006, 05:04:11 PM »
If you are ignoring local connection traffic, you will get infected again, uncheck the 'Ignore local communications' in Web Shield, Customize, Basic. I don't know if this will resolve this as it would depend on what the local traffic was if not http: then I don't think it would catch it. However Standard Shield should catch it if the file is saved to your systems HDD (depends on your Standard Shield settings and sensitivity.

You should ensure all network systems are cleaned or you and any other systems on it are likely to become infected again.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Help.....Brontok, Rontok Worms
« Reply #4 on: February 19, 2006, 05:29:03 PM »
Hi coolsam,

If you have admin rights you can run the following removal tool:
http://wirusy.antivirenkit.pl/en/szczepionki/Brontok.html

greets,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Kunio

  • Guest
Re: Help.....Brontok, Rontok Worms
« Reply #5 on: February 20, 2006, 10:10:03 AM »
this site also have removal tool:
http://jeruk.padinet.com/~ertanto/
but avast currently FP detect is as Win32:Brontok

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89224
  • No support PMs thanks
Re: Help.....Brontok, Rontok Worms
« Reply #6 on: February 20, 2006, 03:49:59 PM »
this site also have removal tool:
http://jeruk.padinet.com/~ertanto/
but avast currently FP detect is as Win32:Brontok
Probably because the signatures it is trying to detect aren't encrypted so avast detects them. In that case avast is detecting correctly as it is looking for signatures, it isn't to know what those signatures are for.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Kunio

  • Guest
Re: Help.....Brontok, Rontok Worms
« Reply #7 on: May 29, 2006, 10:27:52 AM »
this site also have removal tool:
http://jeruk.padinet.com/~ertanto/
but avast currently FP detect is as Win32:Brontok
Is there any way that avast can tag this tool as "safe"? There are too many confuse to user that think it is virus. But infact, this tool is clean.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Help.....Brontok, Rontok Worms
« Reply #8 on: May 29, 2006, 03:41:04 PM »
Is there any way that avast can tag this tool as "safe"? There are too many confuse to user that think it is virus. But infact, this tool is clean.
Until the virus database will be corrected, as a workaround, you can add it to the two Exclusion lists of avast:

For the Standard Shield provider (on-access scanning):
Left click the 'a' blue icon, click on the provider icon at left and then Customize.
Go to Advanced tab and click on Add button...

For the other providers (on-demmand scanning):
Right click the 'a' blue icon, click Program Settings.
Go to Exclusions tab and click on Add button...

You can use wildcards like * and ?.
But be carefull, you should 'exclude' that many files that let your system in danger.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89224
  • No support PMs thanks
Re: Help.....Brontok, Rontok Worms
« Reply #9 on: May 29, 2006, 03:56:42 PM »
I'm not sure the VPS would be changed, it hasn't been for the likes of Panda's signature files which are also unencrypted, avast can't easily make the distinction of what the intent of a tool or file is, it is looking for virus signature patterns and it found one.

So the only option is to add it to the exclusions if you are sure it isn't infected.

You could also consider contacting the author and see if they can encrypt the signatures, that way they wouldn't be scanned.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security