Author Topic: win32:Brontok Avast Chest Error  (Read 2201 times)

0 Members and 1 Guest are viewing this topic.

malakornge

  • Guest
win32:Brontok Avast Chest Error
« on: January 02, 2008, 10:23:33 PM »
Hi, this is a first time I've encountered any virus so I'm not sure exactly how I should go about this.

I have the win32:Brontok virus that some how infected only my USB flash drive. I opened a folder to access a file and avast detected the worm immediately. I then did a scan on my USB flash drive and it found many files that were infected with the worm.

Avast then suggested that I moved all the files to the chest. But of about 10,000 files only 4000 were able to move to the chest. Another 6000 gave me an error when I was trying to move them into the chest. It said that it was not successful.

Is there anyway that I can still save these files and just somehow rid of only the worm? Or is the only fix to delete the files completely.

Sorry if this is such a noob question, but this is the first time I've ever dealt with a virus/worm.  ???

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: win32:Brontok Avast Chest Error
« Reply #1 on: January 02, 2008, 10:39:49 PM »
Searching avast forums for win32:Brontok you'll find some more info.
I suggest:

1. Disable System Restore and reenable it after step 3.
2. Clean your temporary files.
3. Schedule a boot time scanning with avast with archive scanning turned on.
4. Use AVG Antispyware; SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
5. Test your machine with anti-rootkit applications. I suggest AVG or Trend Micro RootkitBuster.
6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.
The best things in life are free.