remains of brontok

Discussion in 'Software Q&A' started by shashanktyagi1, Nov 22, 2006.

Thread Status:
Not open for further replies.
  1. shashanktyagi1

    shashanktyagi1 New Member

    Joined:
    Feb 6, 2006
    Messages:
    157
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Lucknow, India
    i recently got brontok in my compu which the updated version of avg quite succesfully removed. but on startup this error comes.
    cannot find c:\windows\keesenge(something).exe there is no such boot up prog in msconfig.
    how do i remove it?
     
  2. Kiran.dks

    Kiran.dks New Member

    Joined:
    Apr 3, 2006
    Messages:
    2,494
    Likes Received:
    91
    Trophy Points:
    0
    Location:
    Pune, India
    It appears that AVG has removed the Virus, but the registry entry of the virus is not changed. Perform Registry scan using a good registry software. If problem still persists, perform these steps:

    1. Take a registry back up using a registry backup tool
    2. Download:UnHookExec.inf right-click and 'Install'. This is a registry entry. It does not display any notice when you run it.
    3. Restart PC
     
    Last edited: Nov 22, 2006
  3. anandk

    anandk Distinguished Member

    Joined:
    Mar 8, 2005
    Messages:
    3,786
    Likes Received:
    106
    Trophy Points:
    0
    Location:
    Pune
    install and run ccleaner.
    also use its startup tool to remove any relevant entry if u c it.
    reboot. revert.
     
  4. Akshay

    Akshay Active Member

    Joined:
    Aug 15, 2004
    Messages:
    1,121
    Likes Received:
    9
    Trophy Points:
    38
    Location:
    Pune
    I used Kaspersky to clean brontok. It cleared everything without ne prbs.
     
  5. OP
    OP
    shashanktyagi1

    shashanktyagi1 New Member

    Joined:
    Feb 6, 2006
    Messages:
    157
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Lucknow, India
    it is not even allowing modification of registry. whenever i try to run regedit it says that registry editing has been blocked by the admin. i am the admin. so how to open it again. i am using win Xp pro sp2.
     
  6. anandk

    anandk Distinguished Member

    Joined:
    Mar 8, 2005
    Messages:
    3,786
    Likes Received:
    106
    Trophy Points:
    0
    Location:
    Pune
  7. sac_meer

    sac_meer New Member

    Joined:
    Sep 6, 2006
    Messages:
    14
    Likes Received:
    0
    Trophy Points:
    0
    which type of brontok in ur pc brontok.a,brontok.b or brontok.c try panda antivirus and it solve ur reg prob as well as virus prob. but after install ur pc might be start slow but after scan virus u can uninstall safely.

    or u can try another method try to insall panda, in installtion wizard it will ask u to performe a full scan of ur pc try this option and perform a full scan of ur pc, after complete scan u can cancle the installtion process. thats simple for all type of brontok
     
  8. Kiran.dks

    Kiran.dks New Member

    Joined:
    Apr 3, 2006
    Messages:
    2,494
    Likes Received:
    91
    Trophy Points:
    0
    Location:
    Pune, India
    Registry editing is disabled by this virus. For enabling registy editing download the registry entry which I specifed in my earlier post. Just download and right-click 'run'.

    Registry editing must get enabled.
     
  9. OP
    OP
    shashanktyagi1

    shashanktyagi1 New Member

    Joined:
    Feb 6, 2006
    Messages:
    157
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Lucknow, India
    thanx kiran. that registry entry did the trick. will see if it remains after restart. regedit now opening fine.
    __________
    registry opening but that startup entry still there. how to remove it?
     
    Last edited: Nov 27, 2006
  10. Kiran.dks

    Kiran.dks New Member

    Joined:
    Apr 3, 2006
    Messages:
    2,494
    Likes Received:
    91
    Trophy Points:
    0
    Location:
    Pune, India
    ^^^
    Welcome.
    Open the registry editor:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    Delete the value
    "Bron-Spizaetus" = "C:\WINDOWS\PIF\CVT.exe" if exists.

    then perform registry cleaning
    Download: http://www.filehippo.com/download_ccleaner/
     
    Last edited: Nov 27, 2006
Thread Status:
Not open for further replies.

Share This Page