Hey Guys! Great forum & it has helped me in the past.
But I need assistance on this one. I’m having a major problem removing the Brontok infection. Not sure if starting a new topic is the way to go as I have witnessed previous threads in relation to my problem on this forum in the past. As I understand each individual infection is different. Any help or suggestion would be greatly appreciated.
It began last week, Avast blocked a process from Brontok. I ran a scan straight away, full sysytem, including PUP files. It encountered the infection in three files,removed 2 & was unable to the last. Avast suggested a reboot scan of the registry & I proceeded to do so. I scaned again, after the boot scan. . . . no infections found. Then 5 mins later, Avast blocked the process again. I also have spybot search & destroy on my laptop but a full scan showed nothing. My laptop knowledge is fairly low.
Reading a previous thread on this forum, I downloaded malwarebytes, updated straight away & ran a scan & it found nothing. I turned file sharing off & system restore to avoid the infection making things worse. I have been checking my task manager so see if the process is running but it aint appearing, I guess Avast is stoping it from processing.
Just ran a full sytem scan with avast & it found 1 infected file, as follows. …
thanks for response, Just updated Combofix & ran another scan.
Please see file attached.
Note…upon reboot I had no access to files or programes & was prompted by windows… “illegal operation attempted on a registry key that has been marked for deletion”
Just rebooted the laptop & had access again.
Regards
Ray
Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Notes:
Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.
Please downloadThe Avenger by Swandog46 to your Desktop.
[*]Right click on the Avenger.zip folder and select “Extract All…”
[*] Follow the prompts and extract the avenger folder to your desktop
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:
Files to delete:
C:\Windows\SoftwareDistributor\Datastore\Logs\trz\AF80.tmp
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Now, open the avenger folder and start The Avenger program by clicking on its icon.
[*] You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
[*] Click on Execute
[*] Answer “Yes” twice when prompted.
The Avenger will automatically do the following:
[*]It will Restart your computer. ( In cases where the code to execute contains “Drivers to Delete”, The Avenger will actually restart your system twice.)
[*]On reboot, it will briefly open a black command window on your desktop, this is normal.
[*]After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
[*] The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Please copy/paste the content of c:\avenger.txt into your reply.
Not sure if this has worked as the txt file says operation aborted but here is txt file
Just in the process of an Avast scan now to see if there is still infection…
Ragards
Ray
Ok followed your intructions exactly…
inputed the following command into avenger…
Begin copying here:
Files to delete:
C:\Windows\SoftwareDistributor\Datastore\Logs\trz\AF80.tmp
It restarted & I got the black prompt box again but I cant locate the avenger.txt file in C: drive??
Also no txt document was opened upon reboot. I assume the command is not being performed. have tried it a few times, still no C:\avenger.txt present.
However when I inputed the wrong command (as you pointed out) I got the txt file in C drive.
Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Notes:
Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.