11
March , 2010
Thursday

Computer Tips Made Simple! – Thinker

worm brontok

Posted by Thinker On October - 22 - 2008
When the infected file with the virus Brontok is launched for the first time, you will see a Windows Explorer window, with a folder named “My Pictures”.

By installing the brontok worm changes the following registry key, the inaccessibility of tools registry, the command line, and viewing of files and folders in Windows Explorer.

Then Brontok copies itself under the following names

%UserProfile%\Local Settings\Application Data\br<random number>on.exe
%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\svchost.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe

The Emails sent may contain the following attachments with the Brontok Worm:

  • ccapps.exe
  • jangan dibuka.exe
  • kangen.exe
  • my heart.exe
  • myheart.exe
  • syslove.exe
  • untukmu.exe
  • winword.exe

Thinker

I am an Entrepreneur(Think tank), marketing consultant currently in Cochin on my startup.i ain't all that good at writing but i enjoy writing about things around me.You can visit me at www.andrinemendez.com. I tweet as

You might also like

FakeAlert Trojan Virus Removal
Your computer is infected! Windows has detected spyware infection! It is recommended to use special...
W32 Sohanad Worm – Virus Removal
Sohanad is a worm that spreads by sending links to their contacts as messengers such as Yahoo, AOL and...
Remove Braviax.exe – Manual Removal Instructions
Braviax.exe is a nasty virus that installs on your computer and creates all sorts of problems once it...
Bingoo.exe Virus
bingoo.exe Bingoo.exe is a  multi mall mailing worm by the name W32.Mytob.AM@mm also Bingoo.exe terminates...
Grab this Widget

1 Response

  1. lwrnlzzew Says:

    42zhAv vwtiknxxjkii, [url=http://eejpfaflhdkh.com/]eejpfaflhdkh[/url], [link=http://ueqfjakwjkcz.com/]ueqfjakwjkcz[/link], http://dghthpkqojmt.com/

    Posted on February 27th, 2010 at 11:55 pm

Leave a Reply




Recent Comments

There is something about me..

Recent Comments

Fix.exe is a Virus to be Removed!

On Nov-14-2008
Reported by Thinker

Bingoo.exe Virus

On Oct-5-2008
Reported by Thinker

Remove Internet Optimizer Virus

On Sep-19-2008
Reported by Thinker

Six Keywords For an Entrepreneur

On Jun-9-2008
Reported by Thinker

Recent Posts