18
March , 2010
Thursday

Computer Tips Made Simple! – Thinker

worm brontok

Posted by Thinker On October - 22 - 2008
When the infected file with the virus Brontok is launched for the first time, you will see a Windows Explorer window, with a folder named “My Pictures”.

By installing the brontok worm changes the following registry key, the inaccessibility of tools registry, the command line, and viewing of files and folders in Windows Explorer.

Then Brontok copies itself under the following names

%UserProfile%\Local Settings\Application Data\br<random number>on.exe
%UserProfile%\Local Settings\Application Data\csrss.exe
%UserProfile%\Local Settings\Application Data\inetinfo.exe
%UserProfile%\Local Settings\Application Data\lsass.exe
%UserProfile%\Local Settings\Application Data\services.exe
%UserProfile%\Local Settings\Application Data\smss.exe
%UserProfile%\Local Settings\Application Data\svchost.exe
%UserProfile%\Local Settings\Application Data\winlogon.exe

The Emails sent may contain the following attachments with the Brontok Worm:

  • ccapps.exe
  • jangan dibuka.exe
  • kangen.exe
  • my heart.exe
  • myheart.exe
  • syslove.exe
  • untukmu.exe
  • winword.exe

Thinker

I am an Entrepreneur(Think tank), marketing consultant currently in Cochin on my startup.i ain't all that good at writing but i enjoy writing about things around me.You can visit me at www.andrinemendez.com. I tweet as

You might also like

FakeAlert Trojan Virus Removal
Your computer is infected! Windows has detected spyware infection! It is recommended to use special...
W32 Sohanad Worm – Virus Removal
Sohanad is a worm that spreads by sending links to their contacts as messengers such as Yahoo, AOL and...
Remove Braviax.exe – Manual Removal Instructions
Braviax.exe is a nasty virus that installs on your computer and creates all sorts of problems once it...
Bingoo.exe Virus
bingoo.exe Bingoo.exe is a  multi mall mailing worm by the name W32.Mytob.AM@mm also Bingoo.exe terminates...
Grab this Widget

1 Response

  1. lwrnlzzew Says:

    42zhAv vwtiknxxjkii, [url=http://eejpfaflhdkh.com/]eejpfaflhdkh[/url], [link=http://ueqfjakwjkcz.com/]ueqfjakwjkcz[/link], http://dghthpkqojmt.com/

    Posted on February 27th, 2010 at 11:55 pm

Leave a Reply




Recent Comments

There is something about me..

Recent Comments

BlogCamp Kerala

On Jul-5-2008
Reported by Thinker

ise32.exe Properties Window on Startup Virus Removal

On Sep-18-2008
Reported by Thinker

Best Permalink Seo Structure Wordpress

On Sep-24-2008
Reported by Thinker

Twikini – The Best Twitter Client for windows Mobile

On Jun-10-2009
Reported by Thinker

Skip Breakfast And Become A SUMO Wrestler!

On Jun-8-2008
Reported by Thinker

Recent Posts