Remove Rontokbro. Description and removal instructions

 
Title: Rontokbro
Also known as: Brontok
Type: Worms
Severity scale:Rontokbro severity is 66  (66 / 100)
 
Rontokbro is a rapidly spreading Internet worm that propagates by e-mail in messages with infected attachments. Once the user executes such an attachment, the parasite installs itself to the system and runs its spreading routine. It scans the entire system for e-mail addresses and sends itself there using own mail engine. Rontokbro modifies essential system settings in order to disable standard Windows tools such as the Registry Editor or Command Prompt. It also immediately restarts a computer when it detects certain software running. Such software can be various antivirus and anti-spyware programs, web browsers, programming tools and many other popular applications. Rontokbro may launch an attack against several well-known web sites. The worm's activity severely degrades overall system performance and Internet connection speed and causes general system instability. The parasite runs on every Windows startup.


Related files: csrss.exe, cvt.exe, idtemplate.exe, inetinfo.exe, kangent.exe, lsass.exe, services.exe, a.kotnorb.com, empty.pif, 3d animation.scr, smss.exe, bronstab.exe, eksplorasi.exe, ~dfa861.tmp, sempalong.exe

Rontokbro properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Rontokbro removal:

remover for Rontokbro

Rontokbro manual removal:

Kill processes:
csrss.exe, cvt.exe, idtemplate.exe, inetinfo.exe, kangent.exe, lsass.exe, services.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bron-spizaetus
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableCMD=2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistry
Tools=1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\”Bron-Spizaetus” = “C:\WINDOWS\PIF\CVT.exe”
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Policies\System\”DisableRegistryTools” = “1″
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Policies\Explorer\”NoFolderOptions” = “1″
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\Policies\System\”DisableCMD” = “2″
Delete files:
csrss.exe cvt.exe idtemplate.exe inetinfo.exe kangent.exe lsass.exe services.exe a.kotnorb.com empty.pif 3d animation.scr smss.exe bronstab.exe eksplorasi.exe Temp\\~dfa861.tmp sempalong.exe eksplorasi.exe
Delete directories:
C:\Documents and Settings\[Current User]\Local Settings\Application Data\bron.tok-24
Misc:
kangen.exe is the infected file that arrives attached to malicious e-mail messages sent by Rontokbro.

Exact file location:
cvt.exe - C:\Windows\PIF or C:\Winnt\PIF
3d animator.scr - C:\Windows\System32 or C:\Winnt\System32
a.kotnorb.com - C:\Documents and Settings\[Current User]\Templates
empty.pif - C:\Documents and Settings\[Current User]\Programs\Startup
csrss.exe, idtemplate.exe, inetinfo.exe, lsass.exe, services.exe - C:\Documents and
Settings\[Current User]\Application Data

Other programs to remove Rontokbro:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 24/09/05
Information updated: 02/04/08

Additional resources related to Rontokbro:

Attention: If you know or you have a website or page about Rontokbro removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Rontokbro parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Guest. 2006-12-21 12:12:22
thnaks for the support


Latest spyware news:
Similar parasites:
Related discussions: