W32.Rontokbro@mm

Status
Not open for further replies.
Make sure your antivirus programme is up to date, and has the latest virus deffinition files.

Boot into safe mode, and turn off system restore.

Do a complete scan with your antivirus, and remove anything it finds.

See HERE for further info.

Regards Howard :)
 
sorry to hijack your post. i've noticed signs of rontokbro on our network. symantec antivirus intercepts the load and promptly deletes them. i'm not exactly happy that the antivirus is merely doing its job. i want to find out where in the network is the infected machine so i can fix it once and for all. The manner in which it drop its load is not like the write ups on the internet.
symptoms:
- load is dropped into pcs with an active guest account without password.
- load is dropped using the guest account
- load takes the name of the directory it's dropped into eg. c:\winnt\system32\drivers\drivers.exe
- it attempts to drop its load into every single directory and subdirectory. the pc will appear to hang while its doing its rounds.

another interesting observation. after disabling the guest account, a different file in dropped into the pc - this time its qwe.bat and identified by symantec av as secefa. the secefa payload is dropped in using the system account. perhaps secefa and rontokbro mated and this is their offspring.

any idea how i can trace it to the infected machine?

rgds jon
 
Status
Not open for further replies.
Back