Remove Brontok Virus

Start ur computer in safe mode with command prompt and type the following command to enable registry editor:-

reg delete HKCU\software\microsoft\windows\currentversion\policies\system /v "DisableRegistryTools"
and run HKLM\software\microsoft\windows\currentversion\policies\system /v "DisableRegistryTools"

after this ur registry editor is enable
type explorer
go to run and type regedit
then follow the following path :-
HKLM\Software\Microsoft\Windows\Currentversion\Run

on the right side delete the entries which contain 'Brontok' and 'Tok-' words.

after that restart ur system
open registry editor and follow the path to enable folder option in tools menu

HKCU\Software\Microsoft\Windows\Currentversion\Policies\Explorer\ 'NoFolderOption'
delete this entry and restart ur computer

and search *.exe files in all drives (search in hidden files also)
remove all files which are display likes as folder icon.

2 comments:

helena said...

My computer is infected by brontok. It comes up in win32/brontok........this seems to be system files. If I would delete those files to get rid of brontok, would it not affect the system working? I am only a normal private use person with no technical knowledge. PLEASE HELP!!!

Thanks

Helena

Anonymous said...

ya u can delete the brontok folder itself..no need to delete win32 folder.