Newest posts

   Subscribe

Get our E-Mail Newsletter:


               
   Video and Audio
Share videos in orkut

How to find and download MP3 free

How To Extract Audio From YouTube Videos

How To Load YouTube Videos Faster

What is Flv file ?

Search and download flv video

Download YouTube Videos for iTunes player

Download youtube video very easy

How To View Deleted YouTube Videos

Play flv file witn Windown Media

Download free MP3 Cutter for windows

   Microsoft Office
Microsoft Outlook 2007 Running Slow ? Fix the Problem Now

Read and Write Office 2007 Documents in Office 2003

Download Free PDF Plugin for Microsoft Office

Test Drive Microsoft Office 2007

Learn Microsoft Office 2007 from Microsoft

Microsoft Office 2007 Trial for Free Download

   Firefox tutorial
Undo Close Tab in Firefox quickly

How to resize the Firefox Search Bar

Download Firefox for better browsing

Useful Firefox Security Extensions

How to hack firefox to make it faster

Customize Firefox Web Page Appearance

Firefox Search Bar Hacks

Change firefox theme

Make firefox tabs more colorful

Customize firefox appearance

Firefox Search Bar Hacks

BrO_AcT Facts That You Need To Know

BrO_AcT Facts That You Need To Know

Lately, a lot of my friend's computer have been infected by BrO_AcT worm/virus. And it cause them a lot of trouble to get rid of this new virus. Moreover, the information on the Net is still very limited since it is a new virus. Recently, I've found the facts about this virus on the Net and want to share with you so that you will know if you've been a victim or not.

1)What is BrO_AcT ?

Symantec AV -> identify it as W32.sillyDC.
DrWeb CureIT -> identify it as Win32.HLLW.Broact
TrenMicro -> identify it as WORM_VB.BHE

Panda AV -> identify it as W32/SexyGirl.A.worm
Avira -> identify it as Worm/VB.DH.1

2)How it Spreads ?

Normally it spread via removable storage devices(USB drive) . Infected thumb drive will show these files: "MySexy.exe", "User.exe" and "Sexy.Dat".

3)Symptomps

-Popup box appears after login into the Windows, with the title "BrO_AcT.exe". It contains a message but I don't remember what it is written.
-Look at your title bar. An infected hardisk will show the folder name + [:Restricted by BrO_Act:]
- When you try to open C:\Windows\System32 folder, explorer close itself.
- Right click My Computer, select Properties, select Computer, click Change button, you find that your computer name has been changed to "ReAct_User"
-Your antivirus has been deactivated.
-You can't access Task Manager, Regedit, Msconfig, Folder option, and Command prompt.

4)How Do I Confirm that I'm Infected ?

Run Hijackthis. These are the entries added:
C:\WINDOWS\system32\BrO_AcT.exe
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\default__.pif"
O4 - HKLM\..\Run: [System] C:\WINDOWS\SYSTEM32\BrO_AcT.exe
O4 - HKCU\..\Run: [svchost] C:\WINDOWS\SYSTEM32\ReAct_User\svchost.exe


5)What Will This Virus Do or Create in Your Computer ?

It will create and add the following files :-

-C:\Windows\system32\BrO_AcT.exe
-C:\WINDOWS\default__.pif
-C:\WINDOWS\SYSTEM32\ReAct_User\svchost.exe
-C:\WINDOWS\SYSTEM32\ReAct_User\winlogon.exe
-C:\ReActLog (Something with this name)
-NTDETCH.com (on all your drive, root folder)
-Autorun.inf (on all your drive, root folder)
-Hundreds of files in C:\System Volume -Information\_restore{7C0D0734-E9F5-4A30-ABD4-977206CFACB2}\RP411 (With name like -A0062080.com, A0062083.pif, A0062092.exe and etc)
-C:\WINDOWS\system32\MySexy.exe
-C:\WINDOWS\system32\regedit.com
-C:\WINDOWS\system32\msconfig.com

It also will copy itself to any portable USB drive connected to the infected system and creating:-
->Autorun.innf
->BrO_AcT.exe
->My_SeXy.exe

and the USB drive will autorun anytime you connect it to the system. "THIS IS THE WAY HOW THE VIRUS SPREAD".


6) How Do I Get Rid of BrO_Act.exe ?


Update your anti-virus with latest virus definition. As far as I know :-

Nod32 AV - not detect, system infected
BitDefender 10 - not detect, system infected
McAfee - not detect, system infected

Avira - detected as
Worm/VB.DH.1
AVG 7.5 Pro - detected as W32/VB
Kapersky - detected as Win32.VB.DH


I hope this little info will help you to eliminate this annoying virus.


AddThis Social Bookmark Button AddThis Feed Button

Labels: ,

Translate to:

0 Comments:

Post a Comment

<< Home

Previous Posts

  Search

   Tips and Tricks
How to Rename Start Button in XP
How to Hide/Un-Hide Recycle Bin Icon on Desktop in XP
How to Automatically Login to Vista

   Free Download
Download MS Powerpoint viewer

Download calendar 2008 templates for MS Word

Free pdf to word convert

Download IE7 for Windows Xp

   Online Tools
Create logos style Web2.0

Create buttons online without Photoshop or GIMP

Web Instant Messengers

   Blogger Helps
How to create a blog using blogger
Hide or Remove Navbar in Blogger
Add google translate into blogspot
Add Ratings To Your Blog Posts
Put Your Social Bookmarking Icons
Add an icon feed labels Blogger
Add Favicon icon to Blogger URL
Recent Comments and Recent Posts Widgets

   Visitor Location

   Visitor