How to remove W32.Rontokbro Worm?

Salam & hello to all my dearest reader, today i would like to share some notes that related to the most popular virus among the university students, brontok. Have you heard about this name before? How do you feel when your complete project paper soft copy that you concentrate for 3 months more or less crashed by this worm? How do you feel when your unbacked up data in your operation system need to reformat? Ok this is simple idea in order how to solve this problem.
Method 1 (automated) - by eggy
- Download CleanX II
- Disconnect the computer from the internet and save all your project
- Close all programs
- Execute the program
Method 2 (automated) - by antivirenkit
- Download Brontok Removal tool
- Disconnect the computer from the internet and save all your project
- Close all programs
- Execute the program
Method 3 (manual) - by askicode
1. Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Run a full system scan and delete all the files detected.
4. Use the Security Response “Tool to reset shell\open\command registry subkeys.”
5. Delete any values added to the registry.
Navigate to the subkey and delete value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\…
Value: “Bron-Spizaetus” = “”%Windir%\ShellNew\sempalong.exe”"
Navigate to the subkey and delete value:
HKEY_CURRENT_USER\Software\Microsoft\W…
Value: “Tok-Cirrhatus” = “%UserProfile%\Local Settings\Application Data\smss.exe”"
Navigate to the subkey and reset value to default if required:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\… NT\CurrentVersion\Winlogon
Value: “Shell” = “Explorer.exe”
Navigate to the subkey and reset value to default if required:
HKEY_CURRENT_USER\Software\Microsoft\W…
Value: “NoFolderOptions” = “0″ or “NoFolderOptions” = “1″
Navigate to the subkey and reset values to default if required:
HKEY_CURRENT_USER\Software\Microsoft\W…
Values:
“Hidden” = “0″ or “Hidden” = “1″
“ShowSuperHidden” = “0″ or “ShowSuperHidden” = “1″
“HideFileExt” = “0″ or “HideFileExt” = “1″
7. Exit Registry and Restart the computer.
8. Delete the scheduled task.
To delete the scheduled tasks added by the worm
a. Click Start, and then click Control Panel. (In Windows XP, switch to Classic View.)
b. In the Control Panel window, double click Scheduled Tasks.
c. Right click the task icon and select Properties from menu. The properties of the task is displayed.
d. Delete the task if the contents of the Run text box in the task pane, matches the following:
%UserProfile%\Templates\Brengkolang.co…
9. Restart the computer.
10. In order to make sure that w32 rontokbro.k is completely eliminated from your computer, carry out a full scan of your computer using AntiVirus and Antispyware Software. Another way to delete the virus using various Antivirus Program without the need to install can be done with Online Virus Scanner.
* Do at your own risk.


thanks 4 sharing the info…
hahaa, brontok akan terus bermaharajalela. jangan membiarkan komputer anda menjadi mangsa keBRONTOKkan
yang durjana itu. habis jahnam semuanya.
rupanya virus virus brontok nie indon yang buat …
jom serang endon!!
who’s nobron & rundil..?
wahh, indon already have a powerfull virus.,
but when we malaysia gonna attack them with ours too?
Ada cara bagaimana nak detect Virus, Worm, Spyware atau apa-apa menggunakan ClamWin Open Source Antivirus.