<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://debianws.lexgopc.com/wiki143/index.php?action=history&amp;feed=atom&amp;title=Brontok</id>
	<title>Brontok - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://debianws.lexgopc.com/wiki143/index.php?action=history&amp;feed=atom&amp;title=Brontok"/>
	<link rel="alternate" type="text/html" href="http://debianws.lexgopc.com/wiki143/index.php?title=Brontok&amp;action=history"/>
	<updated>2026-05-15T16:47:56Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.1</generator>
	<entry>
		<id>http://debianws.lexgopc.com/wiki143/index.php?title=Brontok&amp;diff=3635386&amp;oldid=prev</id>
		<title>imported&gt;XTheBedrockX: + 21 categories using HotCat</title>
		<link rel="alternate" type="text/html" href="http://debianws.lexgopc.com/wiki143/index.php?title=Brontok&amp;diff=3635386&amp;oldid=prev"/>
		<updated>2024-12-07T04:50:10Z</updated>

		<summary type="html">&lt;p&gt;+ 21 categories using &lt;a href=&quot;/wiki143/index.php?title=WP:HC&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;WP:HC (page does not exist)&quot;&gt;HotCat&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Short description|Computer virus}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Brontok&amp;#039;&amp;#039;&amp;#039; is a [[computer worm]]&amp;lt;ref name = &amp;quot;Yuliansyah&amp;quot;/&amp;gt; running on [[Microsoft Windows]]. It is able to disperse by [[e-mail]]. Variants include:&lt;br /&gt;
&lt;br /&gt;
* Brontok.A&lt;br /&gt;
* Brontok.D&lt;br /&gt;
* Brontok.F&lt;br /&gt;
* Brontok.G&lt;br /&gt;
* Brontok.H&lt;br /&gt;
* Brontok.I&lt;br /&gt;
* Brontok.K&lt;br /&gt;
* Brontok.Q&lt;br /&gt;
* Brontok.U&lt;br /&gt;
* Brontok.BH&lt;br /&gt;
&lt;br /&gt;
The most affected countries were Russia, Vietnam and Brazil, followed by Spain, Mexico, Iran, Azerbaijan, India and the Philippines.&amp;lt;ref&amp;gt;{{cite web |title=Kaspersky Threats — Brontok |url=https://threats.kaspersky.com/en/threat/Email-Worm.Win32.Brontok/ |website=threats.kaspersky.com |language=en |access-date=2022-09-02 |archive-date=2022-05-21 |archive-url=https://web.archive.org/web/20220521064501/https://threats.kaspersky.com/en/threat/Email-Worm.Win32.Brontok/ |url-status=live }}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Other names ==&lt;br /&gt;
Other names for this worm include: W32/Rontokbro.gen@MM, W32.Rontokbro@mm, BackDoor.Generic.1138, W32/Korbo-B, Worm/Brontok.a, Win32.Brontok.A@mm, Worm.Mytob.GH, W32/Brontok.C.worm, Win32/Brontok.E, Win32/Brontok.X@mm, and W32.Rontokbro.D@mm.&amp;lt;ref&amp;gt;{{cite web|title=Worm:Win32/Brontok.AR@mm|url=http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBrontok.AR%40mm|publisher=Microsoft|accessdate=14 February 2013|archive-date=5 March 2014|archive-url=https://web.archive.org/web/20140305102700/http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBrontok.AR%40mm|url-status=live}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Origin ==&lt;br /&gt;
Brontok originated in [[Indonesia]].&amp;lt;ref name=&amp;quot;Yuliansyah&amp;quot;&amp;gt;{{citation |author = Yuliansyah |title = Mengembalikan Data yang Hilang Akibat Virus |isbn = 978-979-8771-03-3 |publisher = Penerbit Mediakom |language = id |page = 10 |year = 2010}}&amp;lt;/ref&amp;gt; It was first discovered in 2005.&amp;lt;ref name = Yuliansyah /&amp;gt; The name refers to [[Changeable Hawk-eagle|&amp;#039;&amp;#039;elang brontok&amp;#039;&amp;#039;]], a bird species native to South &amp;amp; Southeast Asia. It arrives as an attachment of e-mail named kangen.exe (&amp;#039;&amp;#039;kangen&amp;#039;&amp;#039; itself means &amp;quot;to miss someone/thing&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
The virus/email itself contains a message in Indonesian (and some English). When translated, this reads:&lt;br /&gt;
&lt;br /&gt;
  [By: HVM31 JowoBot #VM Community] -- stop the collapse in this country—1. Try the Hoodlums, the Smugglers, the Bribers, the gamblers, &amp;amp; drugs &lt;br /&gt;
 Port (Send to &amp;quot;[[Nusakambangan]]&amp;quot;) -- &lt;br /&gt;
 &lt;br /&gt;
 2.Stop Free Sex, Abortion, &amp;amp; Prostitution (Go To HELL)&lt;br /&gt;
 &lt;br /&gt;
 3.Stop (sea and river pollution), forest burning, &amp;amp; wild hunting. &lt;br /&gt;
 &lt;br /&gt;
 4.SAY NO TO DRUGS!!! - THE END IS NEAR - &lt;br /&gt;
 &lt;br /&gt;
 5. Do you think you&amp;#039;re smart?&lt;br /&gt;
 &lt;br /&gt;
 Inspired by: (Spizaetus Cirrhatus) that is almost extinct [By: HVM31 JowoBot #VM Communityunity --&amp;lt;ref&amp;gt;{{cite web|title=Win32.Brontok.A@mm|url=http://www.bitdefender.co.uk/VIRUS-157247-uk--Win32-Brontok-Amm.html|publisher=Bitdefender|accessdate=14 February 2013|archive-date=19 April 2013|archive-url=https://archive.today/20130419212645/http://www.bitdefender.co.uk/VIRUS-157247-uk--Win32-Brontok-Amm.html|url-status=live}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It also contains a [[JavaScript]] [[Pop-up ad|pop-up]].&lt;br /&gt;
&lt;br /&gt;
The worm also carried out a [[ping flood]] attack on two websites: [[Israel|Israel.gov.il]] and [[Playboy|playboy.com]], possibly in an act of [[hacktivism]]. A number of other websites with .com TLD were also attacked, prompting popular Indonesian forum [[Kaskus]] to switch to [[.us]] TLD until May 2012. Brontok inspired the creation of a more persistent trojan/worm such as [[Daprosy Worm]] which attacked internet cafes in July 2009.&lt;br /&gt;
&lt;br /&gt;
== Symptoms ==&lt;br /&gt;
When Brontok is first run, it copies itself to the user&amp;#039;s application data directory. It then sets itself to start up with [[Microsoft Windows|Windows]], by creating a registry entry in the &amp;lt;code&amp;gt;HKLM\Software\Microsoft\Windows\CurrentVersion\Run&amp;lt;/code&amp;gt; [[Windows Registry|registry]] key. It disables the Windows Registry Editor ([[regedit.exe]]) and modifies [[Windows Explorer]] settings. It removes the option of &amp;quot;Folder Options&amp;quot; in the Tools menu so that the hidden files, where it is concealed, are not easily accessible to the user. It also turns off Windows firewall. In some variants, when a window is found containing certain strings (such as &amp;quot;application data&amp;quot;) in the window title, the computer reboots. User frustration also occurs when an address typed into Windows Explorer is blanked out before completion. Using its own mailing engine, it sends itself to email addresses it finds on the computer, even faking the own user&amp;#039;s email address as the sender.&lt;br /&gt;
&lt;br /&gt;
The computer also restarts when trying to open the [[Windows Command Prompt]] and prevents the user from downloading files. It also pop ups the default Web browser and loads a [[web page]] ([[HTML]]) which is located in the &amp;quot;My Pictures&amp;quot; (or on [[Windows Vista]], &amp;quot;Pictures&amp;quot;) folder. It creates .exe files in folders usually named as the folder itself (..\documents\documents.exe) this also includes all mapped network drives.&amp;lt;ref&amp;gt;{{cite web|title=Win32/Brontok|url=http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Win32%2fBrontok|publisher=Microsoft|accessdate=14 February 2013|archive-date=9 February 2013|archive-url=https://web.archive.org/web/20130209074412/http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?name=Win32%2fBrontok|url-status=live}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Removal ==&lt;br /&gt;
Brontok can be removed by most [[antivirus software]] although there are various standalone tools available by antivirus providers.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Email worms]]&lt;br /&gt;
[[Category:Hacking in the 2000s]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;br /&gt;
[[Category:Windows malware]]&lt;br /&gt;
[[Category:Denial-of-service attacks]]&lt;br /&gt;
[[Category:Internet in Russia]]&lt;br /&gt;
[[Category:Internet in Brazil]]&lt;br /&gt;
[[Category:Internet in Vietnam]]&lt;br /&gt;
[[Category:Internet in Spain]]&lt;br /&gt;
[[Category:Internet in Azerbaijan]]&lt;br /&gt;
[[Category:Internet in Mexico]]&lt;br /&gt;
[[Category:Internet in Iran]]&lt;br /&gt;
[[Category:Cybercrime in the Philippines]]&lt;br /&gt;
[[Category:Attacks in Azerbaijan]]&lt;br /&gt;
[[Category:Attacks in Brazil]]&lt;br /&gt;
[[Category:Attacks in India]]&lt;br /&gt;
[[Category:Attacks in Iran]]&lt;br /&gt;
[[Category:Attacks in Mexico]]&lt;br /&gt;
[[Category:Attacks in the Philippines]]&lt;br /&gt;
[[Category:Attacks in Russia]]&lt;br /&gt;
[[Category:Attacks in Vietnam]]&lt;br /&gt;
[[Category:Internet in Israel]]&lt;br /&gt;
[[Category:Attacks in Israel]]&lt;br /&gt;
[[Category:Playboy]]&lt;/div&gt;</summary>
		<author><name>imported&gt;XTheBedrockX</name></author>
	</entry>
</feed>