I recently had an encounter with an infected Windows XP Pro with SP2 machine which annoyingly restarted whenever a download was initiated and opened on the default browser the link about Brontok.A. The page that was appearing had the following text:
BRONTOK.A [ By: H[REMOVED]Community ]
-- Hentikan kebobrokan di negeri ini --
1. Adili Koruptor, Penyelundup, Tukang Suap, Penjudi, & Bandar NARKOBA
( Send to "NUSAKAMBANGAN")
2. Stop Free Sex, Absorsi, & Prostitusi
3. Stop (pencemaran laut & sungai), pembakaran hutan & perburuan liar.
4. SAY NO TO DRUGS !!!
-- KIAMAT SUDAH DEKAT --
This was my clue, so I searched for the brontok.a reference, and came up with the following aliases for the e-mail worm that had infected the system when the user opened a certain e-mail attachment.
A.K.A. : Email-Worm.Win32.Brontok.a (Kaspersky Lab) is also known as: W32/Rontokbro.gen@MM (McAfee), W32.Rontokbro@mm (Symantec), BackDoor.Generic.1138 (Doctor Web), W32/Korbo-B (Sophos), Worm/Brontok.a (H+BEDV), Win32.Brontok.A@mm (SOFTWIN), Worm.Mytob.GH (ClamAV), W32/Brontok.C.worm (Panda), Win32/Brontok.E (Eset)
An Anti-virus was present on the system, but was not updated (lesson no. 1 !!!), and scanning the system did not find anything. Apparently, upon infection the virus creates registry keys that enable it to run at startup, and edits and sets registry entries that disable the use of regedit, msconfig, folder options, etc. (More info from Sophos.)
On the Sophos website, there is an available removal tool, but running it did not remove the worm variant.
Badly enough, there was no anti-spyware software on the system, and downloading was not an option as the system would restart at every attempt to download one. The Anti-virus software was also unable to do auto-update.
I downloaded Spybot from a different machine, and was able to install it on the infected one. It found and reverted changes made to the registry by the virus. Now this allowed the Anti-virus software to update itself and on restart was able to clean the machine after scan.