Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Dec 07, 2006 | Updated Sep 15, 2017

Worm:Win32/Brontok.AS@mm

Detected by Microsoft Defender Antivirus

Aliases: Email-Worm.Win32.Brontok (Ikarus) Email-Worm.Win32.Brontok.q (Kaspersky) Generic.Brontok.99075776 (BitDefender) I-Worm/Brontok.EA (AVG) W32.Rontokbro@mm (Symantec) W32/Brontok-V (Sophos) W32/Rontokbro (Norman) W32/Rontokbro.gen@MM (McAfee) Win32/Brontok.CV (ESET) Win32/Brontok.worm.42579 (AhnLab) Worm/Brontok.C (Avira) WORM_RONTKBR.GEN (Trend Micro)

Summary

Worm:Win32/Brontok.AS@mm is a mass-mailing email worm that modifies certain computer settings, such as how hidden files are displayed, and disables registry editing.

It spreads by sending a copy of itself, as an email attachment, to contacts stored on your computer. It can also copy itself to USB and removable drives.

Worm:Win32/Brontok.AS@mm is a member of the Worm:Win32/Brontok@mm and Win32/Brontok families.

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

System Restore recommendation to revert registry data modifications

This malware changes registry data that will not be restored by detecting and removing this threat. To return registry data on an affected computer to its pre-infected state, run System Restore:

Follow us