Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: W32/Induc.A  (Read 3442 times)

0 Members and 1 Guest are viewing this topic.

geek hoodlum

    Topic Starter


    Apprentice
  • Thanked: 25
    • Yes
  • Experience: Familiar
  • OS: Windows 7
W32/Induc.A
« on: August 20, 2009, 11:08:44 PM »
Hi CH buddies,

My Avira AntiVir Personal found this one: W32/Induc.A

I searched this Malware in Avira's resources but they don't have any definitions for this. So I Googled-out and here's I found from Symantec and Sophos

My AntiVir said that the file was moved to quarantine. But when I checked my AntiVir Quarantine, there is no malware there.

I followed the steps here. But I'm not sure if I'm still infected by W32/Induc.A

Attached are the logs. Please advise.

[attachment deleted by admin]

Karnac



    Specialist

    Thanked: 211
    Re: W32/Induc.A
    « Reply #1 on: August 21, 2009, 04:54:47 AM »
    Go here for self help

    http://www.computerhope.com/forum/index.php/topic,81761.0.html

    Paste your HJT log into the window of the process tool and follow the instructions at the end to remove the problems....


    Never argue with a stupid person, they'll drag you down to their level and beat you with experience.

    geek hoodlum

      Topic Starter


      Apprentice
    • Thanked: 25
      • Yes
    • Experience: Familiar
    • OS: Windows 7
    Re: W32/Induc.A
    « Reply #2 on: August 21, 2009, 06:48:24 AM »

    Karnac



      Specialist

      Thanked: 211
      Re: W32/Induc.A
      « Reply #3 on: August 21, 2009, 07:09:28 AM »
      Ok, so follow the directions at the end for cleaning your machine, then run another malwarebytes scan and see how the machine runs.

      Follow the instructions here to clear System Volume Information after you have finished all scans.

      http://www.computerhope.com/issues/ch000775.htm
      « Last Edit: August 21, 2009, 07:21:35 AM by Karnac »


      Never argue with a stupid person, they'll drag you down to their level and beat you with experience.

      geek hoodlum

        Topic Starter


        Apprentice
      • Thanked: 25
        • Yes
      • Experience: Familiar
      • OS: Windows 7
      Re: W32/Induc.A
      « Reply #4 on: August 21, 2009, 09:12:44 AM »
      Hi Karnac,

      I fixed the following:
      • R0-R4 section
      • o18 - protocol: groovelocalgws - {88fed34c-f0ca-4636-a375-3cb6248b04cd} - c:\program files\micros~2\office12\gr99d3~1.dll
      • o4 - hkus\s-1-5-19\..\runonce: [showdeskfix] regsvr32 /s /n /i:u shell32 (user 'local service')
      • o4 - hkus\s-1-5-20\..\runonce: [showdeskfix] regsvr32 /s /n /i:u shell32 (user 'network service')
      • o4 - hkus\s-1-5-18\..\runonce: [showdeskfix] regsvr32 /s /n /i:u shell32 (user 'system')
      • o4 - hkus\.default\..\runonce: [showdeskfix] regsvr32 /s /n /i:u shell32 (user 'default user')

      Re-run HijackThis, please see attached log.
      Re-run another MBAM scan, please see attached log.
      Disabled Microsoft Windows XP System Restore.

      [attachment deleted by admin]

      Karnac



        Specialist

        Thanked: 211
        Re: W32/Induc.A
        « Reply #5 on: August 21, 2009, 01:13:54 PM »
        How is your computer running?


        Remember to enable system restore.


        Never argue with a stupid person, they'll drag you down to their level and beat you with experience.

        kpac

        • Web moderator


        • Hacker

        • kpac®
        • Thanked: 184
          • Yes
          • Yes
          • Yes
        • Certifications: List
        • Computer: Specs
        • Experience: Expert
        • OS: Windows 7
        Re: W32/Induc.A
        « Reply #6 on: August 21, 2009, 01:55:14 PM »
        Quote
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        You may also want to check this entry. Some consider it spyware as it tracks your behavior and sends it to Realtek.

        geek hoodlum

          Topic Starter


          Apprentice
        • Thanked: 25
          • Yes
        • Experience: Familiar
        • OS: Windows 7
        Re: W32/Induc.A
        « Reply #7 on: August 21, 2009, 06:50:58 PM »
        How is your computer running?

        Remember to enable system restore.

        My machine runs fine. Wait, what exactly do you mean? Should I enable or disable my system restore? 'Cause the link you gave shows an instruction on how to disable the system restore.

        Karnac



          Specialist

          Thanked: 211
          Re: W32/Induc.A
          « Reply #8 on: August 21, 2009, 06:57:32 PM »
          In System properties>system restore......Make sure the box is unchecked and Status says Monitoring

          You turn it off and then turn it back on to purge any restore points that are infected.


          Never argue with a stupid person, they'll drag you down to their level and beat you with experience.

          geek hoodlum

            Topic Starter


            Apprentice
          • Thanked: 25
            • Yes
          • Experience: Familiar
          • OS: Windows 7
          Re: W32/Induc.A
          « Reply #9 on: August 22, 2009, 03:12:06 AM »
          You may also want to check this entry. Some consider it spyware as it tracks your behavior and sends it to Realtek.
          Done kpac. Please see attached log.

          In System properties>system restore......Make sure the box is unchecked and Status says Monitoring

          You turn it off and then turn it back on to purge any restore points that are infected.
          Done Karnac.

          [attachment deleted by admin]

          kpac

          • Web moderator


          • Hacker

          • kpac®
          • Thanked: 184
            • Yes
            • Yes
            • Yes
          • Certifications: List
          • Computer: Specs
          • Experience: Expert
          • OS: Windows 7
          Re: W32/Induc.A
          « Reply #10 on: August 23, 2009, 08:56:50 AM »
          Quote
          Done kpac. Please see attached log.
          Can't see much else. How're you running?

          geek hoodlum

            Topic Starter


            Apprentice
          • Thanked: 25
            • Yes
          • Experience: Familiar
          • OS: Windows 7
          Re: W32/Induc.A
          « Reply #11 on: August 26, 2009, 11:37:41 PM »
          Hi kpac, my machine runs fine. Oh BTW, please check this news related to this malware. Just got it from Google.  8)

          kpac

          • Web moderator


          • Hacker

          • kpac®
          • Thanked: 184
            • Yes
            • Yes
            • Yes
          • Certifications: List
          • Computer: Specs
          • Experience: Expert
          • OS: Windows 7
          Re: W32/Induc.A
          « Reply #12 on: August 27, 2009, 04:11:30 AM »
          Interesting, thanks. :)