Update on Indt2.sys virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Farscape1, Apr 7, 2008.

  1. Farscape1

    Farscape1 Private E-2

    There is a post back on 2/12/08 regarding a possible virus threat – indt2.sys. This so called virus may come from Digital Picture Frames (DPF). I have a new system that rarely hits the Internet, but it does a lot of testing on DPFs. I got this possible virus on my system and had to find a way of getting ride of it. So this post is a response to this post http://forums.majorgeeks.com/archive/index.php?t-151455.html


    Update on this possible virus “Indt2.sys” – the clicking sounds like mouse clicks as it is running an unseen application or website in the background I did not find out exactly what program it was clicking. The sound pops or strange sounds is like the virus is launching an online radio station or something similar. I have herd music to advertisements, so it may be launching an online radio program for just a few short seconds.

    I haven’t found any real damage or propagating properties like a normal virus, it is just very annoying, especially when you are listening to music or watching a movie.

    If you delete the Indt2.sys application it will just launch itself again. The virus has embedded itself in the Microsoft Prefetch folder which launches every time you start up your system.

    Use the following steps to remove this virus.

    Run a search for “Indt2.sys” you should have two instances, one in C:\Windows\Prefetch which will have an extension of .pf for the prefetch to find then launch, and the other in C:\Windows\System32 rename both of these to .old.

    Next launch from the Run prompt “msconfig” go to the startup tab and you will find some startup items that do not have a name but are just blank, take the check out of them, hit OK, then reboot.

    The annoying clicking and radio burst have gone away, now that it has not launched and wont reload itself, use the above steps to delete and remove the program.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Thanks for posting; however this is not a proper way to remove this. You still have registry entries that were not removed and using MSconfig for long term startup program control is not recommended. Using our standard cleaning procedures given in this READ & RUN ME FIRST. Malware Removal Guide (which the user was asked to run in the link you referenced) will allow proper cleaning and removal of this and also any other possible related malware issues. SYS files are often loaded as drivers and thus you may even still have a service related to this trying to load that you cannot see.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds