W32.alcra.c REMOVED FINALLY!!!

W32.alcra.c REMOVED FINALLY!!!

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
W32.alcra.c REMOVED FINALLY!!! AizA 08-01-2006
Posted by AizA on August 1, 2006, 10:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Updating my previous posts regarding this virus:

I followed everything Elephant Boy and David Lippman suggested. After
HOURS and HOURS of virus scanning and repeatedly getting no viruses
found, I did the final suggestion of going through Clean Boot.

I won't bore with the clean boot detail, but that is not what solved
it .. although it did put me in the right direction.

One of my symptoms was that NAV was coming up saying it found and
delted this virus over and over and over again .. literally hundreds
of times. Once in a while it would say that it could not delete it.
When I moused over that directory, I found the ones it was not able to
delete were the ones in quarantine.

So I got into safe mode, followed that directory to quarantine and
deleted everything in there .. 2,238 files!!!!! I also recleaned the
TEMP folder.

My computer has been running fine since.

I hope this and my previous thread can be useful to others.

I also want to take another moment to thank Mr. Lippman and Elephant
Boy for their time and patience with me as I struggled through this.
You guys are awesome and I appreciate EVERYTHING!!!

And THANK YOU for introducing me to this newsgroup! Newsgroups aren't
just for porn any more! LOLOLOLOL :):):):)

Don in Tucson is OUTTA HERE
AizA




Posted by David H. Lipman on August 2, 2006, 3:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

< snip >

|
| So I got into safe mode, followed that directory to quarantine and
| deleted everything in there .. 2,238 files!!!!! I also recleaned the
| TEMP folder.
|
| My computer has been running fine since.
|
| I hope this and my previous thread can be useful to others.
|
| I also want to take another moment to thank Mr. Lippman and Elephant
| Boy for their time and patience with me as I struggled through this.
| You guys are awesome and I appreciate EVERYTHING!!!
|
| And THANK YOU for introducing me to this newsgroup! Newsgroups aren't
| just for porn any more! LOLOLOLOL :):):):)
|
| Don in Tucson is OUTTA HERE
| AizA
|

That's alot of files in the quarantine !

That means you keep getting infected.

Please learn about Safe Hex practices.
http://www.claymania.com/safe-hex.html

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by URCS on August 2, 2006, 5:12 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Re: Keep getting reinfected ....

not really ..

kept getting REinfected by the same virus. During the entire time I
had the virus I was not even connected to the net. Cat5 outta the
rear end.
When it came to getting the files for AV.exe, done on a different
machine and thumb drived over.

That is what was weird about this infectrion .... although it could
not be found by ANY of the virus checkers, even when on as a slave on
different machine, it kept propagating.

It HAD to have had something to do with the quarantine section of NAV.
NAV was not able to delete that file in quarantine.

And again, I reitrerate, the Symantec site lists this as an "easy"
removal. I followed theirs and the steps listed here and no virus was
found to remove.

Maybe I am the only one that will have this situation. But if not, at
least the next guy will have my notes as reference, too.

Thanks for everything, techs. I appreciate your help.

Don in Tucson
AizA

On Wed, 2 Aug 2006 15:32:24 -0400, "David H. Lipman"

>
>< snip >
>
>|
>| So I got into safe mode, followed that directory to quarantine and
>| deleted everything in there .. 2,238 files!!!!! I also recleaned the
>| TEMP folder.
>|
>| My computer has been running fine since.
>|
>| I hope this and my previous thread can be useful to others.
>|
>| I also want to take another moment to thank Mr. Lippman and Elephant
>| Boy for their time and patience with me as I struggled through this.
>| You guys are awesome and I appreciate EVERYTHING!!!
>|
>| And THANK YOU for introducing me to this newsgroup! Newsgroups aren't
>| just for porn any more! LOLOLOLOL :):):):)
>|
>| Don in Tucson is OUTTA HERE
>| AizA
>|
>
>That's alot of files in the quarantine !
>
>That means you keep getting infected.
>
>Please learn about Safe Hex practices.
>http://www.claymania.com/safe-hex.html


Posted by David H. Lipman on August 2, 2006, 5:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Re: Keep getting reinfected ....
|
| not really ..
|
| kept getting REinfected by the same virus. During the entire time I
| had the virus I was not even connected to the net. Cat5 outta the
| rear end.
| When it came to getting the files for AV.exe, done on a different
| machine and thumb drived over.
|
| That is what was weird about this infectrion .... although it could
| not be found by ANY of the virus checkers, even when on as a slave on
| different machine, it kept propagating.
|
| It HAD to have had something to do with the quarantine section of NAV.
| NAV was not able to delete that file in quarantine.
|
| And again, I reitrerate, the Symantec site lists this as an "easy"
| removal. I followed theirs and the steps listed here and no virus was
| found to remove.
|
| Maybe I am the only one that will have this situation. But if not, at
| least the next guy will have my notes as reference, too.
|
| Thanks for everything, techs. I appreciate your help.
|
| Don in Tucson
| AizA
|

Thios is a worm so re-indfection is totally possible IF your AV software is NOT
up-yo-date
and you don't use a FireWall application and/or an appliance.

You listed this as; "W32.alcra.c" This could be a new variant and thus what is
lised under
the removal instructions is NOT accurate. The fact it was etected as
"W32.alcra.c" but had
different charachteristics is not new to any AV vendor. They can only provide
information
based upon the samples they have received. The signatures however may find the
infector
without the infector being the exect match in the library.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
W32.Alcra.D November 13, 2005, 11:28 am
w32.alcra.f February 28, 2006, 10:25 pm
W32.alcra.b problem July 1, 2005, 2:34 pm
Tell users how to restore files removed by MRT October 7, 2008, 12:06 pm
Virus removed webpages still restricted. Advice please October 7, 2005, 8:03 am
Tough I removed it, I do not know what it is: dllhost32 data resources September 8, 2006, 5:41 pm
Removed Norton Antivirus and can't connect to internet December 19, 2006, 7:23 pm
How would I have manually removed Trojan-Downloader.Win32.ConHook.bd May 17, 2007, 2:25 pm
Worm VB.AS Aliases W32.Alcra.B and W32/Alcan.worm!p2p July 18, 2005, 8:37 am

The site map in XML format XML site map

Contact Us | Privacy Policy