Remove Inker. Description and removal instructions

 
Title: Inker

Type: Worms
Severity scale:Inker severity is 59  (59 / 100)
 
Inker is a specific sript worm written in Visual Basic Script programming language. It spreads in the Internet, usually through IRC chat networks using mIRC program or by e-mail in letters with infected attachments. Once executed, Inker starts to run its destructive payload. The worm overwrites text, batch, configuration and programming files with a copy of itself, destroys the main directory of Symantec Norton AntiVirus and changes the Internet Explorer default home page. Inker also creates a registered user account, swaps the mouse buttons, attempts to disable the keyboard and may hide the desktop. The parasite runs on every Windows startup.


Inker properties:
• Changes browser settings
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Inker removal:

remover for Inker

Inker manual removal:

Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windosxp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DisableKeyboard=rundll32.exe keyboard,disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DisableMouse=rundll32.exe mouse,disable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start_Page=[site address]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start_Page=%Windir%\ipnuker.vbs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop=1
HKEY_CLASSES_ROOT\Shell\Shell\Explore\Command\(Default)=C:\Windows\ipnuker.vbs
HKEY_CLASSES_ROOT\txtfile\Shell\Open\Command\(Default)=%System%\wscript.exe
HKEY_CLASSES_ROOT\txtfile\Shell\Print\Command\(Default)=%System%\wscript.exe
HKEY_CLASSES_ROOT\txtfile\Shell\Printto\Command\(Default)=%System%\wscript.exe
HKEY_CLASSES_ROOT\Themefile\Shell\Open\Command\(Default)=%System%\wscript.exe
HKEY_CLASSES_ROOT\Unknown\Shell\Openas\Command\(Default)=%System%\wscript.exe
HKEY_CLASSES_ROOT\VBSFile\Shell\Command\(Default)=%System%\wscript.exe
HKEY_CLASSES_ROOT\VBSFile\Edit\Command\(Default)=%System%\wscript.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner=Ipnuker
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RegisteredOwner=Ipnuker.net
Delete files:
ip.bat, ipuser.bat, ipusercreate.bat, ipnuker.vbs
Misc:
[site address] is an address of a web site on the ipnuker.com domain.

Exact file location:
ip.bat, ipuser.bat, ipusercreate.bat - C:\Windows or C:\Winnt
ipnuker.vbs - C:\mIRC and (or) C:\Windows

Other programs to remove Inker:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 16/09/05
Information updated: 16/09/05

Additional resources related to Inker:

Attention: If you know or you have a website or page about Inker removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Inker parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites:
Related discussions: