Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Pending] Instala.php! Argh

[Fixed] Hijackthis! Logs - [Pending] Instala.php! Argh posted in the Security & Safety forums; Hi I am new here so please bare with me. I recentlly tried to download a program that allows you to recored youtube videos. When i did i seemed to ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-27-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 3
spik3yb0i - See this Members User comments on their Profile page
Angry [Pending] Instala.php! Argh

Hi

I am new here so please bare with me.

I recentlly tried to download a program that allows you to recored youtube videos. When i did i seemed to have a virus on my computer. When i turn my PC on, Dreamweaver MX opens up a file called instala.php. This is opened from the System32 folder. Within that folder i have seen Instala.php and instala1.php. I have tried to delete both of these but they come back after a while and everytime i reboot. I get a agressive rate of pop ups from this virus. I have scanned with my norton but that doesnt pick it up. Please help me becasue this is driving me crazy. Thanks


  #2  
Old 02-27-2007
madmonkey's Avatar
Site Manager
My PC
 
Join Date: Oct 2006
Location: South Wales
Posts: 6,171
PC Experience: PC Basket Ball Head!
madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page madmonkey - See this Members User comments on their Profile page
Default

Hello Spik,

Welcome to PCHF!

If you follow PCHF Prework on my signature, and post both Hijack and AVG logs back here, we will get a member of security to check this problem out for you.


__________________

  #3  
Old 02-27-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 3
spik3yb0i - See this Members User comments on their Profile page
Default

i am a bit new to this technical language so can you tell me how this is done please thanks


  #4  
Old 02-27-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 3
spik3yb0i - See this Members User comments on their Profile page
Default

hi ignore the previous message. i have attached my AVG and hijack this logs here. thanks
Attached Files
File Type: txt Report-Scan-20070227-063455.txt (91.4 KB, 2 views)
File Type: log hijackthis.log (10.9 KB, 2 views)


  #5  
Old 02-27-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

First off, welcome to the forum. Now for the worky part.
First, please right-click on My Computer, and choose, Explore. Click on Tools, Folder Options, and then View. Make sure that there is a tic next to Display contents of System Folders, Show Hidden Files and Folders is selected, and Hide known file extensions is not selected. Now close Explorer.
Next, please download from my signature: CCleaner, Housecall, and SpySweeper. Update SpySweeper, and CCleaner.

+++++++++++++++++++++++++++++++++

Run Housecall. Let if fix everything that it finds, and allow it to run a second time. If it gives you the option of saving a log, please do so.
Now boot into Safe Mode. To learn how to do that, go to Getting into Windows Safe Mode.

+++++++++++++++++++++++++++++++++

Run CCleaner, make sure that all options are selected, including Advanced. Answer OK or Yes to all warnings. Click on Analyze, then Run Cleaner. Repeat this until either no further files appear, or the same files reappear and cannot be cleaned. If you have files that cannot be cleaned, navigate to the location, right-click on the file and choose Properties. Click on the Security Tab, and Advanced button. Give yourself full ownership of the file, and then manually delete. If you cannot manually delete any file, please note that to post back here.

+++++++++++++++++++++++++++++++++

Now run Spy Sweeper, under Options, Sweep, make sure that all available options under Custom Sweep are selected. Run a full system scan, and let it quarantine everything that it finds. Make sure to save the log to post back here.
Next run AVG again, Under Scanner, Settings, choose Quarantine under How to act?, choose all available files to scan, and put tics next to all options, also select that it automatically generate a report. Run a full system scan.

+++++++++++++++++++++++++++++++++

While still in safe mode, open hijack this and click ‘perform system scan only’, and place a tick next to the following:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: Littlewoods Casino - {BAA37C20-5000-11DB-B0DE-0800200C9A66} - C:\Documents and Settings\Hung Vi\Desktop\Littlewoods Casino.lnk (file missing)
O9 - Extra 'Tools' menuitem: Littlewoods Casino - {BAA37C20-5000-11DB-B0DE-0800200C9A66} - C:\Documents and Settings\Hung Vi\Desktop\Littlewoods Casino.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Click ‘fix checked’.

+++++++++++++++++++++++++++++++++

Next, navigate to the following folders/files and delete them:

C:\PROGRA~1\PACIFI~1
C:\Documents and Settings\Hung Vi\Desktop\Littlewoods Casino.lnk

+++++++++++++++++++++++++++++++++

Don’t forget to post the following:
1. the Spy Sweeper log
2. The AVG log
3. A New HJT log. You need to run the HJT AFTER all the other fixes have been done, so we can see the changes.

+++++++++++++++++++++++++++++++++

Also, I see you have KEMH.exe and JUAE.exe on your desktop, but I can find no record of them on the web. Do you use these applications? If not, please go to Online malware scan and upload them, and post the results back here.

Thanks, and I look forward to your response.
v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #6  
Old 03-08-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

spik3yb0i, were you able to get all the fixes done?

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #7  
Old 05-15-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

marked as pending.


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 07:54 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top