Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Help needed as soon as possible (instala.php)

[Fixed] Hijackthis! Logs - [Fixed] Help needed as soon as possible (instala.php) posted in the Security & Safety forums; A few days ago my computer began acting wierd, it is evident that there is some virus installed on my computer. When i start the computer it has begun to ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-15-2007
Bronze Member
 
Join Date: Oct 2006
Posts: 39
skt4dc8 - See this Members User comments on their Profile page
Send a message via ICQ to skt4dc8 Send a message via AIM to skt4dc8
Default [Fixed] Help needed as soon as possible (instala.php)

A few days ago my computer began acting wierd, it is evident that there is some virus installed on my computer. When i start the computer it has begun to say D:/WINDOWS/SYSTEM32/INSTALA.PHP does not have a folder or a function please go to control panel and fix it. Well everytime i started internet explorer, it would be normal, than would have about 6 pop ups that would come on, i would close them, it would happen again, i have never in the past had one popup. It continued to do the same thing, and i also noticed icons on my desktop that had no picture, but seemed to be an application, when i clicked it it did nothing. so i deleted those, figuring that it was a virus i made internet explorer inaccessable from the set defaults tab in control panel, and now use firefox, but when i need to open something that requires internet explorer, or use active x i use internet explorer, and i get pop ups. so many popups. most from popuptraffic.com, i even went into system 32 and deleted instala.php and instala 1.php but something is still present in the computer. PLEASE HELP.


  #2  
Old 02-15-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

Hi sktfdc8, and welcome to pchf. First, click the prework link in my signature, follow all the steps, and post back with BOTH the hjt log and the AVG log. That way we can see what we are dealing with.

Thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #3  
Old 02-15-2007
Bronze Member
 
Join Date: Oct 2006
Posts: 39
skt4dc8 - See this Members User comments on their Profile page
Send a message via ICQ to skt4dc8 Send a message via AIM to skt4dc8
Default

ok i think this is what you wanted:

this is my hijack this?

Edit: Please ONLY post HJT and spyware logs as attachments. Thanks
Upgrader764
Attached Files
File Type: txt hjt.txt (8.6 KB, 2 views)



Last edited by ladygreenwitch; 02-19-2007 at 07:29 AM.
  #4  
Old 02-15-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

hoo boy, you've got some fun ones in there. Two questions:

1. did you run ATF?
2. Did you run AVG, and if so, can you please attach the logfile it generated? If you are confused, just click the link in my signature marked prework and follow all the steps there; that will leave you with both logs, and ATF having been run as well.

I have class tonight, so I may not get a chance to respond before tomorrow morning, but there is always someone on duty, so hopefully they can answer in my stead. If not, I will be answering you about 7 CST tomorrow a.m.

Thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #5  
Old 02-16-2007
Bronze Member
 
Join Date: Oct 2006
Posts: 39
skt4dc8 - See this Members User comments on their Profile page
Send a message via ICQ to skt4dc8 Send a message via AIM to skt4dc8
Default

well avg i ran the free trial version and it was scanning but saaid it restarted, since the problem is in systnem 32 i decided i was gonna scan there, but before i could it had spotted something as a backdoor in system 32, but i will scan and post

so here is the agv for system 32 i dont think i need to make it an attatchment because its small tell me if i should in the future:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 6:06:57 PM 2/15/2007

+ Scan result:



D:\WINDOWS\system32\__delete_on_reboot__3_7_._e_x_ e_ -> Backdoor.Small.ml.1 : No action taken.
D:\WINDOWS\system32\96.exe -> Downloader.Obfuscated.bg : No action taken.
D:\WINDOWS\system32\xrun.exe -> Downloader.Obfuscated.bg : No action taken.


::Report end

Also if memory serves (this started a week ago) i believe it started when i downloaded a tool called Youtube Downloader, but that might be a coincidence because this looked totally safe, and legit, and i uninstalled it and the virus is still present.





Last edited by skt4dc8; 02-16-2007 at 12:13 AM.
  #6  
Old 02-16-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,672
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

Originally Posted by skt4dc8
saaid it restarted
what do you mean here? It just restarted on it's own? Something probably didn't like it too much. Let's try another one:

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended (if available otherwise Standard)
    • Scan Options:
    • Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information, WITH A NEW HJT LOG, in your next post.

Thanks,

v


__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

  #7  
Old 02-16-2007
Bronze Member
 
Join Date: Oct 2006
Posts: 39
skt4dc8 - See this Members User comments on their Profile page
Send a message via ICQ to skt4dc8 Send a message via AIM to skt4dc8
Default

your link doesnt work- the scan i did of system 32 picked up 3 things to be worried about ^above, i will try scanning the whole thing again and get back to you right away,
Dont bother saying thankyou you have done more than i have asked i should be thanking you

ill google for kapersky



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:21 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top