Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: What is this?  (Read 29384 times)

0 Members and 1 Guest are viewing this topic.

Clippy

  • Guest
Re: What is this?
« Reply #15 on: October 10, 2007, 03:34:10 PM »
I agree with Neljan!

I looked for INSTDRIVER and all I got was stuff about games on the web. Nothing specific about a virus or trojan. Checked Symantec also with no results.

Reformatting requires a complete reinstall of the OS and all programs you use. You would need to backup all of your important files, addresses in your email program and Favorite web pages. That is not for the faint of heart! I have spent hours getting all of my stuff back to something close to what I had before a format!

Download the Hijackthis program and post the results here on the Virus Forum!

Ted

Broni


    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
Re: What is this?
« Reply #16 on: October 10, 2007, 03:45:07 PM »
Quote
InstDriver.zip installed the following programs on our PC:

NTServiceLoader trojan

http://www.siteadvisor.com/sites/rootkit.com/downloads/2712783/
http://vil.nai.com/vil/content/v_116783.htm

GX1_Man

  • Guest
Re: What is this?
« Reply #17 on: October 10, 2007, 06:43:17 PM »
I doubt that any regular here ever has to do that kind of stuff often and people just want an idea of what they can do to avoid reformats and other nasty options.

A good format and reinstall will solve all Windows problems, at least for a while. Sometimes it is much faster than tracking down the issues. I guess it depends what your time is worth and if you have a real Windows CD.   ;)

street1 (RIP)

  • R.I.P.


  • Egghead

  • I Triple Dog Dare You!!! LOL
  • Thanked: 14
    • Obituary
  • Experience: Beginner
  • OS: Windows XP
Re: What is this?
« Reply #18 on: October 11, 2007, 05:27:05 AM »
I doubt that any regular here ever has to do that kind of stuff often and people just want an idea of what they can do to avoid reformats and other nasty options.

A good format and reinstall will solve all Windows problems, at least for a while. Sometimes it is much faster than tracking down the issues. I guess it depends what your time is worth and if you have a real Windows CD.   ;)

and if you have a real Windows CD.   ;)...That's the question.... ;D
Good analysis GX1_Man.
Sorry,The USA has ruined the language The United Kingdom loaned us. We do our best not to type gibberish. I Hope you can forgive us.

casse2go

    Topic Starter


    Hopeful
  • Don't feel bad...I'm lost too.
    Re: What is this?
    « Reply #19 on: October 11, 2007, 08:03:12 AM »
    You guys are being very helpful I'm sure; it's just that I have and have always had this fear factor about downloading things onto this computer. HijackThis has turned up in my Spy-Bots scan as spyware. I'm nailbiting here.

    As for the genuine copy of Windows, mine came as part of their WGA program so if it's invalid, shame on them. Also, AOL backs up Bookmarks, Saved on AOL Mail, and Address Book entries.  I went into Devices manager yesterday and I saw no entry about INSTDRIVE, unless it's in a drop box. I didn't click any applications. Too scared I'd cause another problem. :(
    If you say, "I can", you're right. If you say, "I can't", you're also right.

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: What is this?
    « Reply #20 on: October 11, 2007, 10:25:10 AM »
    Quote
    HijackThis has turned up in my Spy-Bots scan as spyware.
    I can only comment with one word: IMPOSSIBLE!
    HijackThis is worldwide used program, and in many cases is THE ONLY program, that can solve some spyware related problems.

    patio

    • Moderator


    • Genius
    • Maud' Dib
    • Thanked: 1769
      • Yes
    • Experience: Beginner
    • OS: Windows 7
    Re: What is this?
    « Reply #21 on: October 11, 2007, 10:49:02 AM »
    I disagree..
    .it would depend on what Spybot program was run...there are alot of imposters out there.
    casse2go list all the protection programs you currently have and we'll go from there.
    And sorry about the gender confusion.

    p.s. I'm still convinced this file is part of the AOL installation...but better to be safe than sorry.

    patio.
    " Anyone who goes to a psychiatrist should have his head examined. "

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: What is this?
    « Reply #22 on: October 11, 2007, 11:08:57 AM »
    Quote
    .it would depend on what Spybot program was run
    There is only one genuine Spybot, and I assume, that if any computer user wants to run ANY program, he/she better make sure it's a real thing. If someone is careless enough to download, and install anything, that person should rather go back to pencil, and paper, and leave computer alone.
    That's today's computer world reality.

    casse2go

      Topic Starter


      Hopeful
    • Don't feel bad...I'm lost too.
      Re: What is this?
      « Reply #23 on: October 11, 2007, 11:34:13 AM »
      Until last week I had Spybots and lavasoft. Spybots was deleted. So I have lavasoft which always says, "error retrieving Updates". Yet identifies cache MRU's and  Other goodies. Oh yes and the other day it Identified 3 Reg Keys.

      As for the Hijackthis...I read an article yesterday about the newer version of HijackThis, from trendmicro is indeed used a spyware.

      Right now, I' trying to figure if i do indeed have very low memory as my AIM just threw me off twice. Once with it and two windows open, then when it was open by iteslf.
      If you say, "I can", you're right. If you say, "I can't", you're also right.

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: What is this?
      « Reply #24 on: October 11, 2007, 11:59:47 AM »
      Quote
      So I have lavasoft which always says, "error retrieving Updates"
      Which in most cases will indicate, you have some bad guys on your computer, because bad guys will often prevent you from running, or updating good guys (Lavasoft Ad-aware).

      casse2go

        Topic Starter


        Hopeful
      • Don't feel bad...I'm lost too.
        Re: What is this?
        « Reply #25 on: October 11, 2007, 02:11:51 PM »
        I forgot to mention in the previous post that the author of the post about HijackThis being TrendMicro Spyware also said, If you use it use an older version.

        I don't doubt it Broni. My AVG isn't even working and apparently has been since after it was installed. My add/removes says it hasn't worked since 8.31.07. It was installed 8.29.07 and appeared to be scanning to me.


        Here is an article about the newer version of HijackThis.

        HijackThis by TrendMicro: Spyware or Not?
        by nonstopgeek on September 26, 2007 at 5:51 pm · Comments
        Categorized by General, Malware / Related Information

        Earlier this year, my friend Merijn Bellekom sold his HijackThis tool to TrendMicro. Due to other projects, school and ‘real life’, Merijn simply didn’t have have the time to update HijackThis any longer.

        Most of us in the Malware world were quite skeptical of Trend at first. Thankfully, one of their top brass joined the Staff of many forums, and lines of communication were opened. Right off the bat, we were outraged at the “analyze this” function of the new HJT version. While the average user likely thinks the AnalyzeThis button provides helpful information for diagnosing their log, it’s main purpose is to send the HJT log data to Trend Micro. Unfortunately, unless you carefully read the Trend Micro End User License Agreement, you would probably never know that the AnalyzeThis button submits the data from your HijackThis log to Trend Micro for use by them and their partners. Not even in the QuickStart Guide does it explain what this button does.

        We demanded a better alternative. If you feel you need to gather this information, then fine. Gather it. However, you need to make it more obvious what that little button actually does. Show the user in plain sight, using plain text, what exactly you are gathering from them, where it’s going, and what it will be used for. Don’t hide this somewhere in the EULA where no one will ever see it. Put it out there, and let the truth be known.

        I’m personally still not happy with this feature, and believe it isn’t even necessary. However, it’s not likely to go away. Let’s hope that TrendMicro will really listen to those of us who spend countless hours every day helping thousands of people to clean their computers of unwanted Malware. In this instance, we are the voice of the “people”. And we are determined that our voice WILL be heard.

        Tags: merijn, hijackthis, trendmicro, spyware, malware

        « Last Edit: October 11, 2007, 02:22:20 PM by casse2go »
        If you say, "I can", you're right. If you say, "I can't", you're also right.

        patio

        • Moderator


        • Genius
        • Maud' Dib
        • Thanked: 1769
          • Yes
        • Experience: Beginner
        • OS: Windows 7
        Re: What is this?
        « Reply #26 on: October 11, 2007, 02:31:51 PM »
        Broni if you travel to Spybot/Lavasoft's site you will read this is a known issue that they have been working on...apparently the patch/fix is not working for everyone.
        " Anyone who goes to a psychiatrist should have his head examined. "

        patio

        • Moderator


        • Genius
        • Maud' Dib
        • Thanked: 1769
          • Yes
        • Experience: Beginner
        • OS: Windows 7
        Re: What is this?
        « Reply #27 on: October 11, 2007, 02:33:00 PM »
        casse2go list all the protection programs you currently have and we'll go from there.
        And sorry about the gender confusion.

        p.s. I'm still convinced this file is part of the AOL installation...but better to be safe than sorry.

        patio.
        " Anyone who goes to a psychiatrist should have his head examined. "

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: What is this?
        « Reply #28 on: October 11, 2007, 02:48:04 PM »
        Thanks guys for heads up, but I have to add couple of things.

        1. I consider a program, spyware, if it's doing something without my permission.
        When you open HijackThis, you can clearly see this:



        Which means, that by clicking the above button, you VOLUNTARILY  give up your data. I don't see anything malicious hidden here.
        When I read my, or someone's HJT log, I also paste it to my favorite HJT log reading site, just to have general idea what's going on.
        If I wanted to analyze every single entry by hand, it would take at least couple of hours, or more.

        2. Apparently, older version (1.99.1) is not fully compatible with Vista, but version 2.02 is.

        casse2go

          Topic Starter


          Hopeful
        • Don't feel bad...I'm lost too.
          Re: What is this?
          « Reply #29 on: October 11, 2007, 03:00:33 PM »
          All I'm aware of anyway:

          1. AVG
          2. MicroWin Firewall
          3. Lavasoft
          4. I have AOL downloaded but I was told their Security is a different download. Although, I think on AOL's Sign On Page there are indications of spyware security being on. They have this thing called "Zapper" that runs concurrent with the "Welcome Page".
          5. Popup Blocker. Wait, that might be turned off. I was trying to follow     Pogo.Com's instructions for playing the games I'm paying them for. They suggested turning off Blockers. All blocker. But not sure if i have more than one.
          6. AVG Free, doesn't have a Firewall.


          I guess that's it Patio. S'ok about the name, though I though that one was much more clearly female than another one I use. It flatters one of the Fates. :)

          *Back later*

          If you say, "I can", you're right. If you say, "I can't", you're also right.