Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > instb32.exe - Malware?

Reply
Thread Tools Display Modes

instb32.exe - Malware?

 
 
Frank
Guest
Posts: n/a

 
      02-27-2008
Last night i did a windows update to my vista machine. This afternoon,
Threatfire my marware behavior detection program detected "suspicious"
activety. A program called INSTB32.SYS in C:\windows\temp\INSTB32.SYS was
trying to install itself as instb32.exe to the windows system file
C:windows\System32\instb32.exe.

Is either INSTB.SYS or instb.exe a ligitimate windows file? Is this malware.
How come this was not detected with the install if its ligit? I have found
no answers to this so far. I have both files quarenteened until I get an
asnwer.

Sincerly

Frank
 
Reply With Quote
 
 
 
 
PA Bear [MS MVP]
Guest
Posts: n/a

 
      02-28-2008
Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_R...:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/...moving_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/

Frank wrote:
> Last night i did a windows update to my vista machine. This afternoon,
> Threatfire my marware behavior detection program detected "suspicious"
> activety. A program called INSTB32.SYS in C:\windows\temp\INSTB32.SYS was
> trying to install itself as instb32.exe to the windows system file
> C:windows\System32\instb32.exe.
>
> Is either INSTB.SYS or instb.exe a ligitimate windows file? Is this
> malware.
> How come this was not detected with the install if its ligit? I have found
> no answers to this so far. I have both files quarenteened until I get an
> asnwer.
>
> Sincerly
>
> Frank


 
Reply With Quote
 
MowGreen [MVP]
Guest
Posts: n/a

 
      02-28-2008
Did you check the Properties of the suspect file ?
Right click both instb32.exe and instb32.sys then click the Version tab
to see if they are legit are not.
And/or have them scanned at:
http://virusscan.jotti.org/
or
http://www.virustotal.com/

Did you submit the suspect files to Threatfire for analysis ?
Which 'windows update' was installed ?
It would have to be an update to a driver since no security update that
came out on Patch Tuesday contained either of the files you've posted.

MowGreen [MVP 2003-2008]
===============
*-343-* FDNY
Never Forgotten
===============



Frank wrote:

> Last night i did a windows update to my vista machine. This afternoon,
> Threatfire my marware behavior detection program detected "suspicious"
> activety. A program called INSTB32.SYS in C:\windows\temp\INSTB32.SYS was
> trying to install itself as instb32.exe to the windows system file
> C:windows\System32\instb32.exe.
>
> Is either INSTB.SYS or instb.exe a ligitimate windows file? Is this malware.
> How come this was not detected with the install if its ligit? I have found
> no answers to this so far. I have both files quarenteened until I get an
> asnwer.
>
> Sincerly
>
> Frank

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware Zygy Windows Vista Security 14 04-19-2009 02:55 AM
malware ESTEBAN Windows Vista Mail 0 11-30-2008 09:49 AM
Malware estella Windows Vista Security 1 12-14-2007 04:15 PM
malware off manoj jose Windows Vista Security 1 11-19-2007 08:29 PM
Is this Malware B.W. Windows Update 5 11-02-2007 09:55 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59