TechSpot

Serious troubles with virus & other lovely things

By kyleman
Aug 4, 2006
  1. Hey about a month ago our homepage changed to http://www.syssecuritypage.com/, popups kept coming up, virus alerts wouldnt stop popping up down the bottom. I searched around and found out my computer had
    ismon, ishost, isnotify, issearch, ixt0,1,2,3.dll, alg.dll, winclw32.dll
    and heaps more. I deleted them from system32 and prefetch in windows in safe mode all went well until randomly theyd come back! Ive tried this heaps and everytime i do it i find more bad files. I also got hijackthis and deleted sum bad ones like winlogonnotify and cinomnonm (dont no the spelling) but it wont go away.. McAfee wont help adaware gets nothign.. i had to do it manually:( my dads cracking it and he wants to wipe the comp and start again. Im only 13 and i dont no if its me being dumb or just i got a nasty one here...CAN YOU PLEASE HELP ME?? :mad:
    Ps i think it could be a no-cd crack i download for my gta-sa game but 2 of my friends have the same crack and they dont have it. i think this becuase when it comes back i look at properties on ismon ect. and it says created at when i played it... HELP ME
     
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    Get rid of that no cd crack.

    Download and run these three tools. Follow the instructions for each tool.

    Tool1. Tool2. Tool3.

    Then go and read this thread HERE.

    Post a fresh HJT log into this thread, only after doing the above.

    Regards Howard :wave: :wave:

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. Didou

    Didou Bowtie extraordinair! Posts: 4,274

    & please use proper thread titles from now on.
     
  4. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Heres the HJT log and the SmitfraudFix is under just incase you need it. :D
     
  5. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    You need to run those three tools again. This is because your nasty infection is still there. This is not normal, those tools should kill it.

    Post a fresh HJT log after you`ve run the tools.

    Regards Howard :)
     
  6. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Here it is i think i worked :)
     
  7. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Excellent. Your HJT log is now clean.

    Have HJT fix the following inactive entry.

    Run HJT with no other programmes open.Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O20 - Winlogon Notify: wintfj32 - wintfj32.dll (file missing)

    Click on the fix checked button.

    Close HJT.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  8. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Howard your an absolute ledgend :D
    Thanks so much and keep up the good work
     
  9. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Hey im just checking up 2 see if i need 2 delete anything.:grinthumb
     
  10. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Clean as a whistle mate.

    Regards Howard :)

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  11. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Cheers ;)
    Keep up the good work.
     
  12. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Hey again..recently ive been getting popups all of the same thing..theres about 6 of them and they come up all the time. Just Before one of them couldnt fine the url or something and said like google/creatives/CYBOOT or sumthing.
    I ran those three programs but the popups havnt stopped. Heres the HT log.
    Also the popups all are deluxecommunications which i tried deleting from HT but it came back..
    Atm im running spybot also to get rid of the other stuff.
    -Kyle
     
  13. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    You`ve got one or two nasties on your system.

    Go HERE and follow the instructions exactly.

    Post fresh HJT and Ewido logs, only after doing the above.

    Regards Howard :)

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  14. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Dw about it dude my dad did a system restore without telling me..:stickout:
    Thanks anyway will use next time
     
  15. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Hey.
    I need to be able to delete some files. When i right click on them it only comes up with play, add to playlist in media player, open with and send to.
    It says they are Mpegs. When i click delete nothing happens.
    The file names are also very long.

    Not sure if its doing anything but i want them gone.
    Heres a HJT log.
     
  16. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log looks clean. However, there is new malware that can hide form HijackThis.exe. Go and follow these instructions for renaming HJT and post a fresh HJT log.

    Regards Howard :)

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  17. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Ok done.
    But i want to know how to delete these files. ASAP
     
  18. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    The good news is your HJT log is still clean.

    I suggest you use this utility HERE to try and get rid of those files. It usually works very well.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  19. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Thankyou. I tried just deleting the folder before you suggested this program. Deleting the folder worked fine.
    Thankyou and i will keep it for the future:)
     
  20. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Hey ive had a couple of party poker and "you have malicious software!" popups recently.
    Is my HT log clean?
     
  21. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    ??? Anything?
     
  22. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Sorry, I was no longer subscribed to this thread for some reason, so, I missed it.

    You`re running an outdated version of HJT, see HERE.

    Go to add remove programmes in your control panel and uninstall anything to do with(if there).

    ActivationManager

    Close control panel.

    Reboot your computer and post a fresh HJT log.

    Regards Howard :)

    This thread is for the use of kyleman only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  23. kyleman

    kyleman TS Rookie Topic Starter Posts: 91

    Hey its me yet again. Computer's been kicking out very often recently. At least once an hour. I opened up the case and just secured all the plug ins, made sure it was all connected correctly. Still doing it. Our new crappy bigpond anti-virus mysteriously dissapeared too! I miss mcafee.. could be a virus?
    heres the htj log.
    cheers.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...