We'd like to remind Forumites to please avoid political debate on the Forum. This is to keep it a safe and useful space for MoneySaving discussions. Threads that are - or become - political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
We're aware that dates on the Forum are not currently showing correctly. Please bear with us while we get this fixed, and see Site feedback for updates.

How Do I Get Rid Of Wista For Good

I think I am infected with wista antivirus software.
As my computer settings keep reseting all the time and making duplicate ones.
I have scanned using KIS2009 plus superanti spyware pro plus the malwarebites anti malware free version n nothing.
My computer has slowed down to.
I have ruled all the other things out wat could be wrong with my lap top.

What brought this to my attention is while I ran a scan I noticed a file it was scaning said wista so I googled it then I relised the seriousness but scan didnt detect it as bad spyware it passed it with flying colours.

I need to know if I am infected most probly am with wista.
How to remove this spyware as it is a scam so bad about it I have read.
Please help.

ps.I didnt even buy wista as a product.
pps.I have some idea how it got on my system I have been reading up about it.
:A :A :A :A :A :A :A
Over 1000 pound in debt.
To many red letters.
Welfare Rights helped me out.
Now I pay a little amount each month to clear debt.
So much eaiser the pressure has been taken off me. :A :A :A :A :A :A :A
«1

Comments

  • timbim_2
    timbim_2 Posts: 1,292 Forumite
    1,000 Posts Combo Breaker
    Try the scanners in the stickies at the top of the page. They may bring to light somthing that other scanners missed.
    Ubuntu is an ancient African word, meaning: 'I can't configure Debian'.
  • ucc
    ucc Posts: 8 Forumite
    If I get in to this kind of pickle I end up backing up all my files somewhere safe and then reinstalling Windows - I find it's good to do this from time to time anyway as it always runs much faster afterwards. The only things are a) get backups of everything and b) make sure you have the Windows discs handy. Hope that helps.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    New one on me!

    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    SCAN and post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    :idea:
  • Here my the hijack log.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:25:07, on 26/02/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal
    Running processes:
    C:\windows\System32\smss.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\services.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\svchost.exe
    C:\windows\System32\svchost.exe
    C:\windows\system32\spoolsv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\System Control Manager\MSIService.exe
    C:\Program Files\SRS Labs\WOWHD and TSXT Driver\SRS_PostInstaller.exe
    C:\windows\system32\svchost.exe
    C:\Program Files\UPHClean\uphclean.exe
    C:\windows\Explorer.EXE
    C:\windows\RTHDCPL.EXE
    C:\windows\System32\svchost.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe
    C:\Program Files\LG Software\IP Operator\IP Operator.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\SRS Labs\WOWHD and TSXT Driver\SRSTrayApp.exe
    C:\Program Files\Innovative Solutions\DriverMax\devices.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
    C:\Program Files\lg_swupdate\Gilautouc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\windows\system32\cisvc.exe
    C:\windows\system32\cidaemon.exe
    C:\windows\system32\taskmgr.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    O2 - BHO: IEVkbdBHO - !!59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - !!761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - !!9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\autoupdate.exe" Gilautouc
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
    O4 - HKLM\..\Run: [LG Magnifier] "C:\Program Files\LG Software\LG Magnifier\MagnifyingGlass.exe"
    O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
    O4 - HKLM\..\Run: [IPO3] "C:\Program Files\LG Software\IP Operator\IP Operator.exe" -aUtOsTaRtFrOmReG
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [SRSTrayApp] C:\Program Files\SRS Labs\WOWHD and TSXT Driver\SRSTrayApp.exe
    O4 - HKCU\..\Run: [DriverMax] "C:\Program Files\Innovative Solutions\DriverMax\devices.exe" -agent
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [Rapportexe] "C:\Program Files\Trusteer\Rapport\bin\RapportService.exe" -start -after_boot
    O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
    O9 - Extra button: Web traffic protection statistics - !!1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: !!17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: !!5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: !!8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Micro Star SCM - Unknown owner - C:\Program Files\System Control Manager\MSIService.exe
    O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Program Files\SRS Labs\WOWHD and TSXT Driver\SRS_PostInstaller.exe
    --
    End of file - 6153 bytes
    :A :A :A :A :A :A :A
    Over 1000 pound in debt.
    To many red letters.
    Welfare Rights helped me out.
    Now I pay a little amount each month to clear debt.
    So much eaiser the pressure has been taken off me. :A :A :A :A :A :A :A
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    FIX these ~
    C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
    O4 - HKCU\..\Run: [Rapportexe] "C:\Program Files\Trusteer\Rapport\bin\RapportService.exe" -start -after_boot
    O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\autoupdate.exe" Gilautouc
    O4 - HKLM\..\Run: [IPO3] "C:\Program Files\LG Software\IP Operator\IP Operator.exe" -aUtOsTaRtFrOmReG

    Is Kaspersky upto date?

    Download MALWAREBYTES (Make sure you click 'DOWNLOAD NOW')
    http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
    UPDATE and FULL SCAN
    Post the log here AFTER youve deleted everything it finds

    reboot and run a fresh hijack log
    :idea:
  • I am no computer geek soz if taking a while
    :A :A :A :A :A :A :A
    Over 1000 pound in debt.
    To many red letters.
    Welfare Rights helped me out.
    Now I pay a little amount each month to clear debt.
    So much eaiser the pressure has been taken off me. :A :A :A :A :A :A :A
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    sweet ~ take as long as you like x
    :idea:
  • ucc wrote: »
    If I get in to this kind of pickle I end up backing up all my files somewhere safe and then reinstalling Windows - I find it's good to do this from time to time anyway as it always runs much faster afterwards. The only things are a) get backups of everything and b) make sure you have the Windows discs handy. Hope that helps.

    Yes I would like to do that if only I had a hard drive I have a plain netbook
    :A :A :A :A :A :A :A
    Over 1000 pound in debt.
    To many red letters.
    Welfare Rights helped me out.
    Now I pay a little amount each month to clear debt.
    So much eaiser the pressure has been taken off me. :A :A :A :A :A :A :A
  • I ran a scan with Spy Bot in safemode it found Spy Hunter.I deleted this from my system.I believe that Spy Hunter is a programe Wista advertises.
    So does this mean that I have removed the problem or not?
    :A :A :A :A :A :A :A
    Over 1000 pound in debt.
    To many red letters.
    Welfare Rights helped me out.
    Now I pay a little amount each month to clear debt.
    So much eaiser the pressure has been taken off me. :A :A :A :A :A :A :A
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Impossible to say Sweetie. I tend to run a few different programs and only once theyve ALL come back clean do I feel better about it :p

    Id REALLY suggest a full scan with MALWAREBYTES at the very least
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 348.4K Banking & Borrowing
  • 252.1K Reduce Debt & Boost Income
  • 452.4K Spending & Discounts
  • 241K Work, Benefits & Business
  • 617.3K Mortgages, Homes & Bills
  • 175.7K Life & Family
  • 254.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.