Spyware, red X on bottom right corner

Status
Not open for further replies.

xplicitvio

Beta member
Messages
3
Hi Everyone,

I have a some spyware on my computer. There is a red circle with a white x on the bottom right corner of my screen. Due to this spyware I cant open my Limewire. I cant get into my music files.
When I try this window with nothing but a yellow triangle with an
exclamation mark comes up. I click OK on it and it restarts my computer. Also, somethimes on my explorer there is no tool bar.
I can only the the ADDRESS bar. I have ran spybot and adware
during safemode, but it does nothing. Anyone have any solution?
Feedback will be very appreciated. THANKS!

by the way, Here is my HIJACKTHIS log

Logfile of HijackThis v1.99.1
Scan saved at 9:50:19 PM, on 5/24/2006
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINNT\loadqm.exe
C:\WINNT\System32\0mcamcap.exe
C:\WINNT\System32\jsssvc.exe
C:\Program Files\AIM\aim.exe
C:\Windows\xpupdate.exe
C:\WINNT\System32\vxgame6.exe3072.exe
C:\WINNT\System32\taskdir~.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\jeffrey\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Child Protector] C:\Program Files\Child Protector\winlogin.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [0mcamcap] C:\WINNT\System32\0mcamcap.exe
O4 - HKLM\..\Run: [`^aS`\OVNQI`WaKTKULP] C:\WINNT\System32\gfgayb.exe
O4 - HKLM\..\Run: [jssvc23] jsssvc.exe
O4 - HKLM\..\Run: [dmkjq.exe] C:\WINNT\System32\dmkjq.exe
O4 - HKLM\..\RunServices: [`^aS`\OVNQI`WaKTKULP] C:\WINNT\System32\gfgayb.exe
O4 - HKLM\..\RunServices: [`^aS`\OVNQI`WaKTKULP] C:\WINNT\System32\gfgayb.exe
O4 - HKLM\..\RunServices: [jssvc23] jsssvc.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [0mcamcap] C:\WINNT\System32\0mcamcap.exe
O4 - HKCU\..\Run: [WinMedia] C:\WINNT\System32\vxgame6.exe3072.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users.WINNT\Documents\Settings\20242402.dll
O20 - Winlogon Notify: twpR32 - C:\WINNT\SYSTEM32\twpR32.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe



THANK YOU!
 
First thing: Update Windows.
You are running Windows 2000, SP1. Windows 2000 SP4 is available from Windows Update.
Alternatively, you could download SP4 from here:http://www.softwarepatch.com/windows/windows2000sp4.html

In Hijackthis, remove these entries:

O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe

O4 - HKLM\..\Run: [dmkjq.exe] C:\WINNT\System32\dmkjq.exe

R3 - Default URLSearchHook is missing

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

C:\Windows\xpupdate.exe



Also, you have NO antivirus installed. This makes your system wide open to attacks from viruses. Please install an antivirus, there are lots of freebies out there:

Avast
AVG
AntiVir

You have to Firewall installed. This makes your system easy to hack into, and you could lose files, have settings changed, etc. Again, lots of freebies out there:

Zone Alarm Free
Kerio Free Firewall
Outpost Free Firewall

You have no Anti-spyware software installed. I highly recommend using Spybot, since it has the best detection rate.

Also check out Microbell's 5-step process:


MicroBell will check this soon, but in the meantime, remove those entires, install antivirus and firewall of your choice, and wait!
 
WOW, I deleted those entries from my computer and the red x
is gone. However Instead of there being a wallpaper on ym desktop I see my web browser on half of my screen, on the other half I see all black and it says YOUR COMPUTER IS IN DANGER.
I still cant open my LimeWire it shuts of my computer is I do. I tried installing the SP4 but it says, "Setup could not verify the integrity of the file Update.inf. Make sure the Cryptographic service is running on this computer." Please advise.
Thank You!
 
Hey guys. I tried repairing windows. MY desktop still says your computer is infected. And my computer shuts down when I try to open limewire or get into my musci files. Help?
 
Right-click on My Computer, click Properties. Click on the Advanced tab, and click Startup and Recovery Settings. Uncheck "automatically restart".
 
Status
Not open for further replies.
Back
Top Bottom