WARNING! YOU'RE IN DANGER! hijack window overlapping desktop

Discussion in 'Malware Help (A Specialist Will Reply)' started by alrightgame, Mar 28, 2005.

  1. alrightgame

    alrightgame Private E-2

    WARNING!
    YOU'RE IN DANGER!



    ALL YOU DO WITH COMPUTER IS STORED FOREVER IN YOUR HARD DISK. WHEN YOU VISIT SITES, SEND EMAILS... ALL YOUR ACTIONS ARE LOGGED. AND IT IS IMPOSSIBLE TO REMOVE THEM WITH STANDARD TOOLS. YOUR DATA IS STILL AVAILABLE FOR FORENSICS. AND IN SOME CASES FOR YOUR BOSS, YOUR FRIENDS, YOUR WIFE, YOUR CHILDREN.

    Every site you or somebody or even something, like spyware, opened in your browser, with all images, and all downloaded and maybe later removed movies or mp3 songs - ARE STILL THERE and could broke your life!


    SECURE YOURSELF RIGHT NOW!
    REMOVE ALL SPYWARE FROM YOUR PC!

    Removal instructions


    http://daosearch.com--was being a browser hijack, but one of my virus protection got rid of this.
    The message is a desktop hijack that is overlapping my regular desktop (its a black screen background, which may point to the version of the trojan).

    Message hijack does not appear in safemode, but does appear when I am offline during regular mode.
    I did delete something in the hijackthis log (unfortuanetly I do not remember, just microsoft spyware detected it and it was in hijackthis), so now the page is no longer there, but blank white that flickers, but still shows up overlapping the hijack. The adress in the properties window for the hijack desktop add is file://C:\WINDOWS\Web\desktop.html.

    Yes I have done what the forums said to do :/.
    Attached are two hijackthis logs, one from safemode, and one from regular mode. The first one posted will be the safemode hijackthis and the second will be the regular.

    Any help would be most appreciated.
    Keep this Bumped
     

    Attached Files:

  2. alrightgame

    alrightgame Private E-2

  3. alrightgame

    alrightgame Private E-2

    Oh god now it screwed up my desktop. It double created icons. Also when I try to paste an icon something like this will appear
    Select File Name
    The destination does not support long file names. Please enter a name for this file
    originalC:/documents and Settings....
    to folder:
    New name (box)
    ok cancel
     
  4. alrightgame

    alrightgame Private E-2

    Just created myself a new user. I think the desktop was corrupt. God what a mess though it created. Most if not all of the problem has been taken care of.
     
  5. wizz

    wizz Private First Class

    hey i had the same problem as you have. I just want to know how you solved the problem from duplicating icons on desktop? did the files you had in your desktop disappear?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    After doing ALL of the above if you still have a problem:


    • Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT
    • Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file.
    • Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.
    • Run HijackThis and save your log file.
    • Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post).

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds