Alright, I keep getting this little popup deal from my toolbar coming from a little red circle with a white X in the middle of it, that changes to a little earth with the Windows sign over it. It just goes back and forth to that. It also has a little popup that says "Your Computer is Infected!" And then goes on about dangerous malware, or whatever. I had this problem with Spy Sheriff before, and got rid of it using XoftSpy, but its' not working with this. The new problem is Spy Axe, which I seem to have uninstalled using XoftSpy, but the pop up is still coming up, and if you click it it brings up the Spy Axe website.

ALso, since I got rid of Spy Sheriff, whenever my comp starts up a few error messages come up. It seems like it is trying to run something that is no longer there.

Now, honestly, I have really no idea what anything is when it comes to computers. I have googled my problem and it seems that everyone is told to run something called Hijack This, but I cna't find it, don't know what it is, or what it does... I'm really lost here, so any help would be greatly appreciated. This is driving me insane, and all I want to do it throw my computer out the window. Thanks in advance,

joe

Dani AI

Generated

This is a classic rogue "fake AV" situation (SpyAxe/SpySheriff–style): the program shows bogus Windows warnings and links to a scam site, and uninstallers often remove the visible app while leaving services, Run keys, toolbars or browser helper objects behind. That matches ’s report that XoftSpy removed SpySheriff but startup errors remained, and ’s similar symptoms. is also correct that a reputable AV can remove active trojan components — but manual cleanup of leftover startup entries is usually necessary after the scanner finishes.

Practical, order-of-operations cleanup that works reliably:

  • Boot Safe Mode with Networking and run an up-to-date on-demand anti‑malware scan (full system). Quarantine everything the scanner flags.
  • Use msconfig (Startup tab) or the Sysinternals Autoruns utility to inspect and disable suspicious items under Logon, Scheduled Tasks, Services and Browser Helper Objects. Autoruns shows the exact file paths so orphaned entries can be identified.
  • Check and clear browser hijacks: remove unknown toolbars/Add‑ons, reset the homepage, and verify Internet Settings -> LAN Settings to ensure no proxy is set.
  • Inspect these locations for leftover startup references and remove only entries that point to missing/malicious files:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    C:\Windows\System32\drivers\etc\hosts
  • Generate a HijackThis-style log for diagnosis (it’s a diagnostic list, not an automated fixer). Do not use “Fix” items blindly unless confident what each entry does.

Cautions and fallback: back up the registry or create a restore point before manual edits; avoid paying for unknown “removal” software. If multiple system files/services were altered or stability is poor after cleanup, a clean OS reinstall (or image restore) is the safest final fix. Standard next steps for volunteers diagnosing stubborn cases are an updated anti‑malware scan log and a clean HijackThis/Autoruns export so specific leftover entries can be identified.

Recommended Answers

All 3 Replies

Ya I'm having the exact same problem since my brother went on my computer, and I'm positive this isnt legitmate software even though its allegedly coming straight from microsoft.

How do I get rid of this crap?

Ya I'm having the exact same problem since my brother went on my computer, and I'm positive this isnt legitmate software even though its allegedly coming straight from microsoft.

How do I get rid of this crap?

Alright... I was able to get rid of it following these instructions. One of my computer buddies pointed me in this direction. It worked for me, so I hope it works for you! This is the link with the instructions and the file that you need to DL. It's from another forum, so I hope it's not innapropriate to post it here. If it is, sorry about that. But it helped!

http://www.bleepingcomputer.com/forums/topic36868.html

joe

Install McAfee Antivirus it will automatically clean the infection, or use McAfee Stinger and ewido http://www.ewido.net/en/.

I tried to run a downloaded file and with it this virus was also installed. A red mark with white cross appeared in the tray, thankfully i had McAfee installed which automatically said 'a trojan has been found and has been deleted' and the cross disappeared

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.