Desktop Hijack still here

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by chad209, Apr 15, 2005.

  1. chad209

    chad209 Private E-2

    I ran just about all spyware tools and also the fixdesktop.zip file on this site but no luck getting rid of the Warning you have spyware on your PC desktop.

    The location being called on for the desktop is:

    C:\WINDOWS\Web\desktop.html

    I need to get it back to call on the original location. For now I have made a blank desktop.html file so I dont have to see their advertisement.

    I also have a yellow triangle icon next to the clock on bottom with exclamation point in it...that occasionaly pops a box up telling me I have spyware on my PC then pops up a link page.

    I have the latest HJT but I dont see anything in there that could be a problem...

    What next???

    Anyone know how to fix it so it doesnt call on C:\WINDOWS\Web\desktop.html for my desktop anymore?

    Thanks

    Chad
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you do the below:

    Fixing Locked Desktop
    Right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.
     
  3. chad209

    chad209 Private E-2

    Is there another way to get to the desktop options?

    If I right click on desktop I get the properties of the current hijacked desktop...its a webpage. But if I move my mouse to the edge of screen I can get the regular popup box but it doesnt have desktop options in it...only screensaver and settings...

    Even if I go to control panel/display it doesnt have the desktop option...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Click Start and select Control Panel then select Display and then the Desktop tab.
     
  5. chad209

    chad209 Private E-2

    Even if I go to control panel/display it doesnt have the desktop option...Only screensaver and settings.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. chad209

    chad209 Private E-2

    Im on XP.

    I went into rededit and followed what I saw on post 76 but none of those files were there.

    On the one:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

    It says I should have "NoDriveTypeAutoRun" but thats not there..if that matters.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not related to your problem. Here is what the registry key relates too, see:
    http://www.microsoft.com/resources/documentation/Windows/2000/server/reskit/en-us/Default.asp?url=/resources/documentation/Windows/2000/server/reskit/en-us/regentry/93502.asp

    Please follow the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  9. chad209

    chad209 Private E-2

    Heres my HJT log.
     

    Attached Files:

  10. chad209

    chad209 Private E-2

    Well something called browser helper appeared in my add/remove programs that I didnt see before. I unistalled it and now it does not call on C:\WINDOWS\Web\desktop.html for my desktop...

    So I got rid of it being a webpage. Its just plain black now.

    But now when I right click, same problem, it does not give a Desktop tab. Only Screensaver and Settings.

    So it appears the spyware is gone but now I have to try to figure out how to get that Desktop tab back so I can change my desktop.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that HJT log from normal boot mode or safe mode?

    Why are you running without an antivirus application, without a spyware blocker, and don't believe the firewall you are using (BlackIce) is very good from reports I have heard (but I have no first hand info).

    You have some problems we need to fix. I'll be back in a few minutes with a fix.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still here? I need to know if that log was from safe mode or normal boot mode?

    Also, please run Windows Explorer and located the file: c:\windows\system32\flsmngr.dll
    Then right click on it and select Properties. Then select the Version tab.
    Now go thru the Item name list and get information about this file. Get company information at a minimum.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay will post an attempted fix but I needed my other questions answered. So let's see what happens while trying the below. Make sure you follow these steps exactly.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden & system files is enabled (per the tutorial).

    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINDOWS\System32\spoolsrv32.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\spoolsrv32.exe
    C:\WINDOWS\System32\srpcsrv32.dll
    C:\WINDOWS\System32\txfdb32.dll
    C:\WINDOWS\Web\desktop.html

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  14. chad209

    chad209 Private E-2

    normal boot mode
     
  15. chad209

    chad209 Private E-2

    Theres no info about it accept Application Extension.
     
  16. chad209

    chad209 Private E-2

    I will do the steps you gave in a little while. I have to get offline for awhile. Thanks much!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you come back, also tell me the size of that c:\windows\system32\flsmngr.dll

    And do you know how to use WinZip to create ZIP files?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds