Desktop Issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nook, Jun 27, 2005.

  1. Nook

    Nook Private E-2

    Think I've read everything, might of missed it but I am falling asleep atm.

    At the start of my day my computer was just recked with Spy Sheriff and all this other stuff, so I've been updating and cleaning like crazy.. seems everything is gone except for not being able to change my desktop back to normal. Everything in the Desktop tab is disabled except for 'Customize Desktop' ..

    Any ideas would be greatly appreciated, Thanks,
    Nook
     
  2. Anon-068c403e2d

    Anon-068c403e2d Anonymized

    If you are using windows 2000 or higher and the change wallpaper options are greyed out,try this:
    run>gpedit.msc>navigate to>user configuration>administrative templates>control panel>display>prevent changing wallpaper>make sure it is not 'enable'(keep it not configured).
     
  3. Nook

    Nook Private E-2

    'gpedit.msc' does not work for me.

    My desktop also takes about a minute to fully load to add to the problem =/
     
  4. Anon-068c403e2d

    Anon-068c403e2d Anonymized

    Which os?
    Xp home doesnt have it,I am looking for a registry key.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Did you read any of the numerous SpySherrif threads in here where people should hav e similar issues?
     
  6. Nook

    Nook Private E-2

    Ran

    Code:
     REGEDIT4
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoViewContextMenu"=-
    
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoViewContextMenu"=-
    "NoActiveDesktop"=-
    "ForceActiveDesktopOn"=-
    "NoActiveDesktopChanges"=hex:00,00,00,00
    "NoActiveDesktop"=dword:00000000
    "NoSaveSettings"=dword:00000000
    "ClassicShell"=dword:00000000
    "NoThemesTab"=dword:00000000
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
    "NoChangingWallPaper"=-
    "NoComponents"=-
    "NoAddingComponents"=-
    "NoDeletingComponents"=-
    "NoEditingComponents"=-
    "NoHTMLWallpaper"=-
    
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]
    "ThemeActive"="1"
    "DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
    74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72,00,63,00,65,00,73,00,5c,\
    00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00,75,00,6e,00,61,00,5c,00,\
    6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74,00,79,00,6c,00,65,00,73,\
    00,00,00
    
    Desktop is back, hope my problems are all fixed.
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Nook,

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  8. Nook

    Nook Private E-2

    Fixed the wallpaper problem. Only other thing is my desktop is taking too long to load up.
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01

    O4 - HKLM\..\Run: [Open Service Drivers] opiater.exe
    O4 - HKLM\..\RunServices: [Open Service Drivers] opiater.exe
    O4 - HKCU\..\Run: [Open Service Drivers] opiater.exe
    O4 - HKCU\..\RunServices: [Open Service Drivers] opiater.exe

    O15 - Trusted Zone: http://www.neededware.com
    O15 - Trusted Zone: *.sbcglobal.net
    O15 - Trusted Zone: http://*.sbcglobal.net

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    opiater.exe <-- Search for this file and delete when found!

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  10. Nook

    Nook Private E-2

    Alrighty
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Viewpoint


    After you uninstall the above program, navigate to and delete the following folder:

    C:\Program Files\Viewpoint


    After you have complete the above your HJT log will be clean, are you having any further desktop or any other malware problems?
     
  12. Nook

    Nook Private E-2

    Thank you sir, and I believe that is all my problems.
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  14. Nook

    Nook Private E-2

    Aye, I am currently using..

    Panda Antivirus Titanium (AV, Firewall)
    CCleaner
    Microsoft Windows AntiSpyware
    SpyBot-Search & Destroy
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Good Deal, just make sure you keep them up-to-date and you will be ok.

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds