Help 911

Discussion in 'Malware Help (A Specialist Will Reply)' started by GI Joe, Mar 15, 2005.

  1. GI Joe

    GI Joe Private E-2

    I am having the hardest time trying to get rid of spyware . I already

    1. Disabled system restore
    2. disabled Network Security service and Workstation Netlogon
    3. Enabled viewing of hidden files
    4. Created a separate spyware tools file and downloaded :
    Spybot Search and Destroy , Spyblaster , McAfee Avert Stinger , about buster , and Ad Aware SE.
    Ran all like 12 times
    Ran Online virus scan at Trend Micro Free

    Downloaded Firefox . Tried to remove Internet explorer got rid of a few components but it wont totally remove . I tried to delete a few other internet components but it sends a prompt saying " cannot delete" with a red X.
    How do I get rid of that.
    I also have this black page over my desktops wallpaper that i didnt put there it wont move. it says


    WARNING!
    YOU'RE IN DANGER!
    ALL YOU DO WITH COMPUTER IS STORED FOREVER IN YOUR HARD DISK. WHEN YOU VISIT SITES, SEND EMAILS... ALL YOUR ACTIONS ARE LOGGED. AND IT IS IMPOSSIBLE TO REMOVE THEM WITH STANDARD TOOLS. YOUR DATA IS STILL AVAILABLE FOR FORENSICS. AND IN SOME CASES FOR YOUR BOSS, YOUR FRIENDS, YOUR WIFE, YOUR CHILDREN.

    Every site you or somebody or even something, like spyware, opened in your browser, with all images, and all downloaded and maybe later removed movies or mp3 songs - ARE STILL THERE and could broke your life!


    SECURE YOURSELF RIGHT NOW!
    REMOVE ALL SPYWARE FROM YOUR PC!

    I click on it and it sends another message from internet explorer to pay 49.95 to have it removed.

    How do i sue for this . LOL . they infect my computer and then suggest i pay them to remove it.

    How do I remove this . I am poor I cant afford no 49.95 when I already have
    spyblaster , spybot , and ad-aware se , mcfee stinger , and about buster.

    please help me!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENTto your next message. (Do NOT copy/paste the log into your post).
     
  3. GI Joe

    GI Joe Private E-2

    Edit by chaslang: Inline log attached
     
    Last edited: Sep 13, 2006
  4. GI Joe

    GI Joe Private E-2

    Sorry didnt see post as an attachment
     
  5. GI Joe

    GI Joe Private E-2

    Okay I found with Avast 3 trojan horses and then downloaded the avast cleaner tool and now i am trojan free. Re ran the scan again and I am at 0 infections. So I come to the conclusion that Norton Antivirus wasnt doing crap but taking up space. And I had succesfully gotten rid of the www.search , search 2000 , and other wierd spyware items i had . Deleted 1119 ads using ad-aware se. The only thing is removing the black page blocking my desktop wallpaper and the rest of the components of IE.
    Thanks majorgeeks!
    Any Ideas how to get rid of the 2 other items ? email me if you can. Marriedmcginnis@aol.com
    P.s.
    any of you geeks single ? LOL .
     
  6. GI Joe

    GI Joe Private E-2

    Female 24 in california
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also forgot to extract HijackThis from the ZIP file and to put it in the folder requested. You are running it from the ZIP file (see below). You will not get any backups this way.

    C:\Documents and Settings\sean mcginnis\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After correcting the problem with how and where you are running HijackThis, procede with the below.

    Look in Add/Remove programs for uninstalls to the below and uninstall if found:
    MyWay or MySearch or MySearchBar
    iMesh
    Toolbar
    WinTools
    Spyware Begone

    Are the below two lines for SkateTycoon valid?
    C:\DOWNLO~1\SKATET~1.EXE
    O4 - HKCU\..\Run: [SkateTycoon2004.exe] C:\DOWNLO~1\SKATET~1.EXE /r

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\SEANMC~1\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {00000000-0000-0000-0000-000000002230} - (no file)
    O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll
    O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
    O2 - BHO: (no name) - {11B761D4-4B69-4531-BC66-E07526E40FBC} - C:\WINDOWS\System32\beip.dll (file missing)
    O2 - BHO: (no name) - {2E98D047-2181-4852-8A95-B0C5259897FC} - C:\Program Files\CSBB\CSBB.dll (file missing)
    O2 - BHO: (no name) - {422008EE-AF7E-4953-BED8-D9B551FA8375} - C:\Program Files\CSBB\CSBB.dll (file missing)
    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - (no file)
    O2 - BHO: (no name) - {5B3CAEA4-ED3A-408B-B0D4-CFBA1C62B021} - C:\Program Files\CSBB\CSBB.dll (file missing)
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
    O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
    O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
    O2 - BHO: (no name) - {9EAC0102-5E61-2312-BC2D-4D54434D5443} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-7173706D1316} - C:\WINDOWS\System32\spm1316.dll (file missing)
    O2 - BHO: (no name) - {CF021F40-3E14-23A5-CBA2-717765721316} - (no file)
    O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-717765723548} - C:\WINDOWS\System32\wer3548.dll
    O4 - HKLM\..\Run: [CSV7P26] C:\Program Files\CSBB\CSV7P26.exe
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O4 - HKLM\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe
    O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
    O4 - HKCU\..\RunOnce: [Local runole service] C:\WINDOWS\System32\srvc32.exe

    Note it's up to you, but BigFix is a resource hog. You should only run it when needed and not auto load like below at startup.
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxresearch.com/Preloader.dll
    O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://greg-tut.com/G7/chm10.chm::/ieloader.exe
    O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
    O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovi...ffiliate=BRANDY
    O16 - DPF: {6EC42D96-6DFB-7220-7848-46EB49286F97} - http://67.19.99.158/1/rdgUS871.exe
    O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} -
    O16 - DPF: {7EB15626-CB8E-4174-8A72-C055B12B4310} (CQD2Loader Object) - http://smartdownloader.com/installer.dll
    O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} -
    O16 - DPF: {9EAC0186-5F5A-4362-B120-15C312CE012D} - http://www.awmdabest.com/cabl/379/tb.cab
    O16 - DPF: {AD688740-5246-40C3-AF27-090006046834} - http://www.xpehbam.biz/z/load.exe
    O18 - Filter: text/html - {18876288-BC57-4DA1-889D-A9B6D22D4A21} - C:\WINDOWS\System32\beip.dll
    O18 - Filter: text/plain - {18876288-BC57-4DA1-889D-A9B6D22D4A21} - C:\WINDOWS\System32\beip.dll

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Program Files\Toolbar <--- the whole folder
    C:\Program Files\iMesh <--- the whole folder
    C:\Program Files\MySearch <--- the whole folder
    C:\Program Files\CSBB <--- the whole folder
    c:\freescan <--- the whole folder
    C:\Program Files\Common Files\WinTools <--- the whole folder
    C:\Program Files\PartyPoker <--- the whole folder
    C:\DOCUME~1\SEANMC~1\LOCALS~1\Temp\sp.html
    C:\WINDOWS\System32\wer3548.dll
    C:\WINDOWS\System32\spoolsrv32.exe
    C:\WINDOWS\System32\srvc32.exe
    C:\WINDOWS\System32\beip.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.


    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. GI Joe

    GI Joe Private E-2

    I did everything that you listed to do and here is my hijackthis logfile see attachment
     
    Last edited: Sep 13, 2006
  10. GI Joe

    GI Joe Private E-2

    I still cant get rid of the black page blocking my destop wallpaper. Something has been eating at files cause my XP system calculator is missing and all the XP games are missing.

    What do I need to do.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please see message #2 and #7. You still have HJT running from the ZIP file

    C:\Documents and Settings\sean mcginnis\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\hijackthis.exe

    Unless you install it as I requested we cannot continue. I do not want to make changes when we are not getting any backups. Please address this now and post a new HJT log when you have.

    Just incase your problem is that you do not know how to do that, follow the steps below.

    To get hijackthis.exe extracted from the ZIP File into the location we requested do the following.
    The below will work for WinXP based system since it can deal with ZIP files.
    You need to create the C:\Program Files\HJT folder. Do the following:
    - Click START and select Explore.
    - Select the drive where Windows is installed (normally drive C)
    - Navigate to the C:\Program Files folder and select it.
    - Now click the on the top menu where it says File and then select New.
    - Then select Folder
    - A new folder is created and highlighted.
    - Just type HJT to overwrite the default name (New Folder)

    To extract hijackthis.exe:
    - locate the HijackThis.zip file you downloaded and right click on it
    - Select Extract All and click Next
    - Browse your way to the C:\Program Files\HJT folder created above
    - Select the folder and click Next
     
  12. GI Joe

    GI Joe Private E-2

    Here I had placed it into a New folder by itself and then ran hijackthis again so here is another log . Hopefully this ones right.

    Let me know if I had did this one right. I had gone into the file where it was and created a new file for it now its a system file it has the gear symbol next to it.




    And I still need help to remove this black thing covering my destop wallpaper and the little triangle that keeps blinking spyware you are in danger install spyware software . But the thing it I have spyblaster . Is there a better progam I can install that would get those to disappear? Please if you can email me and let me know I have been checking back 3 or 5 times a day trying to seriously destroy this crap on my beloved pc. Marriedmcginnis@aol.com
     
    Last edited: Sep 13, 2006
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You need to follow my steps! You are double click on the HijackThis.Zip file and then running the EXE. You need to take the EXE out of the ZIP file (extract it) and put it in the folder I requested and then run it from there.

    No more red colors please! Hard on the eyes reading that much red.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this for your Desktop problem:


    Right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also not you should not be putting HJT logs into an HTML format. Just save the logs from HJT do not manipulate them.

    Just follow my steps I gave you on extracting the hijackthis.exe file! Those steps are pretty straight forward. If you still cannot get it done correctly (and you should be able to tell that yourself just by looking at the log to see where hijackthis.exe is running from) then just procede with the cleanup steps I gave you below. You must make sure you follow those steps properly!

    Also uninstall the stuff I requested earlier and answer questions.

    What is SkateTycoon?
    C:\DOWNLO~1\SKATET~1.EXE
    O4 - HKCU\..\Run: [SkateTycoon2004.exe] C:\DOWNLO~1\SKATET~1.EXE /r
     
    Last edited: Mar 16, 2005
  16. GI Joe

    GI Joe Private E-2

    I have no clue what skate tycoon . I did already go through and deleted imesh , freescan , i deleted skate tycoon part of it the other file wont delete I get a prompt with a red X , I deleted party poker , tool bar which toolbars i found 36 files that had toolbar . CSBB I ran that in a search it says cant find it . What else should be deleted how do you remove files that sends prompts with a red X saying it cant be deleted.
     
  17. GI Joe

    GI Joe Private E-2

    C:\Program Files\MySearch <--- the whole folder
    C:\Program Files\CSBB <--- the whole folder
    C:\Program Files\Common Files\WinTools
    C:\DOCUME~1\SEANMC~1\LOCALS~1\Temp\sp.html
    C:\WINDOWS\System32\wer3548.dll
    C:\WINDOWS\System32\spoolsrv32.exe
    C:\WINDOWS\System32\srvc32.exe
    C:\WINDOWS\System32\beip.dll
    The rest of these I cant find.
     
  18. GI Joe

    GI Joe Private E-2

    Here is another logfile I did follow the steps to create a new file .
     
    Last edited: Sep 13, 2006
  19. GI Joe

    GI Joe Private E-2

    Here is a second after I had deleted a few things .
     
    Last edited: Sep 13, 2006
  20. GI Joe

    GI Joe Private E-2

    I tried right click on the desktop it brings up a window and it says with a little picture of a paper with a globe on it unavailable it has nothing but a general tab and only one page it also says file protocol , html document , connection not encrypted , address file //c:/windows/web/desktop.html {url} 1523 bytes , created 3/13/2005 and certificates . Click on certificates and it brings up a a prompt saying it does not have a security certificate.
    what do you think? This desktop thing could be?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you completed all the steps in message #18? It does not look like it. I still see the items I wanted you to fix with HJT there.
     
  22. GI Joe

    GI Joe Private E-2

    Here I went through and fixed alot more items and ran hijackthis and ccleaner and sybot and adware like 12 times
     
    Last edited: Sep 13, 2006
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  24. GI Joe

    GI Joe Private E-2

    Everything seems to be ok except the thing on my desktop I called a computer guy from a computer repair he said to install webroot spysweeper and it should get rid of the warning on my desktop oh when i click on the black thing on my desktop it brings up microsoft internet explorer then they try to sell me something to remove it . so how do i remove this?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try doing a file search for a file named desktop.html

    Let me know if you find it and where.


    Also try doing what I gave you in message #14 after booting to safe mode.
     
  26. GI Joe

    GI Joe Private E-2

    I found 2 desktop.html one with IE icon and One with firefox icon. I tried to place them in the recycle bin but the one with IE icon disappeared it is not in the place where it was and its not in the recycle bin. COuld this be a trojan horse. The one guy i talked to he said he had heard of it before the screen theing i called emachine but they guy said he knew but i had to pay him 20 bucks an increment to tell me.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I said was too look for the file and to tell where you found it?

    Was it named exactly desktop.html? Where was it located?

    Do you still have a problem?

    If so, did you do what I asked in safe mode?
     
  28. GI Joe

    GI Joe Private E-2

    it is in c:/windows/web the other i dont know now it moved when i find that i will let you know that one too
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you rebooted since doing this with desktop.html? If not, reboot and see what happens.
     
  30. GI Joe

    GI Joe Private E-2

    One is located had a firefox icon C:/windows/web the other i found had a IE icon and it was located at my computer. I tried earlier to place both in the recycle bin .The one with the firefox icon went in there but not the one with the IE icon. I still had the search page opened it showed the one with firefox icon it was in the recycle bin where I had put it and the other wasnt there to be found . I did it again to find desktop.html and it did not bring uop the IE icon. When I rebooted the computer IE was in the same spot.
    Is it normal for a program to move ? When you try to delete it.
     
  31. GI Joe

    GI Joe Private E-2

    Yes , I have done everything you have had mentioned.
     
  32. GI Joe

    GI Joe Private E-2

    I found a third located C:/ douments and settings/se
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean it was in My Computer? That is not a folder. Where was it located? What was the complete path to the file?

    If one had a FireFox icon and one had an IE icon then you did not find two files named desktop.html. What every is the default browser on your system would determine the icon for the file. So what was the exact name of the file you deleted. Was it EXACTLY "desktop.html" ? Are you sure you have enable viewing of all file type extensions?

    What do you mean "When I rebooted the computer IE was in the same spot"
    IE should always be in the same spot.

    What program moved? Are you talking about IE? You just said it was in the same spot.
    If you are referring to desktop.html, it is not a program. And if you mean desktop.html came back, where is located. Provide the full path. Make sure it is really desktop.html exactly letter for letter (no additional letters or different letters).
     
  34. GI Joe

    GI Joe Private E-2

    It says mycomputer thats what it says when i right click on the icon it says go to location of file and it comes up at the top of the page mycomputer
     
  35. GI Joe

    GI Joe Private E-2

    when i rebooted the comp I went backl to the windows search to find it again it was in the same location it was when i searched it the first time. Yes they both state desktop.html. but they all three of them have different icons.
     
  36. GI Joe

    GI Joe Private E-2

    I also found these in my computer using a online scan by spysweeper
    # CnsMin
    # TopConverting Downloader
    # Trojan-Clicker-Spyre
    # 7adpower
    # CasinoToolbar
    # CoolWebSearch (CWS)
    # CWS-AboutBlank
    # 180search Assistant
    # PurityScan
    # Tubby Toolbar
    # WebSearch Toolbar
    # Atwola Cookie
     
  37. GI Joe

    GI Joe Private E-2

    Okay I am now downloading spysweeper . I will let you know if it works here to remove these . The guy at the computer store said it should work. to get rid of the problems and if it doesnt I will totally delete my hard drive and restart.
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    SpySweeper is a good program and we have it here on MGs for download. It is not freeware. It will let you get one free database update and it will fix problems. But it is only a trial version. Most of what SpySweeper is finding is left over registry keys not totally cleaned up by removing programs or using other scanners. Most are probably harmless but is does not hurt to have them fixed.

    You could have tried MS Antispyware too for free.

    Please check the following (and make sure you tell me if you had each of these set as indicated):
    Click Start.
    Select Explore
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.

    I still don't understand where you are finding the desktop.html file.
    If you do a windows search and after finding the files, click View and select Details. There should be a column labeled In Folder. What does that say? That's the path to the file. Also what exactly appears in the name column?
     
  39. GI Joe

    GI Joe Private E-2

    They were both unchecked. I did however download Webroot Spysweeper and it did alot of damage. I ran spybot and for first time spybot did not find anything to report.
    But Spysweeper did find 3 types of the trojan horse virus . It is strang though they had found them on the first scan the one at the website prior to me downloading the spysweeper . Then I run it it finds it . I run it again and it says nothing about the trojan so I am guessing it did something to it. Along with Avast yesterday it located a trojan horse virus . Then I ran the scan again and nothing . Then earlier today while I allowed the computer to idle while i made dinner the alarm went off saying virus detected. but what does the program do to them . I am hoping that is the last i hear of it . and a new thing when i open aol up before i even connect a window on my taskbar comes up with a picture of a folder that says HI. I click on it and it went. I have seen it more than once but do not know what it is . It doesnt open or nothing it just stays on the taskbar. what can this be I run a search for HI and find nothing.
     
  40. GI Joe

    GI Joe Private E-2

    Been messing with this dam thing on the desktop . I did learn in the web folder there was a desktop.html. I put that into the trash can. then deleted it. I find out i right click and it has view source so i clicked on that and it brought up a notebook pad with the writing from the desktop covering i put save and i opened web file again and erased that too then screwed around with display touching every button . Then i learned I could move the thing cause i saw a crack of a very very line from the other background. i found an x and a ^ at both ends i tried to click on them but it wouldnt go anywhere. just like move kinda like drag along but wont go. then i went actually forgot what i clicked somthing in display that i hit i think it was when i kept changing backgrounds and settings and apply it turned bright white. and the icon was gone and the message was gone . instead was a white screen.
    i quickly thought to restart to see if it would be there still and it was back like it hadnt gone anywhere. I went through messed around some more got it to turn white again contact aol they had me take a screen shot which i never knew i could do that . all they tell me is crap i already knew.
    I am just going off i am FRUSTRATED!!!!
    Here take a gander at my lovely picture look past the spyware window i was running when i took the screen shot. NOW you might want to put on sun glasses its BRIGHT WHITE , lol
     
    Last edited: Sep 13, 2006
  41. GI Joe

    GI Joe Private E-2

    Yes thats my screen as it is there is in fact backgound underneath it . NOt A joke.
    You now see what i have been looking at for an hour tommorrow when i restart it i will send you another of the black screen ( if it comes back <fingers crossed it be gone>).
    But look closely and you can see in my tray a yellow triangle with a ! in it thats the little icon isnt it so cute . (NOT)
     
  42. GI Joe

    GI Joe Private E-2

    P.s how do you get rid of icons in the tray? can get to properties is there a way to delete them . I went to the properties and it does show that one with no title.
     
  43. GI Joe

    GI Joe Private E-2

    Screen shot 2

    In this one I took the taskbar and played with it dragging it all the way up to midhalf center and let it stay there for 2 sec and then drag it down really fast just to catch the bottom half of what the desktop wallpaper is . I have to do it superfast or it will quickly roll back over.
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post a current HJT log. Also right click on the yellow icon in your tray. Can you get an info on what it is or who it belongs to that way? Do any options appear and what do they show?

    Click Start, select Control Panel, select Display. In the Display Properties window select the Desktop tab. For Background scroll up and choose none. Then click the Customize Desktop button. In the next window that comes up select the Web tab. Make sure at the bottom of the window that the option to Lock desktop items is not checked. Then in the part of the window under Web pages: select and delete all items that are in there except My Current Home Page. Then make sure the last one is not checked. Now click OK. Then in the Display Properties window click Apply and then OK.

    Did that work? Any problems? Make sure you clearly explain any problems you have.

    What did you mean when you said
    What did it break?
     
  45. GI Joe

    GI Joe Private E-2


    What I meant by a lot of damage was a figure of speach it destroyed the rest of the spyware that the other software ive installed didnt pick up . All the scans so far says 0 I ran aol spy and it got nothing ran ad aware , spybot says everythings cleaned .
     
  46. GI Joe

    GI Joe Private E-2

    THe icon today isnt showing at the moment I had last night went to the properties and set it as always hide . Then today I went to check on it and its not listed .
    What did show was the same message as the one on my desktop in which i will send an attachment of so you can see what i mean. about the message. and it has a center to where you can click on it and browser pops up with an ad for spyware that can be bought to get rid of this like off the wall software.
     
  47. GI Joe

    GI Joe Private E-2

    Warning
     
    Last edited: Sep 13, 2006
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In message # 38 I asked but you never answered
    In message # 44 I asked but you never answered or complete this request:
     
  49. GI Joe

    GI Joe Private E-2

    I did what you said and now it is plain blue . Let me see if i restart and it stays.

    Avast is a good for picking up viruses quick and moved them to the chest.
    Thank you !

    I feel a tad better now since i dont have to look at that desktop like that.
    You are an A+ !
     
    Last edited: Sep 13, 2006
  50. GI Joe

    GI Joe Private E-2

    When I do a search for desktop.html on windows search I find 2 files labeled desktop.html.
    First one has a IE icon and it is labeled desktop.html and when I click on view details it says location my computer when I click on properties it shows the address as C:/windows/mycomputer I clicked on it to bring up the folder it was in and it said exactly on the folder that is said where the location was C hard drive and in a file thats labled my computer in that has screen shots that was saved that I took of the computers desktop and the icon that was labeled desktop.html.
    The second one has a firefox icon and the location shows C:/windows/web it shows 2 kb file size . When I go to its location I go to my computer , c hard drive then to a folder labeled web and in it is this icon next to files of wallpaper and printer files along with the icon labeled desktop.html.

    I still have a problem with the icon in the tray when i go right click on the taskbar then go to properties . Then go to customize taskbar it then shows all the tray icons it is labeled No title . If i click on the icon on the tray it will bring up a web page the same as the message on the screen. That message isnt back unless I put a wallpaper on it. Cause I tried to set another wallpaper on it then it came back . When I go back and pick none and then delete secruity out of the box under display and uncheck lock items on desktop the apply and ok it goes away.
    What do you make of this. Look at the screen shot of the original message its the same as the icon in the tray.
     
    Last edited: Sep 13, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds