malware hijacked my Background file

Discussion in 'Malware Help (A Specialist Will Reply)' started by lvibrock@swbell.net, Jul 8, 2007.

  1. lvibrock@swbell.net

    lvibrock@swbell.net Private E-2

    I had malware trojans and removed them with recommended scans as found at MajorGeeks.com, following each of the steps in "Basic Spyware, Trojan And Virus Removal Tutorial." The troublesome malware had the following names:
    "Your Privacy Is In Danger"
    OnlineSecurityWorld.com/shandler
    "Udefender"
    "online stability
    "error cleaner"
    and others I am not sure were ever identified.

    Now the Desktop's Red Screen displaying the "Your Privacy Is In Danger" is gone, but I have a totally white Background File. I have checked Control Panel, Display Properties, Theme, and my preferred background is actually selected. I also reapplied a new selection, and the Background screen is still totally white. This is true even thought I tried a couple of others.

    Note that I HAVE NOT performed "Toggle System Restore" as yet. I wish to have all problems resolved first.

    Please help me get my PC back to normal and display my background screen.

    I have attached my HiJackThis log
     

    Attached Files:

  2. lvibrock@swbell.net

    lvibrock@swbell.net Private E-2

    I have attached my remaining 3 files, including HiJackThis.log.
    ...waiting for reply...

     

    Attached Files:

  3. lvibrock@swbell.net

    lvibrock@swbell.net Private E-2

    Can someone help me with my two posts here? A MalWare problem deleted my desktop background. It's white now. Please see below and help me get my laptop returned to to normal.

    would appreciate any help you can give me.

     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please install:
    Java Runtime 6

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:
    ShowNew
    GetRun
    HJT
     
  5. lvibrock@swbell.net

    lvibrock@swbell.net Private E-2

    I followed your instructions. After following instructions, I still have the "white screen" desktop.
    Attached are:
    newfiles.txt
    runkeys.txt
    hijackthis.log

    Thank you for all your help. Once I have problem resolved I will make an appropriate contribution to this site.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rename HJT:
    C:\Hijackthis\Hijackthis.exe ----> C:\Hijackthis\analyse
    Please uninstall Counterspy.
    Run it again and attach the log.

    The malware may have reset your desktop and Norton may be blocking any changes.
    If you right click the desktop ....under properties do you have a theme, under desktop, do you have a background setting?
    Make sure you have turned off all anti-spyware programs as well as Norton before trying to make the changes.
     
  7. lvibrock@swbell.net

    lvibrock@swbell.net Private E-2

    I right clicked the desktop. Under properties it shows:
    Theme: Windows XP (Modified)
    Desktop: Tulips

    All anti-spyware programs including Norton are turned off.
    Changes were made as described

    HJT was renamed:
    C:\Hijackthis\Hijackthis.exe ----> C:\Hijackthis\analyse

    Counterspy was uninstalled.

    Ran HiJackThis. Log file attached.

    I still have a white Desktop.

    At StartUp, there is a brief view that shows "Tulips" desktop, but as the Desktop fully loads, a solid-blue desktop displays, then switches to the white desktop screen with all my appropriate shortcuts showing as appropriate, e.g. shortcut to Explorer, Outlook, Word, etc.

    Not sure now what to do?? Your helpwill be appreciated.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    YOu only added another folder name :
    C:\Program Files\HijackThis\analyse\HijackThis.exe

    Is there a problem with right clicking Hijackthis.exe and renaming it to analyse as per my previous post?

    Right click your desktop ..properties ...desktop tab ...web tab...uncheck the lock desktop and make sure the web page setting is My Current Home Page ( but the box is not checked).
     
  9. lvibrock@swbell.net

    lvibrock@swbell.net Private E-2

    that fixed it! thank you! I've been out of the country for a while...sorry to be so long in responding to thank you.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds