My desktop background has gone crazy!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by alf3367, Jan 18, 2005.

  1. alf3367

    alf3367 Private First Class

    my desktop background had been taken over with this message:
    Windows

    Warning! Windows has detected SPYWARE INSTALLED on your computer.
    What is Spyware, Adware and Malware?
    Spyware and Adware, also called 'Malware', are files made by publishers that allow
    them to snoop on your browsing activity,
    see what you purchase and send you 'pop-up' ads. They can slow down your PC, cause
    it to crash, record your credit card numbers and worse.
    If you're like most Internet users, chances are you're probably infected with these files.
    Simply surfing the Internet, reading email, downloading music or other files can
    infect your PC without you knowing it.
    * It is HIGHLY recommended to install protection from spyware
    * Choose a good antispyware program and install it to protect your privacy
    Click to search the recommended spyware removal
    tools


    i have windows xp home edition and i have all of the good adaware, spyware and anti virus scanner. i also have gone thorugh and did the proper steps of removal and still have this problem can anybody help? thanks. allen
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Allen,

    Take a peek at this thread and see if the suggestion in post #12 applies to your situation.

    Help! Desktop.html...hijacked desktop.

    If not, and if you have exhausted the options in our Cleanup Tutorial,
    then go ahead and send us a HijackThis Log. Please be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!
    Should you need a Fresh Download of HJT, get it HERE: HijackThis v1.99

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I’m not around this forum too often these days, but somebody will try to take a look when they get a chance.

    Best luck :)
    PP
     
  3. alf3367

    alf3367 Private First Class

    hey PP, um my problem is not the same as that thread u posted. but i did download a high jack this scanner, but i know nothing about this high jacking stuff can u explian cuz i think it may be where my problem lies. thank you
    allen
     
  4. PhilliePhan

    PhilliePhan Guest

    Did you do the online scans in the tutorial? Did you take a look at your Active Desktop Settings?

    You didn't mention OS, but if XP, here is how to put HJT in its own folder.

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, RightClick your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder (C:\Program Files\HijackThis)and click Next.

    Now run HJT from there, scan, save the log as a .txt file and attach that log via the “Manage Attachments” tool when you post.

    I will check back whenas time permits.

    PP :)
     
  5. alf3367

    alf3367 Private First Class

    i think this is what u wanted. i attatched it. thanks
    allen
     

    Attached Files:

  6. PhilliePhan

    PhilliePhan Guest

    Hi Allen,

    Please uninstall Free-Popup-Killer.

    Please extract HijackThis to a safe, non-TEMP folder as I asked in my last post. This is very important! Let me know if you have any problems doing this. We can't start cleaning your machine until you do this!

    PP :)
     
  7. alf3367

    alf3367 Private First Class

    ok i think i got it now, see what u think. thanks
    allen
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not yet! You still have it here:
    C:\Documents and Settings\Preferred Customer\My Documents\Scanners\hijackthis\HijackThis.exe

    Put it in a folder that is not part of documents and settings. Use one of these:
    C:\Program Files\HijackThis
    C:\Program Files\HJT

    or even
    C:\HJT
     
  9. alf3367

    alf3367 Private First Class

    lol, ok how about now?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Better but you only need one HijackThis folder in depth.
    C:\Program Files\HighJackThis\hijackthis\HijackThis.exe

    Not a problem but all you need was: C:\Program Files\HighJackThis\HijackThis.exe

    But the below are problems! No browsers should ever be running when using HijackThis unless we specifically request that (rarely - but sometime it is needed):
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that log from safe mode? We need logs to be from normal boot mode unless otherwise requested. It looks like no antivirus application exists on your PC. Is that true? Just some partial signs of one?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download LSP - Fix

    NOW:
    Unzip it and run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the apptoport.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move apptoport.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.


    Now click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\WINDOWS\System32\sfg_7988.dll

    then click OK. If a dialog box confirming this action appears, click OK. If you get any error messages, write them down and tell me about them lated but just continue on with the next steps.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_7988.dll
    O3 - Toolbar: (no name) - {C1EA1782-8E6E-4ea4-9800-B68DE41F1A26} - (no file)
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
    O4 - HKLM\..\RunOnce: [w20aat.exe] C:\WINDOWS\System32\w20aat.exe /k
    O4 - HKCU\..\RunOnce: [w20aat.exe] C:\WINDOWS\System32\w20aat.exe /k
    O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {A81BEF5A-E213-4C28-B9BA-ED6B3395F1A9} - (no file) (HKCU)
    O23 - Service: .NET Framework Service - - (no file)

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\w20aat.exe
    C:\WINDOWS\System32\sfg_7988.dll

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  13. alf3367

    alf3367 Private First Class

    ok thanks give me a bit, i'm slow.....

    allen
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Allen! Run faster, faster!!! :D
     
  15. alf3367

    alf3367 Private First Class

    ok, maybe, that should do it?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. alf3367

    alf3367 Private First Class

    thanks for your help. my pc was a big mess at one time abd now its only a small mess. but i still have the problem with my desktop. i have done all the scans and i have done everything posted in these threads. thanks
    allen
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this:


    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.
     
  19. alf3367

    alf3367 Private First Class

    see thats the thing. its like an ad. when i right click and click properties it just gives the ad's info.
     
  20. alf3367

    alf3367 Private First Class

    properties

    windows warning
    protocol" file protocol
    type: html file
    connection: not encrypted
    address: file://C:\WINDOWS\Web\Desktop/.html
    size: 2266 bytes
    created: 12/12/2004
    modified: 1/9/2005
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try it this way! Click Start and then Control Panel. Now in Control Panel double click display. Now click Desktop and continue with my previous steps.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that does not work, boot in safe mode and run Windows Explorer (nothing else) and delete:

    C:\WINDOWS\Web\Desktop <--- this folder
     
  23. alf3367

    alf3367 Private First Class

    yessssssss, thank god. it worked. thank you very much for your help. i have been dealing with this since early december. well my problems are pretty much gone, but imma stick around MG for a while thanks
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Hang out as long as you like!
     
  25. satmanII

    satmanII Private E-2

    Gentleman

    My thanks to you all for you postings. From reading what you have experienced and solved I was able to recover my Desktop from a HiJacker.

    I was surfing a warez site when my pc cillin popped up 4 times in a row grabbing 2 of the 4 trojans. 2 were not unsuccessfully quaranteed.

    Right after that my desktop was taken over and turned into a webpage.
    They locked me out with security in the desktop feature.

    However following the routing steps here for Hijack recovery I was able to take it back

    Kudos to you all !!!!

    Satty
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Happy to hear it helped you out too!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds