"warning you are in danger" wallpaper

Discussion in 'Malware Help (A Specialist Will Reply)' started by wizz, Mar 20, 2005.

  1. wizz

    wizz Private First Class

    if you need any translation just ask...
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok! I will be awaiting the screenshots I requested.
     
  3. wizz

    wizz Private First Class

    i thought i had sent them long ago.... and because of my internet connection i wasnt able to check the forum... all this time wasted...
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, be sure the file C:\WINDOWS\desktop.html does not exist, if its back delete it!

    Now, Follow the below steps:

    Navigate to the following key(again):

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

    On the right side, right click the string Wallpaper and select delete!


    NOW:

    Navigate to the below key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System

    On the right side make sure your strings & values and look exactly like the attached image!

    If anything on your key is different, change it to fit the attached image! Let me know if you have any problems. Also if you are afraid to do something, feel free to ask first.

    Good Luck!:)
     

    Attached Files:

  5. wizz

    wizz Private First Class

    ok string gone. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System is exactly as in the picture i didnt have to change anything. im rebooting now... sorry if i lose my conection again...
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Good! Try changing the desktop wallpaper, tell me if its still greyed out.
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If still no go then do the following:

    Navigate to the following key:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop

    On the right side, if there is anything other than the (default) string, right click and delete it.

    Also, If a binary value named "NoChangingWallpaper" exist, let me know.
     
  8. wizz

    wizz Private First Class

    !!!!!!!!!!!!!!!!!!!!! i can change my desktop!!!!!!!!!!!!!!!!! Thank you very much!!! now the last problem... the right click... tell me if you want to continue today or if you want to get some sleep we can go on tomorrow.
    AGAIN THANK YOU!!!
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Great! :D What did the job? Which step?

    Okay, Ive been thinking so hard on this..explain your right click problem please. lol
     
  10. wizz

    wizz Private First Class

    this did the job


    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop for this key i have: NoAddingComponents, NoChangingWallpaper, NoComponents, NoDeletingComponents, NoEditingComponents, NoHTMLWallpaper just want to be sure if i should errase them all
     
  11. wizz

    wizz Private First Class

    about my right click problem... i dont know how to explain it... just that when i right click... nothing happens. i can only right click on explorer windows
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, delete all of those entries!

    This key below should only have the (default) string, anything else should be deleted.

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
     
  13. wizz

    wizz Private First Class

    same values exist in hkey local machine... should i remove these too? and remove others when found?
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Not just yet, which key in HKEY_LOCAL_MACHINE are you referring to?
     
  15. wizz

    wizz Private First Class

    i mean HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That key is not supposed to exist, right click and delete the whole key.

    The only keys under:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies

    should be as follows:

    NonEnum
    Ratings
    system
     
  17. wizz

    wizz Private First Class

    to remove the entire key im supposed to right click Active Desktop folder on left panel and delete right?
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That is correct, on the left side, right click the folder Active Desktop and select delete.

    Be sure its under the key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, do you have another mouse you can try?
     
  20. wizz

    wizz Private First Class

    explorer folder is under policies too and was deleted with active desktop folder
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay! let me get an update, you can change your wallpaper, correct? Nothing is greyed out anymore? And the "warning you are in danger" wallpaper is gone for good?

    Only problem is the right click, correct?
     
  22. wizz

    wizz Private First Class

    correct

    about getting another mouse... i dont think thats the problem, because the right click button does work... it only doesnt on desktop and system windows... if they are called that way... right click works on explorer windows and taskbar
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Navigate to the following key:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

    Look for a DWORD value called "NoViewContextMenu"

    When located right click and delete it! Only remove this entry!!!
     
  24. wizz

    wizz Private First Class

    not found... but why search in explorer folder? when i can use right click on explorer windows...
     
  25. wizz

    wizz Private First Class

    wait... i looked for it in the wrong folder... sorry... im a little tired...
     
  26. wizz

    wizz Private First Class

    its deleted now, but still cant use right click
     
  27. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Its just a registry key, explorer.exe is what loads everything, like your desktop :p

    Navigate to the following key:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer


    Again, Look for a DWORD value called "NoViewContextMenu"

    If found delete it.
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot, and try again..sometimes you have to reboot for settings to take effect.
     
  29. wizz

    wizz Private First Class

    YES!!!! VICTORY!!!! right click works!!!!!! i want to thank you guys for giving so much of your time to my problem...
    can we just fix the last details?
    first... my computer is taking a little longer to load desktop... second right click takes a few seconds to appear when before it was instant and when i right click recycler bin it doesnt give me the same options it did before, for example it doesnt give me the option to empty recycler bin... i thought SmartSecurity put this two items (recycler bin and microsoft outlook) on my desktop as some kind of way to make my desktop look real... because the wallpaper moved all my desktop items... i just need to move them back dont i?
     
  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Right Click on your desktop :)D) and select Arrange Icons by and select whatever you prefer (name, date, type) :)

    Should put them all back where they belong.
     
  31. wizz

    wizz Private First Class

    well that didnt do the work... it doesnt matter really i can do it manually, but what about the other problems... my computer is a lot slower that it used to be... and im supposed to be clean as pure water
     
  32. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach one last HJT log so I can see current startup items, also before you attach this log do the following to make sure all items show in HJT.

    Click Start > Run > type in msconfig

    Now, Click the startup tab and make sure EVERYTHING is checked.

    When your are prompted to reboot, click "Exit Without Restart"

    Now scan with HJT and attach the current log.
     
  33. wizz

    wizz Private First Class

    HJT log attached
     

    Attached Files:

  34. wizz

    wizz Private First Class

    ok new problem... when i move all desktop items from Dokuments and Settings to new desktop... they duplicate themselves... as if the real items are hidding somewhere... i think they are really hidden or something, because desktop items are saved on Dokuments and Settings folder isnt it? and when i move the items to desktop... its logical that if the other items are hidding... they will appear double... ... did you understand anything??!?!?! lol....
     
  35. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    There isnt anything bad that jumps out at me but I wouldnt recommend keeping this as it could be a small issue.

    Ares Lite Edition

    All P2P programs are bad in my opinion because they are all loaded with spyware/viruses. Whether its in the program or something downloaded from the program, either way its bad to me! It will not hurt to remove this from startup so it wont take any resources but its up to you.

    Its totally up to you whether you keep it or not!

    Now, as far as your slow booting problem, I dont see any problems that would be causing this, I do see a EPSON printer and sometimes if you do not have enough memory they will use a bit but other than that your ok.

    I would go ahead and uninstall anything we had you install just to free up some space and resources.

    The only other thing I must tell you is that you need surf in to Windows Updates and get Service Pack 2 installed as well as many others.

    You should check out this article on How to Protect yourself from malware!
     
  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Not exactly, everything in the folder below is the same as whats on your desktop:

    C:\Documents and Settings\YOUR USERNAME\Desktop

    Right Click on your Desktop, click on Arrange Icons by and make sure there is a check mark by Show Desktop Icons
     
  37. wizz

    wizz Private First Class

    exactly, but they dont appear on desktop... i did what you told me... but nothing...

    do you want to continue this tomorrow or you dont sleep? lol
     
  38. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I'll be here a few more minutes :p

    So you have no icons on your desktop?

    When you go into this directory, do you see anything?

    C:\Documents and Settings\YOUR USERNAME\Desktop
     
  39. wizz

    wizz Private First Class

    yes i see the items that should be on my desktop... but they dont show up... i also told you that when i tried to move this items... they duplicate on desktop... when i move one of the duplicates to Documents and Settings folder the other copy disappears
     
  40. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you settings like this?
     

    Attached Files:

  41. wizz

    wizz Private First Class

    yes they are
     
  42. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Okay! Since your browsing the web without SP2, go ahead and get updated and we will finish this tomorrow.
    • Visit Windows Updates

    • Download & Install Service Pack 2

    • Get all critical updates!
    Will check back later today as its 3:54 AM lol .:)
     
  43. wizz

    wizz Private First Class

    ok... starting day #... how many days? lol well... saddly i cannot download SP2 i tried to fix it... but couldnt...
     
  44. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Why not, what happened?
     
  45. wizz

    wizz Private First Class

    It says that theres a problem, windows cant show the desired Webpage. problem number: 0x8DDD0004
     
  46. wizz

    wizz Private First Class

    im gonna try with administrator...
     
  47. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  48. wizz

    wizz Private First Class

    hmm... is hard to find the names, mine are in german... can you explain me where they are so maybe i can find them
     
  49. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! That link appears to be more for systems that already have WinXP SP2 and are getting the same error number. I'll see if I can find anything else on this!
     
  50. wizz

    wizz Private First Class

    great.... wallpaper is back... i errased the values i removed last time... i rebooted... and they came back (the values).... NOOOO!!!! can there be something else hidding that re installed everything?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds