White Bland Desktop!

Discussion in 'Malware Help (A Specialist Will Reply)' started by zeke718, Jul 9, 2006.

  1. zeke718

    zeke718 Private E-2

    Hello,

    I have followed all instructions, #1-9 on removing Malware from another thread. I did this after being infected with a nasty trojan horse that hijacked my desktop, turned the screen red, with a flashing advertisement that said "DANGER:SPYWARE" with a link to buy software called razespyware. It also allows popups advertising casinos and other bogus antispyware removal software. First, I ran norton, and when that didn't help, I turned to you. I have now followed the steps for a second time, as after the first, my wallpaper became completely white and would not take my changing settings via the control panel. I found more problems, fixed them as instructed, but still have a white wallpaper. I see my set wallpaper only briefly when shutting down. I have attached my panda scan results, my counter spy results and my hijack this results. Please help!!!

    Zeke
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Why did you skip the running of Bitdefender in step 6 of the READ ME?

    For your wallpaper problem, try running ONLY step 8 from the below link:

    SpySheriff (aka SpywareNo) Removal

    If that does not fix it, then do this next procedure:

    Fixing Locked Desktop
    Right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    After doing the above you have some more cleaning to do.

    You have a Wareout infection.

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now look in Add/Remove programs for the below and uninstall if found:
    UnSpyPC


    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. If it does not launch then run it yourself. Please click Scan, and check the following items if they still exist:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
    O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CBA1CAF7-38A8-4E40-81C5-7593DD8C5206}: NameServer = 85.255.116.73,85.255.112.150


    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    At the end of the fix, reboot into safe mode and use Windows Explorer to double check for the below files and delete if found:
    C:\Program Files\UnSpyPC <--- delete the whole folder if found

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    There could be additional cleanup to do from Wareout and it the log will let us know.

    Also attach a new HijackThis log.
     
  3. zeke718

    zeke718 Private E-2

    I followed all of the above and my system is running perfectly. Thanks so much!!!:) :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are almost done! The worst of you malware is gone but we need to fix a few things.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below file using Windows Explorer and delete it if found:
    C:\WINDOWS\system32\{3C7D33C5-A895-4F93-BE2D-FD05CB97F2C8}.exe

    Now attach a new HJT log!
     
  5. zeke718

    zeke718 Private E-2

    :) I didn't find the file you mentioned, but copied the stuff to the registry. Here is the latest HJT log.:)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds