Windows Security System has detected spyware wallpaper

Discussion in 'Malware Help (A Specialist Will Reply)' started by boverman, May 10, 2006.

  1. boverman

    boverman Private E-2

    I am sorry but I cannot find any thing about this problem.

    A black wallpaper with red type says" Windows Security has detected spyware/adware infection"
    It is strongly reccomended to use special antispyware tools to prevent data loss.

    There are 2 red circles with white x's in the tool bar.
    having run Norton, Adaware SE, and detecting and quarratined the "problem", the problem has not gone away. No java scripts, no mail.

    Running Windows Me.

    Attaching HIJACKthis log.
    please help to decipher what is happening.
     

    Attached Files:

  2. boverman

    boverman Private E-2

    I have found BraveSentry in my own hijack log and dumped it out of the registry...I am trying to get rid of xpupdate.exe...but it will not allow me to delete it...
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
     
  4. boverman

    boverman Private E-2

    Thank you for answering. I decided to look through the log myself...I noticed the Brave Sentry and a file I had not seen before xpupdate.exe...I went into regedit and got rid of Brave Sentry...xpupdate.exe kept giving me the message that windows was using it when I tried to delete it. So after trying several removal tactics, I simply drag and dropped it into the trash. Voila, the red x's were gone. I then checked on the wallpaper issue and went back into the regedit and USER_ Software>Microsoft>Windows>CurrentVersion>Policies>System>---delete wallpaper...and its GONE!
    It is nice to know that you are here if I get stuck.
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    HijackThis is a very useful tool; however it is not the be all/end all tool. It isn't even really an anti-malware tool. It looks at specific areas of the registry commonly modified by spyware and malware. It does not show other areas of the registry that can be modified by malware.

    Many infections can and do regenerate at system restart. Hence our procedure, the scans are necessary since they put your computer at a known state; many infections are removed by simply following our procedures. If the procedures fail then that is why we are here to help you clean out the infection.

    Modifing the registry can have disastrous results. By simply dragging and dropping a file into the recycle bin does not in most cases rid your computer of the infection.

    Follow our cleaning procedures, tedious and long as they may be, you will benefit from it in the long run.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes Shadow is correct!

    For example, you still had other files and registry keys related to the infection.

    C:\WINDOWS\SYSTEM\DLH9JKDQ2.EXE

    is part of the infection and so is a file named desktop.html.

    You also have registry keys trying to load the bad processes from xpupdate and BraveSentry at startup.

    In addtion you also have Viewpoint Manager that should be uninstalled.

    If you had these issues you could have more hiding.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds