run your threat fire
if the doesn't help there are a lot of spyware cleaning programs online
eg. spybot search & destroy
Main Topics
Browse All TopicsMy son was messing with my pc and tried to download something online which seems to be some sort of spyware, this spyware changed my desktop wallpaper to one that states "warning! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer." i tried to change it back but screensaver tab is missing from display properties, im stuck with this, i have trend micro and it found and quarantine/delete some stuff, ive also downloaded some free anti virus/spyware program such as avg spybot search and destroy, all of them found something but still cant seem to see my screen saver tab to change wallpaper.
please
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
your infected by mebroot trojan.
you can download the removal tool here: http://www.brothersoft.com
it also changed the wallpaper and screensaver.
make sure you also delete these files.
if you can't access the background or screensaver anymore when you open display properties you need to change these 2 keys:
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
also create a win98 floppy and do fdisk /mbr as the virus modified the mbr.
good luck getting your pc clean
you find more info on http://www.symantec.com/se
Hi,
Your hijackthis log is showing variant of SDBot.
Download SDFix and save it to your desktop.(either one below)
http://downloads.andymanch
http://downloads.andymanch
If needed: How to use SDFix.
http://www.bleepingcompute
Double click SDFix and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and attach the "Report.txt" back
If problem persists, you can also download Malwarebytes' Anti-Malware to your desktop.
http://www.malwarebytes.or
Double-click "mbam-setup.exe" and follow the prompts to install the program.
Make sure to checkmark 'Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform full scan", then click "Scan".
When the scan is complete, click OK, then "Show Results" to view the results.
Be sure that everything is checked, and click "Remove" Selected.
Hi,
Please follow the instructions below::::
1. goto RUN, type REGEDIT and press ENTER.
2. now navigate to path HKEY_CURRENT_USER > Software > Microsoft > Windows > CurrentVersion > Policies > system
here in the right pane you will see some values, similar to below .......
"NoDispBackgroundPa
"NoDis
"Disabl
"Dis
here all values should be '0' (zero).
so if u have any value that is not 0 so simply double click on that VALUE and change the DWORD value to "0".
NOW ALL VALUES WILL BE equal to '0'.
make sure and EXIT from REGISTRY EDITOR.
now right click on ur Desktop goto Properties - I hope that now u can see the all TABS.
can u?????
NOW simply change the wallpaper and your BLUE anti-spyware screen will be gone.
so to be secure for next time, install a working & latest updated antivirus, SCAN ur system.
and EnJOY
take care
Computer Angel
.a.d.e.e.l.
Business Accounts
Answer for Membership
by: eazstreamPosted on 2008-07-31 at 13:05:51ID: 22133046
just installed hijack this and here is a copy of paste of that scan
xe exe on.exe es.exe exe t.exe t.exe t.exe 24EvMon.ex e t.exe t.exe v.exe vr.exe fIpMon.exe fg.exe r.exe .exe t.exe .exe t.exe miprvse.ex e t.exe e exe exe rs.exe vc.exe Mgr.exe e .exe \procexp.e xe t.exe 32.exe s.exe
ternet Explorer\Main,Start Page = about:blank ternet Explorer\Main,Default_Page _URL = http://go.microsoft.com/fw link/?Link Id=69157 ternet Explorer\Main,Default_Sear ch_URL = http://go.microsoft.com/fw link/?Link Id=54896 ternet Explorer\Main,Search Page = http://go.microsoft.com/fw link/?Link Id=54896 ternet Explorer\Main,Start Page = http://go.microsoft.com/fw link/?Link Id=69157 ternet Explorer\Main,Local Page = ternet Explorer\Main,Local Page = ndows\Curr entVersion \Internet Settings,ProxyOverride = *.local F10577473F 7} - c:\program files\google\googletoolbar 2.dll 819E2EAAC9 3} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien t.dll B52B6139FC 7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll 09027A5CD4 F} - c:\program files\google\googletoolbar 2.dll ay.exe exe rs.exe Mgr.exe .exe" t32.exe e " /background .exe t.dll/Acro IEAppend.h tml t.dll/Acro IECapture. html t.dll/Acro IEAppend.h tml t.dll/Acro IECaptureS elLinks.ht ml t.dll/Acro IEAppendSe lLinks.htm l t.dll/Acro IECapture. html t.dll/Acro IEAppend.h tml t.dll/Acro IECapture. html \OFFICE11\ EXCEL.EXE/ 3000 C9C571A826 3} - C:\PROGRA~1\MICROS~2\OFFIC E11\REFIEB AR.DLL 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe 63509EAE56 B} (SysProWmi Class) - http://support.dell.com/sy stemprofil er/SysPro. CAB CFDF33E833 C} (WUWebControl Class) - http://www.update.microsof t.com/wind owsupdate/ v6/V5Contr ols/ en/x86 /client/wu web_site.c ab?1217256 313965 4455354000 0} (Shockwave Flash Object) - http://fpdownload2.macrome dia.com/ge t/shockwav e/cabs/fla sh/ swflash .cab cpip\Param eters: Domain = delonghi.local : DomainName = delonghi.local cpip\Param eters: Domain = delonghi.local cpip\Param eters: Domain = delonghi.local cpip\Param eters: Domain = delonghi.local y.dll 4\G2AWinLo gon.dll fIpMon.exe r.exe vtEng.exe ice.exe .exe egSrvc.exe 24EvMon.ex e ce.exe .exe .exe ice.exe
thanks in advance
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:48:51 PM, on 7/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\Program Files\Intel\Wireless\Bin\S
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\System32\SCardS
C:\Program Files\Broadcom\ASFIPMon\As
C:\WINDOWS\system32\bmwebc
C:\Program Files\Bonjour\mDNSResponde
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\StacSV
C:\WINDOWS\system32\svchos
C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\ThreatFire\TFService
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\WINDOWS\system32\dllhos
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\system32\wbem\w
C:\WINDOWS\system32\dllhos
C:\WINDOWS\System32\alg.ex
C:\WINDOWS\system32\msdtc.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\WINDOWS\system32\igfxsr
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\ThreatFire\TFTray.ex
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Documents and Settings\ezambrano\Desktop
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuaucl
C:\WINDOWS\system32\rundll
C:\Program Files\Trend Micro\HijackThis\HijackThi
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDoc
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [EmbassySecurityCheck] "C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck
O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysres
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.ex
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClien
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-9
O16 - DPF: {6414512B-B978-451D-A0D8-F
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS2\Services\T
O17 - HKLM\System\CS3\Services\T
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotif
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\51
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\As
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\E
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\R
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageServi
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentServ
O24 - Desktop Component AutorunsDisabled: (no name) - (no file)
--
End of file - 10095 bytes