Bastards tried to change by screen background

TexTex Dallas/Ft. Worth
edited May 2005 in Spyware & Virus Removal
And now all the tabs under display properties disapeared. All I can do is set the resolution. I can't set my background again or anything

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited May 2005
    Sounds like smitfraud. Post your HJT log so we can help.
  • TexTex Dallas/Ft. Worth
    edited May 2005
    I had an error on the background with a illegal instruction or something when it happened. I think either one of the antispyware or virus programs may of tried to catch it but missed.

    Here is the log. I'm not seeing anything in it.

    Logfile of HijackThis v1.99.0
    Scan saved at 8:52:41 AM, on 5/1/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\WINDOWS\system32\spoolsv.exe
    E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    E:\WINDOWS\Explorer.EXE
    E:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    E:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
    E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    E:\Program Files\Messenger\msmsgs.exe
    E:\Program Files\Common Files\Symantec Shared\ccApp.exe
    E:\PROGRA~1\RCrawler\RCrawler.exe
    E:\WINDOWS\SOUNDMAN.EXE
    E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    E:\Program Files\MSN Messenger\msnmsgr.exe
    E:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
    E:\WINDOWS\system32\svchost.exe
    E:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    E:\Documents and Settings\Mark\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.ebay.com/ws/eBayISAPI.dll?MyeBay&ssPageName=H%3AH%3AMYEBAY%3AUS
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/hlidOfficeHomeFromClient?CTT=6&Origin=EC010230001033
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - E:\PROGRA~1\AdShield\AdShield\AdShield.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccApp] "E:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Registry Crawler] E:\PROGRA~1\RCrawler\RCrawler.exe -TRAYONLY
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O8 - Extra context menu item: &Maintain Block List... - E:\PROGRA~1\AdShield\AdShield\maintain.htm
    O8 - Extra context menu item: Add to &Block List... - E:\PROGRA~1\AdShield\AdShield\suppress.htm
    O8 - Extra context menu item: Add to &Exclude List... - E:\PROGRA~1\AdShield\AdShield\restrict.htm
    O8 - Extra context menu item: AdShield Option &Settings... - E:\PROGRA~1\AdShield\AdShield\settings.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: AdShield - {4FB6C25E-7B37-4c93-B592-16ECD8D18361} - E:\PROGRA~1\AdShield\AdShield\AdShield.dll (HKCU)
    O9 - Extra button: Microsoft AntiSpyware helper - {D5331946-E80B-4B1E-8F99-D8BF17452150} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D5331946-E80B-4B1E-8F99-D8BF17452150} - (no file) (HKCU)
    O10 - Unknown file in Winsock LSP: e:\windows\system32\fltmgr.dll
    O10 - Unknown file in Winsock LSP: e:\windows\system32\fltmgr.dll
    O10 - Unknown file in Winsock LSP: e:\windows\system32\fltmgr.dll
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
    O23 - Service: Symantec Event Manager - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - E:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Speed Disk service - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • SpywareShooterSpywareShooter 127.0.0.1
    edited May 2005
    Okay give this a try. I don't know if it will work or not. I made it for someone else with the same problem, but they never responded as to whether or not it worked. Remember to back up your registry first then unzip it and run wallpaper.reg.
  • TexTex Dallas/Ft. Worth
    edited May 2005
    Nope didnt work.

    Here is what I get when I right click on the desktop and go toproperties still
  • SpywareShooterSpywareShooter 127.0.0.1
    edited May 2005
    Hmmm I think Buckeye Sam has a script for it. I'll talk to him and either have him post it here or give it to me.
  • SpywareShooterSpywareShooter 127.0.0.1
    edited May 2005
Sign In or Register to comment.