Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Can't change wallpaper after spysherrif attack
   
BullGuard Antivirus Forum > General Security > Spyware > Can't change wallpaper after spysherrif attack  
Forum Quick Jump
 
New Topic Post reply to : Can't change wallpaper after spysherrif attack Printable version of : Can't change wallpaper after spysherrif attack
34 posts in this thread.
Viewing Page :
 1  2 
[ << Previous Thread | Next Thread >> ]

lenc
New Member


Date Joined Nov 2005
Total Posts : 1
 
   Posted 11-9-2005 10:41 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Hello, recently my computer got infected with spysherrif. The usual blue screen with the "INFECTED COMPUTER" wallpaper was on my screen and there was no way to change the wallpaper. I used Spy Sweeper to get rid of spysherrif but I still can't change my wallpaper. When I go to Display properties -> Desktop, the background window is grey.
 
I ran a hijackthis scan and here are the results:
 
Logfile of HijackThis v1.99.1
Scan saved at 22:49:06, on 9.11.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\QUICKT~1\qttask.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\mysql\bin\winmysqladmin.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\mysql\bin\mysqld.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\GetRight\GETRIGHT.EXE
C:\Program Files\GetRight\GETRIGHT.EXE
C:\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neti.ee/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 217.180.83.133:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O1 - Hosts: 127.0.0.5 topcash.biz
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [EstEID AIP switch] C:\Program Files\IT Arendus\ID-kaart\\aipswitch 1
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINCINEMAMGR] "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [ntsysl] C:\WINDOWS\System32\ntsysl.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [CrashNetCluster] C:\Program Files\Crash.Net Desktop Race Babe\skinkers.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: SharpReader.lnk = C:\Program Files\SharpReader\SharpReader.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagead/preview/en/preview.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Subscribe in default RSS reader - C:\Documents and Settings\Kasutaja\Application Data\RssBandit\iecontext_subscribefeed.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0C8DD11D-D1E5-409F-A021-D66065F412A5} (QCapsule Class) - https://www.valimised.ee/evotein.cab
O16 - DPF: {20CA0570-6E5D-4A0F-A9FF-A2227F2C4543} (algorithm Class) - https://www.hanza.net/scripts/dsigLite2.cab
O16 - DPF: {27DE8550-C471-4378-87E3-EFE4CDA22174} (Installer Class) - http://www.id.ee/installer/InstallerExec.cab
O16 - DPF: {2BD3E3A2-8D92-4438-B335-C1F3F75F83D6} (diskFile Class) - http://www.id.ee/installer/fileInfoUtil.cab
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://www.easports.com/downloads/games/common/ieell.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/xx-elmer/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {7C360B4D-3C03-44CA-9C05-A5AB6E029887} (Detect Class) - http://www.id.ee/installer/IDInstaller.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://gw.tallinnlv.ee:11082/activex/AxisCamControl.cab
O16 - DPF: {9FD4887A-0B1A-41FF-9816-4F27ABADCB9E} (UpdateCerts Class) - http://www.sk.ee/id-kontroll/certupdated.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697516} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_mp3.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697517} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_aac.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_aac.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{27248B80-2150-4EF8-8506-AA934A956F64}: NameServer = 194.126.115.18,194.126.101.34
O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\System32\msctl32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 
Back to Top
 

dhonam
New Member


Date Joined Nov 2005
Total Posts : 1
 
   Posted 11-19-2005 8:37 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
then tell me how you know the problem inbe is that to remove tell me
Back to Top
 

silentmute
New Member


Date Joined Nov 2005
Total Posts : 2
 
   Posted 11-19-2005 6:08 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I had the same problem. I ran spysweeper and still couldn't change the wallpaper. Then I opened up redit and navigated to the following entry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html

I deleted this key(I suggest backing it up first), everything seems fine now.


Hope that helps.
Back to Top
 

Shadow1100
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-3-2005 6:23 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I went here: http://www.hijackthis.de/index.php?langselect=english
I did a scan with Hijack, had it analized, and had my desk top back in just a couple of minutes.
Hope it helps,
Shadow
Back to Top
 

loen
New Member


Date Joined Dec 2005
Total Posts : 2
 
   Posted 12-8-2005 7:57 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Someone metioned getting rid of spysherrif's spell using a program called redit,  I'm having this problem also and I was wondering where I could download this redit program.
Back to Top
 

ZippoLag
New Member




Date Joined Dec 2005
Total Posts : 15
 
   Posted 12-15-2005 7:56 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
loen said...
Someone metioned getting rid of spysherrif's spell using a program called redit,  I'm having this problem also and I was wondering where I could download this redit program.
I believe you mean "smitrem", you can get it from
once you've downloaded it, you must extract it (on your desktop for making it easier to find), then reboot in safe mode, and between he extracted files execute "RunThis.bat" that should clean most of stuff, but still you should scan your computer with some softs as ewido, or others, just take a look in others spy sheriff posts, some of them should work for your case.


_-*Zippo*-_

Envio editado por (ZippoLag) : 12/15/2005 7:02:17 PM GMT

Back to Top
 

liam1
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-19-2005 7:18 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
loen said...
Someone metioned getting rid of spysherrif's spell using a program called redit, I'm having this problem also and I was wondering where I could download this redit program.

he means REGEDIT a windows program which can be run by typing "regedit" in Start>Run box.
spysheriff is spyware itself and creates its own key in the registry disabling any access to the wallpaper, etc. the only way to fix the problem is deleting the key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System.
Back to Top
 

CarlisleMark
New Member


Date Joined Dec 2005
Total Posts : 5
 
   Posted 12-19-2005 8:01 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
hop Silentmute's solution for the gray wallpaper works great!  Note the key that I deleted just said "wallpaper Reg_Sz  (data not set)" .  I got my wallpaper back after the next reboot.  My system's running great!!!  One annoying "Advertisement" window still pops up, but infreqently.  One of the things that it keeps advertising is a registry cleaner, but I will NEVER buy anything from an ad-ware hustler.
 
Back to Top
 

arachnidae
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-27-2005 6:06 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Thanks silentmute, I had been having the same problem as you and spent many hours trying to get rid of the locked desktop wallpaper problem.  Following your advice, I got the wallpaper activity back...
:-)
 
Back to Top
 

JA$H Vs. SPYSHERIFF
New Member




Date Joined Dec 2005
Total Posts : 13
 
   Posted 12-27-2005 11:14 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
silentmute said:
I had the same problem. I ran spysweeper and still couldn't change the wallpaper. Then I opened up redit and navigated to the following entry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html
I deleted this key(I suggest backing it up first), everything seems fine now.

Sry, but that only restores your original desktop settings but you might still have SpySheriff which you HAVE TO get rid of (it's dificult and I don't know how to do it) because it uses all your information (email, passwords and credit card information). SpySheriff is your main problem, not the desktop. Anyone know how to get rid of SpySheriff?
Back to Top
 

dungorg
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-27-2005 12:26 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I had same problem and fixed

look at this thread :
http://www.bullguard.com/forum/5/Cannot-change-desktop-settings_25247.html

you to also remove registry key using regedit (Start -> Run and type 'Regedit')
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html

.. be careful how to use regedit if you are still a novice in computer .. ASK FOR DIRECT HELP!

.. download and run windows µsoft antispy software from:
http://www.microsoft.com/athome/security/downloads/default.mspx


hope this helps
Back to Top
 

nevermindthat
New Member


Date Joined Dec 2005
Total Posts : 1
 
   Posted 12-29-2005 9:55 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Hey guys, I am a network admin and I just thought I would chime in with my 2 cents.  I had a user get this nasty little scumbag and all I did to get rid of the spysherriff was to go into the control panel and remove the program using add/remove programs .. however, the bigger problem is that this spysherriff thing is used inconjunction with a new strain of CoolWebSearch (aka home search assistent, aka: Shopping Buddy, aka: shopping assistant .... and the list goes on.  What I ended up doing was using the program "about:buster" to get rid of it, then going to that reg. key and deleting it to get rid of the wallpaper problem.  Hope that helps ... feel free to email me if you have any Q's
Back to Top
 

julzpogi
New Member


Date Joined Apr 2006
Total Posts : 1
 
   Posted 4-12-2006 5:25 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
:p hi all!
 
ive encountered the same problem, and i panic freaked .
i though the way to get rid of it is to reformat my pc.....
but instead i try so many ways to det rid of it...
and its s failure, so if you cant defeat them... join them!
 
ive download a serial number for that spysheriff then i use it....
its a good software im telling you...
but they must not attack users like that to sell their thingnono
 
julzjumpin
Back to Top
 

PhreddyPfander
New Member


Date Joined Jun 2006
Total Posts : 1
 
   Posted 6-20-2006 2:37 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Go to the following key...

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies

If this key contains anything OTHER THAN "Explorer" Back them up and delete them. Had a laptop brought to me that had picked up "Spy Sherif". You couldn't change the desktop background on it either and doing the above fixed it.

Also see the following web page: http://spywarewarrior.com/rogue_anti-spyware.htm which provides a comprehensive list of phoney, crappy, fraudulent antispyware products which are not worth the powder to blow them to h*ll much less even two cents of your hard earned cash. This list includes Spy Sherif and says nothing good about the paid version. The entry for Spy Sherif also has links to lavasoft and systinerals' excellent discussion of the fraudulent practices of some antispyware authors. Well worth your time to read this. Especially unerving is the link to another page on spywarewarriors' site detailing the similarities between Spy Sherif and Brave Sentry, PestTrap, PestWiper, SpyDemolisher, SpyTrooper, SpywareNo, & Spyware-Stop. A look at the screens that each of these app display as they do their magic will leave you convinced as to the real value of these applications. Lying to your potential customers and trashing their desktops is not a good way to win them over. Also changing the name of your product every once in a while in an attempt to prevent your reputation from preceding you does not strike me as a model for building a successful software business. Hmmm?

Do your homework, make an informed choice. These days anything that voluteers itself while you're surfing the web is best automatically ignored. PERIOD.

Have a pleasantly productive day...
Back to Top
 

twitchy
New Member


Date Joined Jun 2006
Total Posts : 1
 
   Posted 7-9-2006 8:07 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I had the same problem with a different spyware, I deleted the registry key and it fixed my desktop image, however now all my desktop icons have a shadow like they are highlighted, I go to display properties, desktop tab, and where it says color on the bottom right, when i change that it also changes the color of the shadow around my icons. Is there a way to fix that without pulling wires out and throwing things around? freaked
Back to Top
 

Krait
New Member


Date Joined Jun 2006
Total Posts : 2
 
   Posted 7-16-2006 1:20 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Hello Guys,

i dont seem to have the "wallpaper" reg file, but still i cant change my background and modify my desktop icons
Back to Top
 

Krait
New Member


Date Joined Jun 2006
Total Posts : 2
 
   Posted 7-16-2006 2:04 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
oh wait, i fixed it. thanks guys. but i got another problem, i cant seem to select any options from "arrange icon by" its like being disabled like the browse icon.
Back to Top
 

RT-58
New Member


Date Joined Jun 2006
Total Posts : 1
 
   Posted 7-21-2006 4:40 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Hi, i´m new and i had that problem too, i follow the instructions of delete de wallpaper file and that works, but i have one before that, i found some files on my c: hard drive named nj.exe, wintall.exe and adj.exe,  i scan my pc with the symantec antivirus and with ad-adware se, some files was founded, i deleted twice from and i hope dont apear again, but when the files was on my pc the antivirus and the adware scan dont detect the files, i need to said that one message apear on my task bar that said windows detected spyware on you computed the icon was a red circle with a withe x on the center, and a internet explorer pop-up window still apearing on my screen that said waring, spyware and bla bla bla so i dont know how to fix my pc? 
Back to Top
 

iiaziinxboi
New Member


Date Joined Aug 2006
Total Posts : 1
 
   Posted 8-6-2006 11:14 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
i just deleted the virus but then my desktop settings were grayed out and i deleted the reg key

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

then now there is a black box around my icons and i need help to get it back to be transparent...so if someone knows how to do this please help me...or if someone still have the registry key that they can export and then send to me. thatll be very helpful!

email: xvietstyle@gmail.com
AIM sn: iiaziinxboi

thank you!
Back to Top
 

ndall
New Member


Date Joined Aug 2006
Total Posts : 1
 
   Posted 8-10-2006 7:29 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I've had this problem. Located the wallpaper key in the registry mentioned above, but get a "Error deleting values, unable to delete all specified values" message when I attempt to delete it. It's not an admin account, is that why? Do I have to do it via the admin account, and where will I find the Key?

Thanks in advance for any help.
Back to Top
 

Cosmo
New Member


Date Joined Aug 2006
Total Posts : 1
 
   Posted 8-18-2006 6:07 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
To get rid of the black box around icons, try delete all items under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer but "NoDriveTypeAutoRun". Windows is a blackbox to me. I have no idea why it worked for me. Wish you luck.
Back to Top
 

silentmute
New Member


Date Joined Nov 2005
Total Posts : 2
 
   Posted 8-20-2006 6:59 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
silentmute said...
I had the same problem. I ran spysweeper and still couldn't change the wallpaper. Then I opened up regedit and navigated to the following entry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html

I deleted this key(I suggest backing it up first), everything seems fine now.


Hope that helps.
Back to Top
 

Southpaul
New Member


Date Joined Sep 2006
Total Posts : 1
 
   Posted 9-30-2006 5:49 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I just battled with the same problem all morning. I was infected with brave sentry and spy sheriff. It took away my desktop and erased all my restore dates. I had to run Adaware twice, and this helped a lot. But this annoying little popup from my system tray every 40 seconds telling my I was infected kept popping up. I used ctrl+alt+del, then clicked on process and found 'xupdate.exe' , I ended this process and all is fine now. I just rebooted and my desktop returned back to normal, although all my restore dates are still erased.
Back to Top
 

sbpruitt
New Member


Date Joined Dec 2006
Total Posts : 2
 
   Posted 12-7-2006 11:26 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
Hey guys, here's a new twist.  I took care of the registry entry a couple of weeks ago, but had the problem with the blue background in my icon text.  After going into system properties today and trying to deselect and then reselect the "drop shadow for icon", I went to my desktop and found all my icons GONE and when I went to try to redo it, the title of the windows box had changed to (approximately) "desktop icons have been taken by Pest Trap"  I went back and checked the registry, but it does not have the bad entry in it.  Any ideas?
Thanks
Back to Top
 

bigdave1
New Member


Date Joined Dec 2006
Total Posts : 1
 
   Posted 12-29-2006 7:36 (GMT +1)    Quote: Can't change wallpaper after spysherrif attackAlert an admin about: Can't change wallpaper after spysherrif attack
I can't delete the registry HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html

Every time I try I get a message saying "Unable to delete all specified values." I would really like some help with this. I'm also a complete noob so please make it as easy to follow as possible.

Thanks!
Back to Top
 
New Topic Post reply to : Can't change wallpaper after spysherrif attack Printable version of : Can't change wallpaper after spysherrif attack
34 posts in this thread.
Viewing Page :
 1  2 
 
Forum Information
Currently it is Friday, March 12, 2010 6:39 AM (GMT +1)
There are a total of 76.122 posts in 17.591 threads.
In the last 3 days there were 10 new threads and 69 reply posts. View Active Threads
Who's Online
This forum has 31123 registered members. Please welcome our newest member, Mr. Ciza.
38 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Very slow internet - probably virus (3)12-03-2010 04:54:34 (Touch)
Explorer 2010 trojan (6)11-03-2010 23:46:17 (tpa)
How to remove a redirect virus that also stops my Antivirus for updating (2)11-03-2010 23:12:02 (Philippos)
Internet browser redirect virus (8)11-03-2010 22:39:01 (404)
Redirect Virus (5)11-03-2010 20:20:15 (markusg)