Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
Missing Wallpaper; Only sidebar & desktop icons/shortcuts are disp, I once had that PRIVACY DANGER wallpaper, I followed the steps in '
dressydoll
post May 21 2008, 05:46 AM
Post #1


Member
**
Posts: 12
From: Cavite
OS: XP SP2



I had deleted the 'privacy_danger' folder in WINDOWS, but it said that 'CANNOT FIND FILE privacy_danger/index.htm. blah blah' and got a white screen desktop. I followed the steps in 'BEFORE POSTING A HIJACKTHIS LOG'. And what I got was just a sidebar 'FILE & FOLDER TASK' in Internet Explorer. Below is my HIJACKTHIS LOG.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:21 PM, on 5/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: qtvglped - {65C76A0A-B5A4-4170-8F62-947A0145677C} - C:\WINDOWS\qtvglped.dll (file missing)
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O24 - Desktop Component 0: Privacy Protection - (no file)

--
End of file - 4948 bytes

What I got?


This post has been edited by dressydoll: May 23 2008, 03:33 PM
Go to the top of the page
 
+Quote Post

Posts in this topic
- dressydoll   Missing Wallpaper; Only sidebar & desktop icons/shortcuts are disp   May 21 2008, 05:46 AM
- - sage5   Hi dressydoll, Welcome to Geeks to Go! My nam...   May 21 2008, 06:47 AM
- - dressydoll   Hi Sage. Here's your request. main.txt Decka...   May 22 2008, 06:24 AM
- - sage5   The Main.txt seems to have got cut off at: QUOTE 2...   May 22 2008, 06:26 AM
- - dressydoll   I don't know what happened but the file here o...   May 22 2008, 06:31 AM
- - sage5   Did the scan get interrupted at all?   May 22 2008, 06:34 AM
- - dressydoll   I don't think so because the scan was complete...   May 22 2008, 06:36 AM
- - sage5   OK, we will continue on. Please download the foll...   May 22 2008, 06:40 AM
- - dressydoll   Here's the combofix.txt ComboFix 08-05-21.2 -...   May 22 2008, 07:22 AM
- - sage5   Create a fresh log file with it & paste it bac...   May 22 2008, 07:35 AM
- - dressydoll   Logfile of Trend Micro HijackThis v2.0.2 Scan save...   May 22 2008, 07:40 AM
- - sage5   Hi dressydoll, Create a CombFix Script: Please op...   May 23 2008, 06:11 AM
- - dressydoll   Combofix ComboFix 08-05-21.2 - Owner 2008-05-23 1...   May 23 2008, 11:44 AM
- - sage5   Hi dressydoll, Export a Registry Key: Please copy...   May 25 2008, 06:42 AM
- - dressydoll   Sage5, here's what I got. Windows Registry Ed...   May 26 2008, 03:19 AM
- - sage5   Hi dressydoll, There seems to be a strange Deskto...   May 26 2008, 06:35 AM
- - dressydoll   sage5, I didn't see the entry that you said. T...   May 26 2008, 10:50 AM
- - sage5   Can you post me a fresh HijackThis log to check yo...   May 27 2008, 01:45 AM
- - dressydoll   Logfile of Trend Micro HijackThis v2.0.2 Scan save...   May 27 2008, 05:35 AM
- - sage5   Hi dressydoll Congratulations, your new log looks...   May 27 2008, 07:54 AM
- - dressydoll   sage5 I can't seem to find the OTMoveIt softw...   May 27 2008, 08:20 AM
- - sage5   You should have downloaded OTMoveIt in the first i...   May 27 2008, 06:15 PM
- - dressydoll   sage5 I am receiving an error message. 'Wind...   May 28 2008, 02:33 AM
- - sage5   Sounds like at least one of your System Files has ...   May 28 2008, 08:47 AM
- - sage5   Due to lack of feedback, this topic has been close...   Jun 10 2008, 06:43 AM


Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 12:40 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising