"Add This Attachment".
Spy Sheriff spyware [RESOLVED]
Started by
chaosloki
, Jun 14 2005 01:09 AM
#16
Posted 14 June 2005 - 11:39 PM
"Add This Attachment".
#17
Posted 14 June 2005 - 11:40 PM
#18
Posted 14 June 2005 - 11:45 PM
Thank you.
Go to Start > Run - paste this in the box:
regedit /e c:\deskpol.txt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
Click OK.
Navigate to c:\deskpol.txt
Open it, copy the text inside and paste it here.
Go to Start > Run - paste this in the box:
regedit /e c:\deskpol.txt HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
Click OK.
Navigate to c:\deskpol.txt
Open it, copy the text inside and paste it here.
#19
Posted 14 June 2005 - 11:48 PM
k
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoChangingWallpaper"=dword:00000000
"NoComponents"=dword:00000000
"NoAddingComponents"=dword:00000000
"NoDeletingComponents"=dword:00000000
"NoEditingComponents"=dword:00000000
"NoHTMLWallPaper"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"Wallpaper"="C:\\WINDOWS\\desktop.html"
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoChangingWallpaper"=dword:00000000
"NoComponents"=dword:00000000
"NoAddingComponents"=dword:00000000
"NoDeletingComponents"=dword:00000000
"NoEditingComponents"=dword:00000000
"NoHTMLWallPaper"=dword:00000000
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000001
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"Wallpaper"="C:\\WINDOWS\\desktop.html"
#20
Posted 14 June 2005 - 11:53 PM
Ok, thank you.
One more for me, then I'll get you fixed up
Go to Start > Run paste this in the box:
regedit /e c:\deskpol2.txt HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies
Navigate to c:\deskpol2.txt, copy the text and paste it here.
One more for me, then I'll get you fixed up
Go to Start > Run paste this in the box:
regedit /e c:\deskpol2.txt HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies
Navigate to c:\deskpol2.txt, copy the text and paste it here.
Edited by bananafanafo, 14 June 2005 - 11:54 PM.
#21
Posted 14 June 2005 - 11:55 PM
okay, thanks alot
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum]
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"=dword:00000001
"{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}"=dword:40000021
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"=dword:00000020
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum]
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"=dword:00000001
"{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}"=dword:40000021
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"=dword:00000020
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
#22
Posted 14 June 2005 - 11:57 PM
Ok great, I'll be right back!
#23
Posted 14 June 2005 - 11:59 PM
okay
#24
Posted 15 June 2005 - 12:07 AM
Please navigate to this file and delete it:
C:\WINDOWS\desktop.html
Copy everything inside the code box below (starting with REGEDIT4). Paste it into Notepad. Go up to "File > Save As", then click the drop-down box to change the "Save As Type" to "All Files". Save it as fixsheriff.reg on your desktop. *Make sure there is NO blank line above REGEDIT4!
Double-click fixsheriff.reg on your desktop. When asked if you want to merge with the registry click YES. After the merged successfully prompt, reboot your computer and you should be able to change it back to normal.
C:\WINDOWS\desktop.html
Copy everything inside the code box below (starting with REGEDIT4). Paste it into Notepad. Go up to "File > Save As", then click the drop-down box to change the "Save As Type" to "All Files". Save it as fixsheriff.reg on your desktop. *Make sure there is NO blank line above REGEDIT4!
REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "ForceActiveDesktopOn"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "Wallpaper"=-
Double-click fixsheriff.reg on your desktop. When asked if you want to merge with the registry click YES. After the merged successfully prompt, reboot your computer and you should be able to change it back to normal.
Edited by bananafanafo, 16 June 2005 - 09:05 AM.
#25
Posted 15 June 2005 - 12:23 AM
okay i just rebooted and the system seems to be running fine now, thanks alot for the help
Thank You!!
Thank You!!
#26
Posted 15 June 2005 - 12:26 AM
Your very welcome!!
Congratulations your log is clean! Great job on the clean up
I recommend checking the http://www.microsoft.com website periodically for critical updates to install.
Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
Ewido Security Suite <= Protection against Trojans, Worms, Dialers, Hijackers, Spyware, and Keyloggers.
Detect and Remove Programs:
Congratulations your log is clean! Great job on the clean up
I recommend checking the http://www.microsoft.com website periodically for critical updates to install.
Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
Ewido Security Suite <= Protection against Trojans, Worms, Dialers, Hijackers, Spyware, and Keyloggers.
Detect and Remove Programs:
- How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
- How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
- Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
- Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
- MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
- Google Toolbar <= Get the free google toolbar to help stop pop up windows.
- Firewall<= A firewall is definitely a must have. Three good free versions are Sygate, Kerio, and ZoneAlarm.
#27
Posted 15 June 2005 - 01:36 PM
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users