Background changed, can't use task manager

Status
Not open for further replies.
Oh I found it I was looking in program files for some dumb reason.

I still have that black overlay on my background just so ya know. I don't where that's coming from it seems we got rid of everything else. No more pop ups, my CPU is back to running like normal not maxed out. Everything seems to be good again with the exception of the background.

I won't be around much today as I have a lot of stuff to take care of that got delayed because of the computer. I will respond to anything you say later on this afternoon when I return home.
 
One more scan then we may need to run 1 more fix.


Scan with Smitfruaffix by S!ri
* Download http://siri.urz.free.fr/Fix/SmitfraudFix.exe
* Double-click SmitfraudFix.exe
* Select 1 and hit Enter to create a report of any infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt

Attach it here
 
Ok, it's fine. Now we can get your background working again and tighten up security.

Open notepad and copy and paste next bold in it:

regedit /e peek1.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies"
type peek1.txt >> look.txt
del peek*.txt
start notepad look.txt


Save this as look.bat , choose to save as *all files and place it on your desktop.

It should look like this on your desktop:
batgif.jpg


Doubleclick look.bat
Notepad will open with some txt in it. Copy and paste the contents in your next reply.
 
sorry I need 1 more just to be sure before I give you a script

Open notepad and copy and paste next bold in it:

regedit /e peek.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components"
type peek.txt >> look1.txt
del peek.txt
start notepad look1.txt


Save this as look.bat , choose to save as *all files and place it on your desktop.

It should look like this on your desktop:
batgif.jpg


Doubleclick look.bat
Notepad will open with some txt in it. Copy and paste the contents in your next reply.
 
First delete the following file if there
C:\WINDOWS\desktop.html


Making a .reg file
Open notepad and copy and paste the text in the quotebox below in it:

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
Take the space out of system ^^^

Name the file as Fix.reg

Change the "Save As" type to "All Files" and save it on the desktop.

It should look like this:
reggif.jpg


Double-click on it and when it asks you if you want to merge the contents to the registry, click yes/ok.


Afterwards, try to change your background
 
No take out the space, for some reason when you copy from notepad and paste here it puts the space, but when I edit, it doesn't show the space.
 
Make sure your trend micro firewall is enabled, and that your AV is updated and active

Update your Java Runtime Environment
  • Click the following link
    Java Runtime Environment 6 Update 6
  • The 5th option down is the one you want (click Download)
  • Check the box to agree to terms of service
  • Check the box for your operating system and click 'Download selected'at the bottom
  • After the install Go to Start-> Control Panel-> add/remove programs (Programs and features), and uninstall any old versions
  • Navigate to C:\programfiles\Java -> delete any subfolders except the jre1.6.0_06 folder

-----------------------------------------------------------------

Uninstall Combofix
* Click START then RUN
* Now type Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit Enter.

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

-----------------------------------------------------------------------

OTCleanit! by Oldtimer
  • Download OTCleanIt
  • Click the CleanUp! button.
    • It will go thorugh the list and remove all of the tools it finds and then delete itself (requiring a reboot).

---------------------------------------------------------------------------

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  1. Set correct settings for files
    • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
    • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
    • If unchecked please check Hide protected operating system files (Recommended)
    • If necessary check "Display content of system folders"
    • If necessary Uncheck Hide file extensions for known file types.
    • Click OK

    clear system restore points

    • This is a good time to clear your existing system restore points and establish a new clean restore point:
      • Go to Start > All Programs > Accessories > System Tools > System Restore
      • Select Create a restore point, and Ok it.
      • Next, go to Start > Run and type in cleanmgr
      • Select the More options tab
      • Choose the option to clean up system restore and OK it.
      This will remove all restore points except the new one you just created.

  2. Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    5. Next press the Apply button and then the OK to exit the Internet Properties page.
  3. Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  4. Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  5. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  6. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.This is done in Vista through control panel -> windows updates.

  7. Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety

  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software
 
OK. I did everything you said and then I totally uninstalled and reinstalled my trend micro internet security 14 package. This time now it updates fine. Will the anti-virus and firewall that comes with that be sufficient protection? Also my router has a firewall in it. Does having a software firewall and a router firewall cause any kind of conflicts with each other? For instance if I need to open a port for a specific program to work do I need to open it on both?
 
If you open a port on your router to allow a program to work. You should just add the trusted program through your firewall. Sorry that I am not to familiar with trends firewall. But there should be an easy way to add trusted programs.

There is no conflict between a hardware firewall (router) and software firewall (trend)

The anti-virus and trend is good protection but you still need as I said above

1)Antispyware -MBAM or Superantispyware
2)Temp file cleaner - ATFcleaner or CCleaner
3)A program to monitor registry changes and control startups -Winpatrol or spybot

I highly recommend you install Winpatrol. It takes up hardly any resources and you won't really even notice it is there until something changes your startup registry entries. You can also right click the scotty dog in the tray and select startup info... then disable any programs that you don't want to run every time you turn on the computer. This will increase performance
 
I will definitely take your advice and install winpatrol immediately. I will also download and install MBAM and ATFcleaner. Are those programs I need to run every so often manually?
 
Yes, you should already have MBAM (malwarebytes antimalware) from earlier unless you removed it. I would check for updates and scan with it every 2 weeks or so. MBAM instructions are on page 1 of this thread if you need them.

ATF cleaner is just to clean out temporary files from surfing the internet ect. You can also run this every 2 weeks or so. Doesn't need updated. You can check and uncheck the things you want it to clean. It will remove saved passwords if you check that.

Download and Run ATF Cleaner
Download ATF Cleaner by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox or Opera:
Click Firefox or Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.
 
Got em all now. Thank you so much for your help. I couldn't have asked for a more informative person to assist me.
 
Status
Not open for further replies.
Back