Search : in
By :

Background message "Warning! Spyware detected

Last answer on Aug 31, 2009 4:04:56 pm BST Griff, on Jul 14, 2008 9:50:24 pm BST 
 Report this message to moderators

I let my roomie use my comp while i was away for a few weeks. I returned to find "Warning! Spyware detected on your computer! Install antivirus or spyware remover to clean your computer" as my background message. I tried to place a new background on but this message still appears in the middle. I just bought Norton 360 but it doesn't seem to be detecting it. Also if I leave my computer idle for too long a blue screen pops up with a bunch of computer nomenclature and eg. bogus_driver or something of the sort being the problem. If I hit any button on the keypad it will close that screen and it will no longer pop up until the computer is idle again.

Best answers for « Background message "Warning! Spyware detected » in :
Warning: rmdir(..): Directory not empty Show Warning: rmdir(..): Directory not empty If you are attempting to delete a PHP file and that you get the error message: Warning: rmdir(..): Directory not emptyť. This might mean that the directory is not empty. To be able to...
NTLDR - Boot.ini - NTDETECT Missing (no Windows cd) Show NTLDR - Boot.ini - NTDETECT Missing (no Windows cd) If you have the installation CD of Windows, see this tip. If you do not have it, then follow the procedure below: You have a message warning you that one of...
NTLDR - Boot.ini -NTDETECT missing ShowNTLDR - Boot.ini -NTDETECT missing Recovery Console Repair XP Recovery from the Windows CD You have a message warning you that one of these files is missing: NTLDR is missing NTLDR manque. Entrez CTRL+ALT+SUPPR pour...
Error Message: Disk Boot failure ShowError Message: Disk Boot failure-insert system disk and press enter Solution 1: Ensure that your drives are empty Solution 2: BIOS set up Solution 3: New hard drive configuration Solution 4: Hard drive not properly plugged in Solution 5:...
[VBA] Detecting changes in cell Show[VBA] Detecting changes in cell The Event Change feature of a sheet will detects the change in the active cell but it gives no information about the content. The example given below will help you to find out if the cell was changed,...
Download Spy Sweeper ShowA very good antispyware which possesses, according to its publisher, the most sophisticated spywares detection. Like CounterSpy, Spy Sweeper is the world leader in fight against spywares!
Download Messenger Detect ShowWith Messenger Detect, you can monitor and record automatically and secretly all the conversations on MSN, AOL (AIM), Yahoo chat, ICQ as well as network chat. It allows you know what your employees are talking about on the network or you would...
Intrusion detection systems (IDS) ShowIntroduction to intrusion detection systems An IDS (Intrusion Detection System) is the term for a mechanism which quietly listens to network traffic in order to detect abnormal or suspicious activity, thereby reducing the risk of intrusion. There...
Attack detection ShowAnalysing logs One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short). In general, servers store logs of their activity, and in particular any errors encountered, in files. Therefore, after a computer...

1

murphy, on Jul 15, 2008 12:53:07 am BST

I got this spyware/trojan also - replaced my picture on screen with same saying. Continually popped up messages saying I was infected, click here for spyware, etc. Changed my privacy settings to accept all cookies. Slammed me with ads. Was a particularly insidious problem. Since I am not techy inclined, I went to Office Max and bought a disk called PC Restoration (save the receipt - you need numbers off it). You plug in the disk, and it takes you to a web site where you get one of their techs. You let him log onto your computer through a process they give you. It took them hours to fix it - but they did. They keep working on it until it is fixed. Cost $99 for the disk. That is the expensive way I guess - but it worked for me.

Reply to murphy

124

zahid, on Sep 21, 2008 5:46:14 pm BST
  • +3

I got this spyware/trojan also - replaced my picture on screen with same saying. Continually popped up messages saying I was infected, click here for spyware, etc. Changed my privacy settings to accept all cookies. Slammed me with ads. Was a particularly insidious problem. Since I am not techy inclined, I went to Office Max and bought a disk called PC Restoration (save the receipt - you need numbers off it). You plug in the disk, and it takes you to a web site where you get one of their techs. You let him log onto your computer through a process they give you. It took them hours to fix it - but they did. They keep working on it until it is fixed. Cost $99 for the disk. That is the expensive way I guess - but it worked for me.

Reply to zahid

202

Jj, on Jul 11, 2009 8:39:13 am BST
  • +3

Take a look here on how to solve it:
http://www.geekpolice.net/virus-removal-guide-t8083.htm

Reply to Jj

195

idear, on May 20, 2009 12:19:09 pm BST

You may try this tool,
It can scan your whole registry, repair most windows error.
I google this tool,it works well.
free scan limk http://www.google.com/...

Reply to idear

2

phanthom309, on Aug 3, 2008 5:58:51 am BST

http://billjr.spaces.live.com/blog/cns!28cbd6442f406227!675.­entry

this link will give you step by step instructions on how to remove this problem

blue screen warning spyware detected

Reply to phanthom309

5

needhelp, on Aug 18, 2008 2:41:06 am BST

That link is unavailable. Can you help?

Reply to needhelp

3

chevy_77, on Aug 17, 2008 8:11:21 am BST

I just received the exact same thing on my PC tonight. Something popped up and wanted me to install it or block it??? I had NO idea what it was and it didn't seem right, due to nothing like that happens when my PC needs an update. Usually has that yellow caution type symbol down in the taskbar by the time.....So when this weird one popped up I clicked block it. I did a virus scan and also a spyware scan. 3 came up but then a 4th one. I decided to try fixing it myself and deleted all 4. BUT I still have that same warning up on my main screen/desktop and also it won't allow me to restore it back to a different date.

Can you please tell me what you did and how????

PLEASE AND THANK YOU!!!!!

(all I was on at the time was Facebook site and that thingy popped up then all went to poop)

Pam

Reply to chevy_77

126

Vasu, on Sep 22, 2008 1:56:13 pm BST

I can't get away!

Reply to Vasu

7

su, on Aug 18, 2008 6:16:08 pm BST

Start the Windows in safe mode and search for .bmp file which shows the same as background. select last fourletters of that .bmp file and search in the windows for all the files. and search in registry also.

once you done restart the computer. Install the you ethernet drivers if you miss any.

gpedit.misc to change the hidden display property to disable in system settings.

Reply to su

8

Debbie, on Aug 19, 2008 9:23:06 am BST
  • +1

Hi I've just had the same problem over the weekend and have had success removing what turned out to be a large number of trojan viruses which found their way in through a fake email ecard I received.
I used the Dr Web Cure it programme which is free www.freedrweb.com/
If your computer won't stay on long enough for you to download it off the internet which is what happened to me, then what I did was to download it from another computer onto a cheap disk I bought from asda. I then started my computer in safe mode, inserted the disk, and the Dr Web download icon popped up after about a 20 second wait. Just click on it (it took me about 10 goes before it wanted to activate) and then follow the download instructions.
I would recommend the 'Complete' scan. I ran the express scan first which allowed me delete about 7 viruses but when I ran the complete scan it found even more. The complete scan takes 2 hours.
Hope this helps, Debbie.
PS I'm no computer nerd, in fact I don't have a clue about the things, but I found this process quite simple and more importantly, successful. Good luck!

Reply to Debbie

137

kathryn, on Oct 6, 2008 12:52:54 pm BST

You are brillianttttttttttttttttttttttttttttttttttttttt i had my desktopand screen saver tabs lost after downloading antivirus 2008 from microsoft and have been reading how to fix the problem a lot of the cures went over my head yours was the easist by far to do thank you sooooooooooooooooooooooo much youve made the problem easy to fix

Reply to kathryn

190

Marco, on Mar 24, 2009 5:11:17 pm GMT

You are a star!
Been working on this problem for weeks. Thankyou... my daughter can finally stop nicking my laptop!
I used a pen drive thing instead of a disk.
Top marks.. cheers!

Reply to Marco

197

Josettte, on Jun 9, 2009 7:55:29 pm BST

Uhh, I tried to the web cure you suggested and I got it to download on my laptop just fine.But every time I try to run it,it never starts. What should I do? I really messed up my computer.

Reply to Josettte

12

madshady, on Aug 21, 2008 8:06:59 am BST

Hey mikethedike

1.it's may be good idea in display settings after that warning there isin't any desktop tab in it that's the problem too

2.and another problem that in my computer there was a adware so i put it into qurantine and deleted, but it also show that screen ;(

Reply to madshady

19

Jack, on Aug 21, 2008 11:21:10 pm BST

Did you ever figure out how to fix the problem? I also am missing the desktop tab. Since I don't normally go to these websites would you mind just e-mailing me directly???
Thanks

Reply to Jack

13

mikethedike, on Aug 21, 2008 9:02:21 am BST

Hi mad shady,
I am sorry, but i dint get you. Can you explain in brief so i can help you out of this problem

awaitng

Reply to mikethedike

131

dennisb51, on Oct 1, 2008 5:31:39 am BST

Mine says its windows warning message and under that it says spyware detecter
tells me to please run my virus scan to eleminate the virus and it shows two different viruses ???
never seen them or this damn thing in the center of my desk top and my back ground color is now white.
I deleted and uninstalled all its componits and its still there and McAffee, says i am clean
how do you get it off the screen and my color back to blue on my desk top??

windows knows nothing of it, either

Thanks
Dennis

Reply to dennisb51

138

Alex, on Oct 7, 2008 6:03:07 pm BST

Dennis, I am getting the same error message on my dell laptop. I cannot get that stupid error message off my screen. I have a white screen and that error message. Were you successful in getting it off? what did you do? Anxious to find out.
Thanks
Alex

Reply to Alex

14

pramod, on Aug 21, 2008 9:09:51 am BST

Hi mike,
I too got the same screen saying "your computer is been affected and use a spyware to clean your computer". I could remove the program files containing the Antivirus XP 2008 but couldn't remove that blue screen. And today when I was downloading one of the adobe photoshop softwares the screen colour changed to white bearing the same message. Please do help me to remove the virus from the computer. Please do help..
Waiting eagerly for the solution..
thanks

Reply to pramod

139

Piramid, on Oct 9, 2008 7:06:05 pm BST

Best way is to install microsoft malicious software removal tool and then run it, once its done u'll get the list of softwares which u can remove
Live one care is good but wants many updates also slows down the pc speed
AVG will give up in some time and does not actually work as an antivirus but works like a small firewall
NORTON needs updates now and then and after some time it turns into an addware and screws the pc and therefore we have to format the hard drive

Reply to Piramid

16

Ebomb, on Aug 21, 2008 10:20:55 pm BST
  • +1

Here is how to do it. Its already been posted, but this is the definitive answer:

-Search your drives for *.bmp
-Find the one that matches your background
-Note the last 3 characters before the .bmp - mine was called phccekj0e3cn.bmp
-Search your drives for the last 3 characters noted in previous step. in my case i searched on *3cn
-This search resulted in 4 files for me.
-Go to your task manager, look under the processes tab, and find the process that matches the name of one of the files you are trying to delete (the .exe file)
-end the process - mine was called lphccekj0e3cn.exe
-delete all files found in your search
-reboot and you should have your display tab back for background right-click -> properties
-if you do then you are good to go. set your background and don't let other people who have no clue (most people) use your computer

Reply to Ebomb

24

pramod, on Aug 22, 2008 9:34:14 am BST

Hi Ebomb,
Thank you so much man...... thanks a million.... thanks a trillion.... thanks a lot. I could fix the problem completely. Now no virus. I got backthe desktop and screensaver options in desktop properties window. Your method really worked..... Thank you buddy... be in touch..... can I get your personal email id.... mine is attitude_dedication@rediffmail.com.
Thanks once again and take care..

Reply to pramod

25

chris, on Aug 22, 2008 9:58:08 am BST

I wanna kiss you.........your info about blue screen virus worked a treat

Reply to chris

33

bsmon1, on Aug 23, 2008 5:18:08 am BST

Very helpful ebomb, you da man, or woman, or whatever, but thanks, i appreciate your instructions, and it seems to have worked.... it was very frustrating having that crap when i logged on every time, but you saved the day...

thx again, dude...

Reply to bsmon1

50

Elizabeth, on Aug 25, 2008 1:07:08 pm BST

Got the same problem over the weekend; followed your instructions, removed the .bmp file and, voila, problem solved. Wow, that was a REALLY annoying problem. Thanks so much!

Reply to Elizabeth

51

Elizabeth, on Aug 25, 2008 1:08:01 pm BST

Got the same problem over the weekend; followed your instructions, removed the .bmp file and, voila, problem solved. Wow, that was a REALLY annoying problem. Thanks so much!

Reply to Elizabeth

54

cal, on Aug 26, 2008 3:31:05 pm BST

Hey dude Thanks for the advice but im still stuck:'(
Basically i can see the file in the *.bmp place where im searching but whenver i go to delete it
it says cannot delete: cannot read from the source or disk or sumut
any suggestions dude
any help would be greatly appreciated xx:(

Reply to cal

59

mikethedike, on Aug 27, 2008 5:06:21 am BST

Try to do it in safe mode

Reply to mikethedike

73

Frustrated, on Aug 29, 2008 1:53:33 pm BST

Hello, I've been googling everything, I've done all the instructions given out there, except for downloading anysoftware, because I can't get to the internet, I've done the tskmgr instructions and deleted the files, I've restarted in safe mood and disabled turn off system restore, I've run avg after deleting from registry files and search my entire computer and it found those trojans even after I deleted from registry and taskmgr. So when it showed that AVG asked if I wanted to remove I said remove, so I'm thinking it's gone, I can't find anymore of those files. However I did the policies thing for desktop to be enabled again, I changed my desktop and my screensaver went back to what I had before Antivirus, I restarted my pc and boom that message in the middle of my desktop is still there.

It wont go away, I can't connect to internet or anything.

What am I missing what am I doing wrong????

Reply to Frustrated

74

3@NiL, on Aug 30, 2008 9:05:10 am BST

Hey ebomb, thnks mate for the solution. Although i did find a solution earlier where u had to change the registry value , it was just a temporary solution and every time i restarted the problem would resurface. but with ur solution the problem has been solved for good. Thanks once again.

Reply to 3@NiL

90

Ann, on Sep 8, 2008 3:19:21 am BST

I did everything.. but when i got to the task mgr part.. i couldnt find the process to turn off. Nothing fit the searches i found. But i deleted everything in the search that came up. However, my Background tab still does not show. What do i do?

Reply to Ann

91

mikethedike, on Sep 8, 2008 9:25:55 am BST

Ok Ann, pls follow the below given info

The first time this thing runs it changes entries in your registry to hide the 'Desktop' and/or 'Screen Saver' tabs
-In the registry navigate to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\­Policies\System
-delete entries 'NoDispBackgroundPage' and/or 'NoDispScrSavPage'


Check out your display properties again, they should be back to normal.

Empty your recycle bin to get rid of it for good

Rebooting at this point is probably a good idea.


Melisio Mascarenhas
India

Reply to mikethedike

95

Ana, on Sep 10, 2008 5:48:53 am BST

I read the instructions you provided to remove the annoying background screen, however i wish i would have read this before i installed an anti virus software the removed the annoying screen and the pop ups forcing consumers to purchase their product. I now have the screen saver problem that appears when computer is idle advising there was an error in the installation of a new software and it names all these files and suggest a reboot. The computer appears to be rebooting but it is not. Its like some sick persons way to annoy you with a screen saver that is an eye soar. So my question is how do i get rid of this and i know you have posted directions several time sorry if i am not getting it. Each time you posted it you ask that we look for the original file or even a file with bogus numbers. When i do the search for the file .bmp it pulls of 1400 files of pics which i totally understand. What i dont get is which file it could be if it is in that section or did i miss my chance when the anti virus software i installed deleted it. I just want to change the background on my computer and take the screen saver off. I dont have these tabs and maybe i was just fast reading but it appears to be a problem that is linked. Also i dont mean to sound like an air head but a little fix it for dummys instructions would be helpful. I also want to point out this is sad i can not fix it my self as i did get an associates degree in IT. Maybe it was not the major for me but i am very fasinated by it.

Reply to Ana

96

Ann, on Sep 11, 2008 1:35:12 am BST

Thanks! it worked. i have my bg back now

Reply to Ann

100

Gratefull !!! Very, on Sep 13, 2008 6:13:45 pm BST

Thanks, I followed Ebomb and your instructions and I got rid of it completelly....after 3 days of downloading all sort of crap.

Thanks again!!!

Reply to Gratefull !!! Very

113

Grateful, on Sep 18, 2008 10:26:31 pm BST

Thank you sooooo much I had this damned thing for a few days before I finally found it, but still had the issue with the background you made it sooo simple, but one last thing. Every time I click anything in an webbrowser I am redirected to other pages that have nothing to do with what im searching for. any clues?


Thanks
Robert S

Reply to Grateful

130

Mike, on Sep 30, 2008 11:52:58 pm BST

I tried to do the following:

-In the registry navigate to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\­Â­Policies\System
-delete entries 'NoDispBackgroundPage' and/or 'NoDispScrSavPage'


and now I have no desktop just a blue screen. Can anyone help?

Reply to Mike

142

Help, on Oct 10, 2008 11:55:35 pm BST

Hey i cant find registry what is it

Reply to Help

147

Steve, on Oct 15, 2008 11:00:15 pm BST

Click Start -> Run -> Type regedit

Be careful. You can screw your entire computer up.

Reply to Steve

99

Gratefull !!! Very, on Sep 13, 2008 6:08:43 pm BST

Thanks, had the same problem. I followed your instructions and was able to get rid off the stupid virus!!!

Thanks AGain

Reply to Gratefull !!! Very

104

nomad, on Sep 16, 2008 2:59:39 am BST

Hi EBomb
So far so good but I cannot see the file in task manager.

i have deleted the files from search. But it is still on my desktop.

Please help there are no similar files in Task Manager and I dont want to stop something that I am not sure of.

Nomad

Reply to nomad

106

matt022, on Sep 16, 2008 3:22:36 am BST

Hey i had the same problem and ebomb your directions helped me thx.
but now something strange has happened with my browser
anytime i Google search something
and click on one of the search links it redirects me and takes me to some worthless shady website
the only way i can access websites is by typing in the url
my internet is also running very slow now
i get the feeling some form of spyware is still in my comp and using my net
any help would be greatly apreciated !!!
thank you!!!!!! verymuch

Reply to matt022

108

taniaaaaa, on Sep 16, 2008 11:35:08 am BST

Just wanna thank u SOO much it really scared me when i got that BSOD! thought i had a scaryyyy viruss!!! but following ur step by step instructions couldnt have been easierr to remove that stupid screensaver! you're a legendd!! thanks again!!!

Reply to taniaaaaa

114

Reyna, on Sep 19, 2008 12:30:09 am BST

How do you search your drivers?

Reply to Reyna

133

jenn, on Oct 6, 2008 12:41:47 am BST

PLEASE HELP!! im having the same problems as everyone else. i think i may have a virus. my screen savers is now all white. last week it said the same message that the other people were talking about. I AM VERY NEW to computers and have no clue what you are talking about. is there any way you could give a bit more detailed instructions? I have tried searching in drives for .bmp & the only thing that comes up are pictures of different screen savers and other s. savers things ive never seen. i dont see any.bmp after the files. please help

Reply to jenn

134

jenn, on Oct 6, 2008 12:41:28 am BST

PLEASE HELP!! im having the same problems as everyone else. i think i may have a virus. my screen savers is now all white. last week it said the same message that the other people were talking about. I AM VERY NEW to computers and have no clue what you are talking about. is there any way you could give a bit more detailed instructions? I have tried searching in drives for .bmp & the only thing that comes up are pictures of different screen savers and other s. savers things ive never seen. i dont see any.bmp after the files. please help

Reply to jenn

140

Weed, on Oct 10, 2008 2:19:49 am BST

Thanks man - thanks so much - you saved me lotsa grief.

Reply to Weed

143

dex, on Oct 11, 2008 4:59:48 pm BST

The bmp file doesn't show up in my search?

Reply to dex

145

retfam, on Oct 12, 2008 7:10:43 pm BST

You resolution would probably be great, but my task manager is disabled. Happen at the same time this lovely virus appeared. Any suggestions?

Reply to retfam

146

dex, on Oct 12, 2008 7:23:01 pm BST

My task manager is also disabled

Reply to dex

156

yoyi, on Oct 23, 2008 4:07:55 am BST

Thanks!

mine was phcelhj0e1e1

Reply to yoyi

158

psha84, on Oct 26, 2008 3:42:01 am GMT

Hye i just got the same mssg as others. now my problem is i duno wer to start...wer do i find the drive...i mean wer to click got im so helpless nw...just got this notebook 2 month ago n now it's damn slow!! please helpppp

Reply to psha84

161

manushyamrigam, on Nov 7, 2008 12:44:10 pm GMT

Thanks a lot for your precise advice. keep it up buddy!

Reply to manushyamrigam

181

TheVinMan, on Feb 7, 2009 9:55:09 pm GMT

Ebomb

Let me tell you what happened to me and maybe you can help me and also give a warning to others.
I consider myself to be pretty careful when downloading anything onto my pc. Well it just so happens that a volcano is about to erupt in Alaska so I wanted to find live web cam coverage. So I was lead by Google to what looked like an authentic web site When I went to down load the viewer that was required to view said video the normal Norton warning you could be downloading a virus ect ect ect. came up.
after installing the viewer well you guessed it every Trojan and worm you can imagine. I was majorly infected after many different virus sweeps the system seams to be clear, however I am left with a blue screen and can not load any background or wallpaper and all I have read here and tried to find bmps and check the reg edit for the suggested codes I find none if you can suggest any thing else I would appreciate it.

Reply to TheVinMan

189

d, on Mar 11, 2009 5:22:39 am GMT

This isn't working for me!

When i search for *.bmp i don't get anything like what you got, so i can't follow the instructions. no long weird filenames.

Reply to d

193

Bush_sucks, on Apr 5, 2009 8:38:48 pm BST

Hey, umm Ebomb... yeah I'm pretty sure ur thing works but when i open the display properties I can't change the desktop theme and i can't even click on the wallpapers, so i don't know what the *.bmp thing is so yeah... hope you can reply soon i need help! Thanks

Reply to Bush_sucks

204

Melonss, on Jul 28, 2009 7:15:48 pm BST

Hi . so , obviously , i have the virus stated . and i think your method will work .. it's just , i have a couple of problems ..

for one , when you say look for your wallpaper , do youu mean the 'YOUR SYSTEM IS INFECTED' message which is currently on the background , or do you mean the one before that? because i have found the one before that , but seeing as i have created numerous new accounts to try and rid my computer of the virus , the wallpaper was a default . it was just called 'wallpaper'. when searchingg *per , about 400 results came up , some of them just harmless default games like minesweeper .

secondly , whenever i press ctrl alt del , or try andd get to task manager another way , it comes up with a box saying ' your system is infected ' or , if i continue pressing it ' this has been disabled by your administrator ', making me unable to access it . i am the administrator and i did not disable it.

have any ideas of how i can still fix the virus ? also , when you had this virus , did you experience messages coming up when you tried to get on some websites , saying that the security preference or something , prevented you from being on it ? or did some just close completely ? because thats whats happening with mine .

basically , i have a bad feeling its conkedd , and that there's no going back .

Reply to Melonss

17

Ebomb, on Aug 21, 2008 11:04:43 pm BST

Ugh! I got ahead of myself in the previous post. If you followed those directions you still will be missing the 'Desktop' and/or 'Screen Saver' tabs in your Display Properties. (right click on background and select properties)

Also, just deleting the background image is not enough! This is a nasty sucker running a process, it may not find the background anymore but its still doing harm. i.e. my computer started blue screening and rebooting over and over after like 20 min

So here is the complete definitive answer: (thank you again for previous posts pointing me in the right direction)

REMOVE THE FILES FROM YOUR HARD-DRIVE:
-Right-Click on My Computer and select Search...
-click All files and folders
-search for *.bmp (all or part of file name)
-Find the one that matches your background
-Note the name of the .bmp file - mine was called phccekj0e3cn.bmp (copy and paste into notepad or something as you weill need this later, or write it down as your computer can reboot)
-Search your drives for the last 3 characters noted in previous step. in my case i searched on *3cn
-This search resulted in 4 files for me.
-Go to your task manager, look under the processes tab, and find the process that matches the name of one of the files you are trying to delete (the .exe file)
-end the process - mine was called lphccekj0e3cn.exe
-delete all files found in your search

REMOVE REGISTRY ENTRIES: (not as important since the files are no longer there but still good idea)
-Start -> Run
-regedit
-Edit -> Find
-I searched on *3cn (the last 3 characters) but this returned some valid registry entries. I suggest you either carefully delete all entries that look they are related. I found 5 or 6 valid entries, but they were obvious to me to not be related.
-typically they will have the full name like "lphccekj0e3cn" In fact you could probably search on whatever the .exe name was (minus the .exe extension) and you can surely delete all those entries.

FIX REGISTRY ENTRIES:
-this is what i missed in the previous post. The first time this thing runs it changes entries in your registry to hide the 'Desktop' and/or 'Screen Saver' tabs
-In the registry navigate to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
-delete entries 'NoDispBackgroundPage' and/or 'NoDispScrSavPage'


Check out your display properties again, they should be back to normal.

Empty your recycle bin to get rid of it for good

Rebooting at this point is probably a good idea.

Reply to Ebomb

18

Marie, on Aug 21, 2008 11:12:01 pm BST

Hi Ebomb:
Thank you so much for your help. I did not know what to do about this problem. But now it is resolved. Your step by step description worked great for me.
For everyone!
Follow the description and you do not need to install anything.
Thanks again. Marie

Reply to Marie

20

Bloody Puppy, on Aug 22, 2008 2:27:10 am BST

Dude, thank you so much Ebomb. Clear instructions, and they worked perfectly. You rock.

Reply to Bloody Puppy

21

chevy_77, on Aug 22, 2008 2:50:58 am BST

I got rid of all the viruses and such/background etc.....BUT, I am also having a problem with my computer.....
It show's my Windows Live OneCare antivirus/spyware is working 100% BUTTTTT, whenever my kids/myself are on the computer, it ALSO shuts down to that blue screen with warnings and such////then reboots itself over and over again....till I hit the enter button then it goes back to whatever we were doing on the computer. Why isn't this one fixed???? I'm lost and confused.....

Please help since the LIVECARE ain't fixing up that problem.....

Reply to chevy_77

29

JohnC, on Aug 22, 2008 5:33:17 pm BST

It's not really rebooting -- it's an "evil genius" screen saver. Check your screen saver tab to see if the goofy looking name (as described by Ebomb) is still selected. If so, pick something else (or none), then search for the .scr file with that name and delete it. You could still have the registry entries too, so search for those in regedit and delete them.

If your screen saver tab is still missing, go back to Ebomb's last post above and try again -- you may have missed one of the steps.

Reply to JohnC

26

monica, on Aug 22, 2008 1:59:40 pm BST

Ebomb - you are a lifesaver!!
Thank you so much for your instructions, I have downloaded so many anti spyware and antivirus programs over the past few hours trying to get rid of this thing. Turns out all I needed to do was follow your simple instructions and voila, the problem is gone!!
SO GRATEFUL!
Everybody follow these instructions and it will be fixed, i can guarantee it!

Reply to monica

28

JohnC, on Aug 22, 2008 5:28:01 pm BST

Thanks, Ebomb! Worked perfectly, VERY clear instructions.

You DA MAN!

Reply to JohnC

30

chevy_77, on Aug 22, 2008 7:50:42 pm BST

Hi!!! THANK YOU SOOOO MUCH for those EASY STEPS to go by. The other replies were kinda confusing, but yours WAS GREAT AND SEOOO EASY!!!!

BUT>>>>>>>>>>I went to where you stated this: FIX REGISTRY ENTRIES:
-this is what i missed in the previous post. The first time this thing runs it changes entries in your registry to hide the 'Desktop' and/or 'Screen Saver' tabs
-In the registry navigate to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
-delete entries 'NoDispBackgroundPage' and/or 'NoDispScrSavPage'

I did do that and I was able to have my properties back/able to change my settings for screen saver.......BUT>>>>>that file is STILL THERE AND I DONT KNOW HOW TO DELETE IT FROM MY SCREEN SAVER LIST......
I clicked on it but this box pops up and is very ODD looking...don't wanna click anything on it as I'm scared it may just come back to attack me...lol. The file that came up in my pc that won't delete from my screensavers list is called: blphc11pj0ep57

HOW DO I DELETE THAT??????

Please and THANK YOU SO MUCH!!!!!!!!!!

Reply to chevy_77

31

Perm, on Aug 22, 2008 11:22:03 pm BST

E-Fizzle,

I owe you big time! No more gutter surfing for me :-)

Reply to Perm

32

bigjeff, on Aug 23, 2008 2:35:08 am BST

Ebomb ...........THANK YOU SOOOOOO MUCH you are the coolest. i wish you the best.

Reply to bigjeff

38

amrearoz, on Aug 24, 2008 9:54:28 am BST

Hey Thanks a lot.....

I was so terrified of what was happening.... being a computer illiterate and all. Thank you so much for those detailed steps....
Cheers

Reply to amrearoz

44

Daniel, on Aug 24, 2008 7:47:34 pm BST

Ebomb,

I tried everything you did in the first step and restarted my computer and now my screen is just blue and still I cannot change it. So I went back and you created new steps and I thought "great! my answer!" but you asked my to get my last three characters which I had deleted and forgotten, but I know they are not the same as yours were. I emptied my recycling bin so there is no way to find them. what should I do?

Reply to Daniel

45

Noviss, on Aug 24, 2008 8:54:50 pm BST

Hi Ebomb! You're a starrrrrrrrrrr! Totally noviss like I jus followd yr step bistep . It WORKED !!!!!!!!!!!!!!

Reply to Noviss

52

Kristy, on Aug 26, 2008 4:19:16 am BST

Hey,

Your info was great!... everything worked just as you said except when I tried to delete the files access was denied... I must have a more advanced version of this virus.. Do you have any suggestions?

Thanks!
Kristy

Reply to Kristy

53

mikethedike, on Aug 26, 2008 5:18:06 am BST

Wait

1) which method did you use ??

2) the scan spyware method??

or the other ones (search sepecific files one)

if the spyware method

then the software hasnt been installed properly

try uninstalling and reintall it once more

follow the steps again

then try to fix it

if its the second method then u have to run ur system in safe mode, then delete it

awaiting comments

Melisio Mascarenhas

Reply to mikethedike

55

CyberKid, on Aug 26, 2008 8:15:16 pm BST

Hey Ebomb! You are the BEST! I really apriciate your job! I believe you saved many many people!
Although I have a question to make and I would be thankful if you reply me. Before I read your post I tried Superantispyware which I think removed the bmp files and the exe that you refer to be found in taskbar menu>proccesses. I believe it worked because I didn't find neither the bmp files nor the exe. So the only I had to do was to clean my registry...well hopefully, I made a search but I found nothing. Finally I deleted the 2 files that hide the desktop and screensaver tabs. Right now, everthing seem to be working good. My question is: Do you think I have to do something else? I had the bad idea to restore my system at the point before using superantispyware (which means the point in total chaos), but I didn't do it. Should I do it and follow your help from the start or not?
I'm looking forward for your reply! Thank you again!

Reply to CyberKid

58

Jon, on Aug 27, 2008 3:41:56 am BST

Dude, Thank you so much. I could seriously kiss you.. LOLLL

Thanks alot man, Keep it real.


- Jon

Reply to Jon

75

LostSteak, on Aug 30, 2008 12:00:14 pm BST

Hi ebomb,

It is great that you provided a step by step instructions, of which i will confirm work.

I would also recommend people to install a virus scanner to go with this. I am running Avast 4.8 home addition, it is free and it found this for me. and fixed it on a machine i was working on. The only thing it didn't do is delete the back ground and bring back the tabs on the display setting.

Nice post,

Regards

-LS

Reply to LostSteak

83

thanks!, on Sep 4, 2008 4:25:55 am BST

Thank you ebomb! Your instructions were so easy to follow and they worked perfectly!

Reply to thanks!

86

johnnyb, on Sep 7, 2008 12:56:55 pm BST

I too have the same virus. I tried your fix but when i search for the *.bmp file, none show the virus backround. Where do i go from here?

Reply to johnnyb

87

mikethedike, on Sep 7, 2008 1:46:48 pm BST

I have already have posted the solution of this problem in my earlier posting

but here it one more time

REMOVE THE FILES FROM YOUR HARD-DRIVE:
-Right-Click on My Computer and select Search...
-click All files and folders
-search for *.bmp (all or part of file name)
-Find the one that matches your background
-Note the name of the .bmp file - mine was called phccekj0e3cn.bmp (copy and paste into notepad or something as you weill need this later, or write it down as your computer can reboot)
-Search your drives for the last 3 characters noted in previous step. in my case i searched on *3cn
-This search resulted in 4 files for me.
-Go to your task manager, look under the processes tab, and find the process that matches the name of one of the files you are trying to delete (the .exe file)
-end the process - mine was called lphccekj0e3cn.exe
-delete all files found in your search

REMOVE REGISTRY ENTRIES: (not as important since the files are no longer there but still good idea)
-Start -> Run
-regedit
-Edit -> Find
-I searched on *3cn (the last 3 characters) but this returned some valid registry entries. I suggest you either carefully delete all entries that look they are related. I found 5 or 6 valid entries, but they were obvious to me to not be related.
-typically they will have the full name like "lphccekj0e3cn" In fact you could probably search on whatever the .exe name was (minus the .exe extension) and you can surely delete all those entries.

FIX REGISTRY ENTRIES:
-this is what i missed in the previous post. The first time this thing runs it changes entries in your registry to hide the 'Desktop' and/or 'Screen Saver' tabs
-In the registry navigate to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
-delete entries 'NoDispBackgroundPage' and/or 'NoDispScrSavPage'


Check out your display properties again, they should be back to normal.

Empty your recycle bin to get rid of it for good

Rebooting at this point is probably a good idea.

p.s. if u have prob finding the bmp files try to find it as file named as "pch or else try 3cn"


awaiting comments

Regards
Melisio Mascarenhas
India

Reply to mikethedike

163

europe, on Nov 16, 2008 6:09:38 pm GMT

I was so thrilled with your instructions & I did everything. It took the spyware message off. I rebooted,
and then it said, malicious spyware was taken off computer. I was so thrilled, I thought I fixed it.

But, when I try to click on the internet, it
tries to & flips back off. What else can I do?

You've been very helpful. Thank you & I hope maybe you can help with this.

Thanks

Reply to europe

201

nicki, on Jul 11, 2009 1:51:01 am BST

I know this is an old thread, but the problem of spyware changing wallpaper is still around. however, it now is using a .html file, rather than a .bmp file, and it is named 'critical warning.html' and is in the system32 folder, so do you happen to have another solution to restore the wallpaper? i do have the desktop tab showing, i just cannot click on any of the wallpapers, so i am sure it is just a setting somewhere that i have yet to find....thanks buddy

Reply to nicki

94

MelisAva, on Sep 9, 2008 10:44:39 pm BST

Hi,

I followed all of your directions, and it seemed to work. But now internet explorer redirects me to weird sites that are obviously still part of this virus anytime I try to search using any search engine. I have been trying to download spybot hoping that would take care of it, but I can't even get to the sites because it redirects me everytime or says internet explorer cannot display blah, blah, blah, you know. Also, my computer has started freezing up to the point I can't do ANYTHING! Please help me.

Reply to MelisAva

97

Ann, on Sep 11, 2008 1:40:31 am BST

I get the same thing! i dont know what to do.. Please help someone.. i thought about reformatting my computer. But i wonder if there's another way

Reply to Ann

118

Gee, on Sep 20, 2008 7:59:10 pm BST

Ebomb you're a true lifesaver.

Reply to Gee

144

dex, on Oct 11, 2008 5:05:21 pm BST

The bmp file doesn't show up in my search? I'm not sure why

Reply to dex

148

Plyer69, on Oct 16, 2008 4:58:29 pm BST

Thanks so much. I was able to remove the trojan but was unable to change the background. after I followed your steps everything is fine.


Thanks

Reply to Plyer69

180

LP3, on Feb 1, 2009 8:35:19 pm GMT

What if none of the ".bmp" files are the image of the virused wallpaper? Thanks!

Reply to LP3

184

pablo, on Feb 26, 2009 6:52:12 am GMT

Hi
Did you find any files named "buritos" associated with this
antivirus 2008 infection??

Reply to pablo

205

k8 care, on Jul 30, 2009 2:06:57 am BST

Thank you so much! worked awesome i could handle all of it on my own except the simplest part. finding the background. thank you thank you thank you.

Reply to k8 care

22

AppsBabu, on Aug 22, 2008 4:18:08 am BST

Hi Ebomb,

Thank you very much for your perfect step by step instructions to get rid of the junk.

Thanks
Appsbabu

Reply to AppsBabu

27

Caitlin88, on Aug 22, 2008 4:25:10 pm BST

Hi Ebomb,

Thank you so much!!! I was about to throw my laptop across the room!!!! O man!!! You saved me thousands of dollars!

Reply to Caitlin88

35

Paul, on Aug 23, 2008 12:06:55 pm BST

I appear to have been infected with this problem. I could not find the link to which you refer. I went to the web site you listed, and did a search for the string of letters and numbers you mention to identify the entry that was supposed to contain the needed fix. My search for that string did not yield any result. Can you confirm that you had a correct listing to find the fix, or can you copy the instructions and send them to me by email? I am desperate, and have worked on this problem for over a week without success. I simply cannot get the bogus message to disappear.

Reply to Paul

37

Tony, on Aug 24, 2008 4:35:22 am BST

Paul,

The characters that E-bomb referenced were randomly generated by the trojan virus. It will be different for every one. Do a Windows Search of *.bmp files, and fine the file that is your background image. It should be a somewhat random sequence of letters and numbers. It is this sequence that you should use.

Reply to Tony

39

rediak, on Aug 24, 2008 1:19:53 pm BST

Hey ebomb! thanks so much for the info! it worked..... However I am still having problems with my internet explorer and firefox.

For example whenever i search something on google, if I click on any of the links that my search brings up, I will be taken to a different page. Theses pages are always some stupid advertising for random antivirus or anti-spyware software. i cant seem to get rid of this problem. If anyone can help me fix this, I would greatly appreciate it!

Reply to rediak

43

isaac, on Aug 24, 2008 7:44:45 pm BST

Ebom is the greatest !!!.
Worked for me too, thanks.
Also delete Rich Video Codec in IE
Thanks again

Reply to isaac

47

SicariuS, on Aug 25, 2008 9:11:32 am BST

Hi people,
Ive been havin problems with this one just now.. its very vague as per how i got it, my fiance tells me she didnt do anything out of the ordinairy..

Anyway, i caught the bugger in a very early stadium, where it hasnt altered my security settings.
I have had this one with various workstations at work and i can tell you that it isnt over by doing the steps Ebomb provided.
Although when you get it in the early stage (be sure that the screensaver didnt enable itself yet) you can remove it with those steps.

When you did them (In safe mode!! with the network cable unplugged!!) do NOT reboot until you have checked the following:

Before you do anything, Start > Run > regedit [Enter]
look for ScreenSaveActive and put that to 0 (it disables the screensaver)

Check Msconfig (start > Run > Msconfig [Enter] ) and go to the startup tab, check if theres anything that you dont trust.. or turn off everything for safety

Check your screensaver file

Go to c:\Windows\system32\drivers\etc and edit the hosts file in notepad (open with notepad)
See if theres anything else but 127.0.0.1 in there.. if there is anything else, delete everything unless you have put it there

Check your entire registry for those 3 letters (for example e2s) plus scr (search for *e2s.scr) and change that into ribbons.scr (default windows screensaver)
and do the same for .bmp

Delete all your cache and cookies, AND your system restore points and turn on security in IE/firefox

If you still have problems, i suggest installing a premium antivirus package or bringing the machine to an expert, if you dont want to pay for it, re-install windows after backing up everything :)

Reply to SicariuS

68

VitiatR, on Aug 28, 2008 6:05:38 pm BST

Hi SicariuS,

I have the same virus but I am unable to boot up in safe mode. It logs me out as soon as I try to log in just like normal. Any advice? I'm assuming it's no longer in the 'early stage'.

Reply to VitiatR

69

SicariuS, on Aug 28, 2008 8:12:04 pm BST

Hi VitiatR,

This is another form of the virus that i havent encountered yet. Try to follow my instructions in the later on message on this thread, and specifically the hijackthis steps (put it on a usb stick on a non-infected computer)

Look for suspicious files and delete them on startup (very important to remove network cable before you do this) and also delete them out of the prefetch directory (look for the same filename with .pf instead of .exe)
Then reboot and try again.

Reply to SicariuS

89

wparkinson, on Sep 7, 2008 11:31:09 pm BST

I am having this problem... Try to log into windows and it just keeps recycling.... Logging off.... Logging in... Logging off.....

ARRRG... this is a pain... Is there any way to bypass the login screen and go in and delete the bad files...

HELP!!!!!!!

Reply to wparkinson

153

LOL SO EASY, on Oct 20, 2008 10:49:30 am BST

Try safe mode?

Reply to LOL SO EASY

191

JORGE, on Mar 28, 2009 9:10:38 pm GMT

http://malwarebytes.org/ THEY HAVE A FREE SOFTWARE it help me to remove the background "warning..etc.. in just 6 minutes of scanning.

Reply to JORGE

198

JOKirk, on Jun 10, 2009 2:02:48 pm BST

It's not an issue of safe mode. It's a missing library/executable for loading Windows profiles.

Reply to JOKirk