in browsing the web, my computer has contracted a program which has hijaked my desktop. It has created an image over the desktop background which properties are:

__________________________________
General: Not Available
Protocol: File Protocol
Type: HTML document
Connection: Not encrypted
Address(URL): file://C:\WINDOWS\Web\desktop.html
Size: Not Available

Created: Not available
modified: Not available

___________________________________

It first appeared covering my desktop background, making it impossible to multi-select desktop items with the cursor. It was a black add with a red eye in it for some spyware removing software. I went to the C:Windows\Web\desktop.html file and deleted it from my computer. Now the image is replaced by a flashing white, cream, and tan colored background that will not leave my pc. My hijack this log shows nothing out of the ordinary, and I have no clue how to remove this flashing screen, what do i do?!?

Dani AI

Generated

This is a classic Active Desktop overlay: an HTML page added to the desktop via Internet Explorer’s Active Desktop feature. Removing the on-disk HTML file often leaves the IE/Active Desktop registry entries in place, which produces the flashing/“Active Desktop Recovery” behaviour described in the thread — that explains why deleting the file didn’t permanently fix the problem. (Active Desktop is the mechanism that places HTML/ActiveX content on the desktop.) Microsoft: Using the Active Desktop Object. A known quick registry fix is to reset the Active Desktop HTML version or remove the offending component entry. Microsoft Q&A: change DeskHtmlVersion to 0 / Components key steps.

Recommended next steps (safe, minimal-impact order):

  • Work from Safe Mode to avoid a running process re-creating or locking the desktop HTML. Back up the registry before editing. How to back up and restore the registry (Microsoft).
  • Inspect and clean the Active Desktop keys under HKCU\Software\Microsoft\Internet Explorer\Desktop\Components and HKCU\Software\Microsoft\Internet Explorer\Desktop\General. Either set DeskHtmlVersion to 0 or delete only the subkeys whose Source / SubscribedURL point at the removed HTML. Also check policy locations that can force an HTML wallpaper (HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System and ...\Policies\ActiveDesktop) and clear any Wallpaper/policy values that reference an HTML file. (These entries are how Active Desktop and wallpaper policies are applied.) ADMX Desktop policy mapping.

Because malware commonly uses this feature for persistence, verify autostart/persistence and which process (if any) holds desktop handles:

Complementary to ’s scanner suggestion and to ’s temporary “remove the Web desktop item” fix, run up-to-date offline/on-demand malware scans (Microsoft Safety Scanner, Malwarebytes or equivalent) after the registry cleanup, and reboot to apply changes. If the per-profile desktop remains corrupted, try a fresh user profile or a restore from a known-good backup. Microsoft Safety Scanner | (https://www.malwarebytes.com).

Recommended Answers

All 2 Replies

Download & instal Adaware from
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot

Download & instal Spybot S&D from Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot

Download & instal Adaware from
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot

Download & instal Spybot S&D from Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot

Went looking on the net and found a temporary solution to my problem. The desktop is configured to run the Web file: SECURITY, which leads to desktop.html.; I went to Control Panel: Display: Desktop: Customize: Web
and deleted the SECURITY link, then checked the "lock my desktop" box, now the problem if fixed temporarily.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.