Here is the log file from hijack this,..

please advise what I should check off and what I shuold do?

My desktop is gone is has Warning Your in Danger a htlm file on file://C:\WINDOWS\Web\desktop.html

I can't get rid of it.. GRRRR

Please help. Thanks in advance...

-Artchess

Dani AI

Generated

was right — the HijackThis output didn’t arrive. Post the full HJT logfile (use the Save Log button and paste the entire text) along with the exact Windows version and which antivirus is installed. Do not use HJT to "fix checked" items until someone confirms which entries are bad; removing the wrong things can break the system.

Immediate containment and a quick desktop restore:

  • Disconnect the PC from the Internet to stop further downloads.
  • Boot to Safe Mode (F8). Using Explorer in Safe Mode, rename or delete C:\WINDOWS\Web\desktop.html. That file is what Active Desktop can be pointing to.
  • In Windows XP, disable any Active Desktop web item via Display Properties -> Desktop -> Customize Desktop -> Web tab and remove/uncheck the offending item. If the file is locked, delete it from a rescue environment or by using Safe Mode with Command Prompt.

Cleaning workflow to follow (after you post the HJT log):

  • Run a current anti-malware scanner such as Malwarebytes and a second on-demand scanner such as the .
  • Use Autoruns (Sysinternals) to inspect startup, services and browser helper objects: Autoruns.
  • Temporarily turn off System Restore before cleaning so malware cannot hide in restore points; recreate a clean restore point afterward.
  • If a rootkit is suspected or the system remains unstable, scan from a rescue CD/USB (offline) or consider a clean reinstall.

Aftercare: change all passwords from a different clean machine, fully update Windows and AV, keep real-time protection enabled, and create a fresh restore point. ’s suggestions about adware/spyware tools are useful for PUPs; add the current tools above and then post the full HJT log and scan reports for targeted advice.

Recommended Answers

All 2 Replies

Erm- your HJT log didn't seem to make it into your post... try again?

Also, before you post the log, Download & instal Adaware from
& update it before scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
In 'tweaks' under 'scanning engine' set it to 'unload recognised processes during scanning.'
Also in 'tweaks' under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion' & 'let Windows remove files in use at next reboot.'
Select 'activate in-depth scan' before starting scan.
When the scan is finished select 'next.'
Remove what it finds by placing a check in the box to the left of the object. Reboot

Download & instal Spybot S&D from Update it before scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. This program will prevent the install of bad activex controls that it has knowledge of. Download that & you can keep it updated by selecting the same link that you use to download it. Reboot

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.