icons(i think they are IE ones) such as "website hosting" "poker" "casino online" "travel" appear everytime i log into windows and they multiply until they completely cover the desktop :eek: and this happens to every one of the XP users on my computer.

i've tried using adaware, spybot, and pestpatrol to get rid of everything i can but nothing works. HELP PLEASEEEEEEE!!!!!!

Dani AI

Generated

A short diagnostic checklist and safe first steps based on ’s symptom (icons reappear and multiply at every login). This usually means something on startup is recreating Internet shortcuts (.url) or .lnk files for every user — often an adware/installer running from a common location (All Users profile, Run keys, or a Scheduled Task). Before heavy cleanup, create a system restore point and a backup of any files you care about.

Immediate checks you can do now (do these in Safe Mode if possible): look in both
C:\Documents and Settings\All Users\Desktop
and
C:\Documents and Settings\<your user>\Desktop
and note whether the unwanted items are .url (web shortcuts) or normal .lnk files. Show file extensions (Explorer: Tools > Folder Options > View > uncheck “Hide extensions for known file types”) and inspect Properties -> Web Document (for .url) or Shortcut -> Target (for .lnk) to see what program or URL is being launched. If the files are created inside All Users, deleting them from a single user won’t stick — remove them from All Users or stop the creator first.

To find what’s recreating them: check Startup folders and Scheduled Tasks, and examine Run/RunOnce autostart registry keys under HKLM and HKCU (export keys before editing). Use msconfig to spot obvious startup entries and use an autorun/startup viewer (Autoruns or equivalent) or a file-system monitor to catch the creator process. If you don’t know how to interpret the entries, capture the autostart log and post it here — mention and ’s earlier scan/log suggestions when you do so.

Final tips: run up-to-date anti-malware scans from Safe Mode, uninstall any recently added toolbars or suspicious programs, and consider creating a clean test account to confirm whether the problem is profile-specific. If the shortcut source is a stubborn, unknown executable, remove its autostart entry, reboot, then delete the shortcuts. Always back up the registry and user data before making deletions or registry edits.

Recommended Answers

All 2 Replies

If caperjacks link didn't help you can..

Try downloading Hijackthis

http://www.spychecker.com/program/hijackthis.html

Run the program and save the log file somewhere easy to find. Open the log file and copy the entire thing into one of the threads or areas helping to analyze hijackthis logs... if no one can help you decipher the log copy your log file to the box here..

http://www.help2go.com/modules.php?name=HJTDetective

.. and click submit, it will show you any malicious and suspicious entries and you can go from there.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.