Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Hijacked Desktop Background

  • Please log in to reply
2 replies to this topic

#1 flaboy


  • Members
  • 1 posts
  • Local time:04:32 PM

Posted 13 March 2008 - 08:52 PM

My desktop background has been hijacked by a blue backgroung with yellow letters which tell me my computer is infected and to click on a link to repair. The link takes me to the following web address //antispywareupdates.net/?aid=496.cbcbcb

I have rebooted and scanned using Norton, Spybot and Adaware in Safe Mode and the problem is still there. Please help.

Edited by KoanYorel, 14 March 2008 - 08:00 AM.
to sanitize URL above and move to more appropriate forum

BC AdBot (Login to Remove)


#2 boopme


    To Insanity and Beyond

  • Global Moderator
  • 73,416 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:04:32 PM

Posted 14 March 2008 - 10:09 PM

Hello and welcome... If this is an XP computer please do this.

NOTE: If you have downloaded SmitfraudFix previously please delete that version and download it again! Also delete C:\rapport.txt

Please download SmitfraudFix by S!ri

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Once in Safe Mode, double-click SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process.
Please copy/paste the content of the SmitfraudFix report into your next reply.

The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

Edited by boopme, 14 March 2008 - 10:12 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Kiminae


  • Members
  • 1 posts
  • Local time:04:32 PM

Posted 05 August 2008 - 12:13 AM

I had the same problem and these instructions fixed the problem. Curiously, it also fixed a problem with my wireless network card which had disappeared from my list of hardware in device manager several months ago. I'd searched for fixes for that issue online and found that it was a known HP issue and that it would require that the motherboard be replaced (model dv6000). So, instead of trying to get HP to replace the motherboard, I just bought an external Wireless USB adapter (which is bulky and I don't really like it). Short story long, my wireless card is showing up in device manager again. Thanks much.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users