Active desktop problem

Closed
prasanna - Mar 16, 2010 at 08:38 AM
Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 - Mar 18, 2010 at 10:03 AM
Hello,
my desktop icons are beeing displayed as selected icons at every time .
iI think some active desktop is being added can u please say how i can see my desktop as normally again and how to overcome this problem?

8 replies

Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 11,240
Mar 16, 2010 at 09:44 AM
Hello,

As simple as this:

Right click on your desktop (not on a icon) then left click on reorganize icons. Choose the setting you wish.

Best regards
0
mikethedike Posts 158 Registration date Saturday August 16, 2008 Status Member Last seen September 22, 2012 40
Mar 16, 2010 at 09:56 AM
hi prassnna ;)

ok this should solve ur current issue

two reasons why this happens

a) When ur "visual effects" settings have been changed

Click on Start
1. Choose Control Panel
2. Click on System Icon
3. Choose the "Advanced" tab, click "Settings" under "Performance"
4. Under the "Visual Effects" tab Choose (get it checked) Use Drop Shadows for Icon Labels

OR

1. Click Start, and then click Control Panel.
2. Click Performance and Maintenance, and then click System.
3. On the Advanced tab, click Settings under Performance .
4. Click to clear the Use drop shadows for icon labels on the desktop check box ( get it checked), click Apply, & then click OK two times.
5. Close Control Panel

b) when ur dekstop icons are locked

1) Right Click on ur Desktop
2)go on "Arrange Icons by'
3) Uncheck "Lock Web icons on Desktop"


ur problem should be solved by now

awaiting comments

Melisio Mascarenhas
mikethedike
mumbai India
0
no sir my problem remaind same my desktop is not normal;
still i can't overcome my problem please suggest more
0
No sir my problem remaind same my desktop is not normal;
still i can't overcome my problem please suggest more
0
Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 11,240
Mar 16, 2010 at 10:47 AM
Hello,

I suggest we investigate a possible virus infection, autorun type.

Please download and install Hyjackthis. Request a scan and save log. Copy the log and paste it here.

http://free.antivirus.com/hijackthis/

Looking forward to hear from you.

P.S. Do you use USB keys, Pendrive, Flashdrive and other similar USB devices?
0
i already had antivirus and also i downloaded the software you suggested but still my problem remains same
0
Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 11,240
Mar 16, 2010 at 02:40 PM
Hello,

Did you paste the Hyjackthis log?
0
i didnt understood that can u please explain me what should i do regarding Hyjackthis log
0

Didn't find the answer you are looking for?

Ask a question
mikethedike Posts 158 Registration date Saturday August 16, 2008 Status Member Last seen September 22, 2012 40
Mar 17, 2010 at 12:20 AM
try redoing the steps i Mentioned above in safe mode

alos update ur anti virus program
and scan ur system for virus

awaiting comments

Melisio Mascarenhas
mikethedike
mumbai India
0
Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 11,240
Mar 17, 2010 at 09:37 AM
Download and install Hyjackthis

Run Hyjackthis and from the main page, press Scan and save a log. Once the scan is finished the log will automatically open.

Click edit, select all and copy.

Paste you log here.
0
where should i paste this is the copied one
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 6:59:24 AM, on 3/17/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe
C:\Program Files\G Data\AntiVirus\AVK\AVKService.exe
C:\Program Files\G Data\AntiVirus\AVK\AVKWCtl.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\G DATA\GDScan\GDScan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\G Data\AntiVirus\AVKTray\AVKTray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WordWeb\wweb32.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\IncrediMail\Bin\IncMail.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.rd.yahoo.com/customize/ycomp/defaults/sp/*https://in.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchmp3.tv/bar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://in.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchmp3.tv/bar
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchmp3.tv/...
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://in.rd.yahoo.com/customize/ycomp/defaults/su/*https://in.yahoo.com/
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\SearchMP3\searchmp3.exe\Streaming_Search_MP3_Toolbar\tbhelper.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: G Data WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G Data\AntiVirus\Webfilter\AvkWebIE.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: TBSB07458 - {5B839A5A-753B-4CFA-9330-071FC5B60471} - C:\Program Files\SearchMP3\searchmp3.exe\Streaming_Search_MP3_Toolbar\tbcore3.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Streaming_Search_MP3_Toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\SearchMP3\searchmp3.exe\Streaming_Search_MP3_Toolbar\tbcore3.dll
O3 - Toolbar: G Data WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Program Files\G Data\AntiVirus\Webfilter\AvkWebIE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [G DATA AntiVirus Trayapplication] C:\Program Files\G Data\AntiVirus\AVKTray\AVKTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?s=100000347&p=ZQfox000&si=&a=CxhK3ahJM2JjMtWyVSlopA&n=2010031209
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Streaming_Search_MP3_Toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\SearchMP3\searchmp3.exe\Streaming_Search_MP3_Toolbar\tbcore3.dll
O9 - Extra 'Tools' menuitem: Streaming_Search_MP3_Toolbar - {C86FF9FA-AEED-451B-A9CC-39A53173AE2E} - C:\Program Files\SearchMP3\searchmp3.exe\Streaming_Search_MP3_Toolbar\tbcore3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{73EF6275-995E-4453-A9E3-8335AB1B19FC}: NameServer = 218.248.255.146 218.248.255.212
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files\Common Files\G DATA\AVKProxy\AVKProxy.exe
O23 - Service: G Data Scheduler (AVKService) - G Data Software AG - C:\Program Files\G Data\AntiVirus\AVK\AVKService.exe
O23 - Service: G Data Filesystem Monitor (AVKWCtl) - G Data Software AG - C:\Program Files\G Data\AntiVirus\AVK\AVKWCtl.exe
O23 - Service: G Data Scanner (GDScan) - G DATA Software AG - C:\Program Files\Common Files\G DATA\GDScan\GDScan.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.jpg
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/msohtmlclip1/02/clip_image002.jpg
0
Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 11,240
Mar 17, 2010 at 10:33 AM
Hello,

I found your virus MWSBAR.

Here is how to remove it:

1.Type alt+ctrl+delete

2.Click on the processes tab
3.Locate and click on: C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
4.Terminate the process.

5. Run Hykacthis again but scan only

6. Check the following items:

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O24 - Desktop Component 0: (no name) -

7. Click on Fix checked.

8. Download and install Malwarebyte

9. Update Malwarebyte, second tab from the welcome page

10. Run a FULL system scan delete the items found.

11. Once your computer is clean and working normally just to be on the safe side
•Turn off system restore and wait 30 seconds,
•Turn it back on and create a new restore point.

This way it gets rid of anything bad that might have gotten saved in a restore point and you have a clean restore point to use in the near future if needed.
Do not turn it off until your computer is clean and working normally because you might need to use it if something goes wrong during the clean-up process.
It is better to go back to an infected restore point if something goes wrong then to not be able to undo changes that were damaging.

Please do let me know how this worked for you, we like to read about happy ending stories and victories over viruses.

Regards
0
where will be the processor tab
0
Ambucias Posts 47359 Registration date Monday February 1, 2010 Status Moderator Last seen September 1, 2021 11,240
Mar 18, 2010 at 10:03 AM
When you do alt+ctrl+del, this opens the task manager, top of the window, your will see 5 tabs, it is the second one from the left
0