I m now using win 2000 professional with avast antivirus. Now my computer shows a desktop image which says its a ad which warns me to download some s/w to sweep my computer from spies. I try to change the Backgrounf of the PC and found no Desktop tab. I think its a job of ome respectable Adware and run a full sys scan . Avast says the PC is clean. can any body help me sort this problem .
A link in the back ground directs me to //top adware where i find only commercial info.


The above one is in my desktop background

This is my propertie dialo g box.

Avast wont find spyware, it only detects viruses. Donwload a couple of antispyware tools such as Adaware and Spybot Search and Destroy. Install them and update them with latest definitions. Run them in safe mode...
Then, download HijackThis and post its log (that you can obtain by running the software) in the forum so that we can verify if there is anything else left.

After being sure that the spyware is gone, you can get back the background tab by opening regedit and navigating to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
Look for the entry named NoDispBackgroundPage and either delete it or set its value to 0.



thanks pal:spybot and ad aware almost rectifies my system , i think ihave posted the correct log file : verify it.

Check following two entries in HijackThis .. and fix them.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdocie.dll/blank.html

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)



Download KillBox, extract it to your desktop.

Download and install Ewido Security Suite v3.5. After download, double click on the file to launch the install process. During installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". Launch ewido, the program will prompt you to update - click the "OK" button. On the left side of the main screen, click on "Update" and then click "Start Update". After updating, exit from Ewido.

Right-click on this link and selecet "Save Target As" (or "Save Link As") and save the file with the default file name (Default filename would be Smitfraud.reg).

Boot in Safe Mode.

Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdocie.dll/blank.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - HKLM\..\Run: [BatSrv] F:\WINNT\batserv2.exe
O4 - HKLM\..\Run: [FA Page] F:\WINNT\system32\shdocie.exe home

Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.

Double-click on the SmitFraud.reg file and click "Yes" to merge it to Registry.

Run Ewido, click on the "Scanner" button in the left menu, then click on the "Settings", here select the option "Scan every file" and click "OK". Next, click "Complete System Scan" button to start scan. If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.

Open Killbox.exe. Check the following box:-

Delete on Reboot

Highlight all the entries in the quote box below and then Copy them.
Then in Killbox click File > Paste from Clipboard.

At this point the "All Files" button should be enabled so you can click it. Click the "All Files" button.

Then click the Red X button and for the confirmation message that will appear, you will need to click "Yes".

A second message will ask to Reboot now? you will need to click "Yes" to allow the reboot.

Note: Killbox will let you know if a file does not exist.

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.

Reboot to Normal Mode. Run HijackThis again, click Do a System scan and save log, and post the fresh log.
