Author Topic: smartsecurity  (Read 132182 times)

Annoyed

  • Guest
smartsecurity
« Reply #140 on: March 18, 2005, 10:13:22 AM »
Quote
at the very top of the screen, right click, it should appear as a standard option menu (compared to when right click the big black desktop..)

as you right click, select properties..

destop tab..

click the "customize destop" button at the bottom..

select the "web" tab..

an uncheck the "security" box..

I tried this, but there IS NO items called "security" precent... what am i supposed to do, i have looked for all the files listed here but none of those can be found on my computer, i have tried everything and can't get rid of it....

Offline Michal126

  • Newbie
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
smartsecurity
« Reply #141 on: March 19, 2005, 09:08:59 AM »
Hello i haave on my desktop smart security can you help me.
my log file is below
Logfile of HijackThis v1.99.1
Scan saved at 14:45:55, on 2005-03-19
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\logonui.exe
E:\WINDOWS\system32\spoolsv.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
E:\WINDOWS\System32\ntddetect.exe
E:\WINDOWS\System32\Ekk.exe
E:\WINDOWS\System32\ctfmon.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Spyware Doctor\swdoctor.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\WINDOWS\System32\notepad.exe
E:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.ht...count_id=138770
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *new-search.net*;*x-google.net*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O1 - Hosts file is located at: E:\WINDOWS\nsdb\hosts
O1 - Hosts: 82.179.166.192 new-search.net
O1 - Hosts: 82.179.166.190 x-google.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - E:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [Qum] E:\WINDOWS\Bop.exe
O4 - HKLM\..\Run: [ntddetect] E:\WINDOWS\System32\ntddetect.exe
O4 - HKLM\..\Run: [Vrn] E:\WINDOWS\System32\Ekk.exe
O4 - HKLM\..\Run: [Ssg] E:\WINDOWS\System32\Dcg.exe
O4 - HKLM\..\Run: [Gfi] E:\WINDOWS\System32\Cgr.exe
O4 - HKLM\..\Run: [Vli] E:\WINDOWS\Mtt.exe
O4 - HKLM\..\Run: [Mib] E:\WINDOWS\System32\Mpc.exe
O4 - HKLM\..\Run: [Dhb] E:\WINDOWS\Ont.exe
O4 - HKLM\..\Run: [Eml] E:\WINDOWS\Drk.exe
O4 - HKLM\..\Run: [Tkr] E:\WINDOWS\System32\Tbr.exe
O4 - HKLM\..\RunServices: [ntddetect] E:\WINDOWS\System32\ntddetect.exe
O4 - HKLM\..\RunOnce: [VcCleanUp.exe] E:\DOCUME~1\Michal\USTAWI~1\Temp\VcCleanUp.exe /F E:\PROGRA~1\COMMON~1\SYMANT~1\LiveReg\ /RemoveAll
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NBJ] "E:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "E:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Qum] E:\WINDOWS\Bop.exe
O4 - HKCU\..\Run: [ntddetect] E:\WINDOWS\System32\ntddetect.exe
O4 - HKCU\..\Run: [Vrn] E:\WINDOWS\System32\Ekk.exe
O4 - HKCU\..\Run: [Ssg] E:\WINDOWS\System32\Dcg.exe
O4 - HKCU\..\Run: [Gfi] E:\WINDOWS\System32\Cgr.exe
O4 - HKCU\..\Run: [Vli] E:\WINDOWS\Mtt.exe
O4 - HKCU\..\Run: [Mib] E:\WINDOWS\System32\Mpc.exe
O4 - HKCU\..\Run: [Dhb] E:\WINDOWS\Ont.exe
O4 - HKCU\..\Run: [Eml] E:\WINDOWS\Drk.exe
O4 - HKCU\..\Run: [Tkr] E:\WINDOWS\System32\Tbr.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - E:\WINDOWS\web\related.htm
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x15.chm::/trs15.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/es/SysWebTelecom.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://67.15.101.3/g_bin/pl/billard8_2_0_0_21.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C5} (GameDesire Snooker) - http://67.15.101.3/g_bin/pl/snooker_2_0_0_21.cab
O18 - Filter: text/html - {4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

Guest

  • Guest
smartsecurity
« Reply #142 on: March 19, 2005, 08:55:05 PM »
Thnx guys!    Fixed it I think..

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
smartsecurity
« Reply #143 on: March 19, 2005, 09:00:16 PM »
Hi Michal126, if you would like to start your own Post in this forum and supply a fresh Hijackthis log, I'll be glad to look at it
It's too confusing to work on a log in this long of a thread

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


GSB

  • Guest
smartsecurity
« Reply #144 on: March 20, 2005, 10:13:57 AM »
FINALLY !

Got this annoying thing off my PC.
Followed removal instructions at the SmartSecurity Website.

http://www.smart-security.info/removal.html

Downloadable uninstaller did nothing, but editing desktop values via regedit did the trick. It´s cumbersome but the only thing that has worked for me...

If you´ve tried everything else, follow the instructions on changing values in regedit. It did work for me.

Phew.

Guest_steve_*

  • Guest
smartsecurity
« Reply #145 on: March 20, 2005, 11:12:22 AM »
I found a free removal tool for smartsecurity, and it worked ! I did not have to drop to safe mode, just download and run!
http://www.smart-security.info/removal.html

Guest

  • Guest
smartsecurity
« Reply #146 on: March 20, 2005, 03:40:32 PM »
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/dry.gif\' class=\'bbc_emoticon\' alt=\'<_<\' /> Although the red screen is gone and system appears to be fixed, after running the free fix above, windows shuts down very slow , im not convenced the fix is 100% complete. ill run a reg checker and system works windows scan.steve http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/dry.gif\' class=\'bbc_emoticon\' alt=\'<_<\' />

Nabs

  • Guest
smartsecurity
« Reply #147 on: March 20, 2005, 04:48:15 PM »
I managed to do a system restore to yesterday's date (before smartsecurity invaded my computer) and everything seems to be fine.  My computer seems to be running normally and all.  I'm not a techie or anything, so could I be missing anything?  Any ideas/suggestions are very much appreciated!

Thanks!

Techie From Canada

  • Guest
smartsecurity
« Reply #148 on: March 22, 2005, 02:02:25 AM »
Hey I just got a clients comp in and it had this smart-security bs which everyone is having problems with. After removing the annoying background page I noticed all my icons were double and I couldn't change my desktop. I believe I have fixed it completely and here's how:

*WARNING EDITING THE REGISTRY CAN CAUSE SERIOUS PROBLEMS IF NOT DONE EXACTLY AS SHOWN*

Open registry editor (Start->Run->[type regedit.exe and press enter]).

Delete the following registy keys (the key structure is accessible through
the tree on the left).

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[any thre letters, the first is capital]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[any thre letters, the first is capital]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\\Desktop\General\Wallpaper

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\BackupWallpaper

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\SafeMode\General\Wallpaper
   
   HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu   
   HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Wallpaper

   HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\
   
Set value "%USERPROFILE%\Desktop" to the following keys:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User shell folders"\Custom Desktop

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell folders\Desktop
   
   HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell folders\Desktop
   
   HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\User shell folders\Desktop
   
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User shell folders\Desktop

Set blank value to the following keys:

HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper
HKEY_CURRENT_USER\Control Panel\Desktop\OriginalWallpaper
HKEY_CURRENT_USER\Control Panel\Desktop\ConvertedWallpaper

REBOOT IMMEDIATELY AFTER DOING THESE STEPS!

You'll notice most of this was taken from the smart security removal page however his instructions not only messed things up, some things were missing so I modified it to the way I fixed the problem. I hope this has been useful for everyone and thank you to everyone who posted solutions.

Guest

  • Guest
smartsecurity
« Reply #149 on: March 22, 2005, 02:04:44 AM »
[censored] sorry folks accidently left 1 line in that shouldn't have been please DO NOT delete the following key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\

Garden

  • Guest
smartsecurity
« Reply #150 on: March 22, 2005, 04:48:26 AM »
Hi,

we got this SmartSecurity crap too, arghrhrghhs!! We spent two days to remove it and finally it happens. But only partially. I delete desktop.html from C:\WINDOWS  (we use Win XP in Czech language edition) and work with register keys (only in "Set value "%USERPROFILE%\Desktop" to the following keys" we replace "Desktop" to Czech equivalent "Plocha").

Now we  have no red background on desktop, we can use right button, but we cannot change Desktop picture (yes, I read advices about unchecking Security in Control Panel Display/Desktop/settings/web but in Cuech version is no checkbox Security, but only Lock items on desktop...) and every item I place on desktop is shown twice there (but in apropriate folder in system is only once!!). Can somebody help me, please?? Thank you.

Garden

Offline Chris_Guest

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
smartsecurity
« Reply #151 on: March 22, 2005, 08:20:21 AM »
Garden: look at this link. I got the same problem... it will get your DisplayPro. working. No solution on the missing files on the desktop yet...

Garden

  • Guest
smartsecurity
« Reply #152 on: March 22, 2005, 09:20:28 AM »
Thank you, Chris_guest, it works for me fine. Last thing is that items on desktop are show twice. Have you any ideas?

Garden

Offline Chris_Guest

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
smartsecurity
« Reply #153 on: March 22, 2005, 03:08:00 PM »
yes, I also get double file icons on the desktop...

Techie From Canada

  • Guest
smartsecurity
« Reply #154 on: March 22, 2005, 04:00:21 PM »
Hey Chris, as long modify the registry EXACTLY as I posted(minus my error with the 1 extra key) it WILL fix the problem basically he made it so that your desktop is set to allusers so when u go to make a new icon it makes one on all account and your local one as well. Hope this cleared things up a bit.

Pissed Off

  • Guest
smartsecurity
« Reply #155 on: March 23, 2005, 03:41:05 AM »
You want them...Here's what InterNIC had to say about the owner of "Smart Security."

Maybe a few THOUSAND E_MAILS will get OUR point across!!

InterNIC

Whois Search Results

    Search again (.aero, .arpa, .biz, .com, .coop, .edu, .info, .int, .museum, .name, .net, or .org):

    Domain   (ex. internic.net)
    Registrar   (ex. ABC Registrar, Inc.)
    Nameserver   (ex. ns.example.com or 192.16.0.192)

NOTICE: Access to .INFO WHOIS information is provided to assist persons in
determining the contents of a domain name registration record in the Afilias
registry database. The data in this record is provided by Afilias Limited
for informational purposes only, and Afilias does not guarantee its
accuracy.  This service is intended only for query-based access.  You agree
that you will use this data only for lawful purposes and that, under no
circumstances will you use this data to: (1) allow, enable, or otherwise
support the transmission by e-mail, telephone, or facsimile of mass
unsolicited, commercial advertising or solicitations to entities other than
the data recipient's own existing customers; or (2) enable high volume,
automated, electronic processes that send queries or data to the systems of
Registry Operator or any ICANN-Accredited Registrar, except as reasonably
necessary to register domain names or modify existing registrations.  All
rights reserved. Afilias reserves the right to modify these terms at any
time. By submitting this query, you agree to abide by this policy.

Domain ID:D5928130-LRMS
Domain Name:SMART-SECURITY.INFO
Created On:18-May-2004 10:24:19 UTC
Last Updated On:23-Feb-2005 21:01:51 UTC
Expiration Date:18-May-2006 10:24:19 UTC
Sponsoring Registrar:R159-LRMS
Status:CLIENT LOCK
Status:OK
Registrant ID:C4844095-LRMS
Registrant Name:Aleksandr Romantsev
Registrant Organization:Smart Security GM
Registrant Street1:Lindaal 33
Registrant City:Overijse
Registrant Postal Code:3090
Registrant Country:BE
Registrant Phone:+1.3022617417
Registrant FAX:+1.3022617417
Registrant Email:[email protected]
Admin ID:C4844095-LRMS
Admin Name:Aleksandr Romantsev
Admin Organization:Smart Security GM
Admin Street1:Lindaal 33
Admin City:Overijse
Admin Postal Code:3090
Admin Country:BE
Admin Phone:+1.3022617417
Admin Email:[email protected]
Billing ID:C4844095-LRMS
Billing Name:Aleksandr Romantsev
Billing Organization:Smart Security GM
Billing Street1:Lindaal 33
Billing City:Overijse
Billing Postal Code:3090
Billing Country:BE
Billing Phone:+1.3022617417
Billing Email:[email protected]
Tech ID:C4844095-LRMS
Tech Name:Aleksandr Romantsev
Tech Organization:Smart Security GM
Tech Street1:Lindaal 33
Tech City:Overijse
Tech Postal Code:3090
Tech Country:BE
Tech Phone:+1.3022617417
Tech Email:[email protected]
Name Server:NS1.SMART-SECURITY.INFO
Name Server:NS2.SMART-SECURITY.INFO

Pissed Off

  • Guest
smartsecurity
« Reply #156 on: March 23, 2005, 07:00:30 AM »
I just found this at the Smart Security website: http://www.smart-security.info/removal.html

I haven't tried it yet, but at this point, I figure I have nothing to loose.  The "Free Clean Utility" mentioned can be found at their website.

I'll make another post after I follow these instructions and let you all know how it turns out.

We apologize for actions of several our advertisers. We are investigating their promotion business.
Download FreeClean Utility to remove desktop advertisement.
Active desktop should disappear. If it have not disappeared - then try to disable it via Control Panel.
If the utility does not work (the spyware has blocked it out, we
are getting this problem solved), try the following steps to remove
the ad maually.

Open registry editor (Start->Run->[type regedit.exe and press enter]).

Delete the following registy keys (the key structure is accessible through
the tree on the left).

HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\[any thre letters, the first is capital]

HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\[any thre letters, the first is capital]

HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Desktop\\General\\Wallpaper

HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Desktop\\General\\BackupWallpaper

HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Desktop\\SafeMode\\General\\Wallpaper
   
HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoViewContextMenu
   
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoViewContextMenu   
Set value "%USERPROFILE%\\Desktop" to the following keys:

HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User shell folders\\Common Desktop

HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User shell folders"\\Custom Desktop

HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell folders\\Desktop
   
HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell folders\\Desktop
   
HKEY_USERS\\.DEFAULT\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User shell folders\\Desktop
   
HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User shell folders\\Desktop

Set blank value to the following keys:

HKEY_CURRENT_USER\\Control Panel\\Desktop\\Wallpaper
HKEY_CURRENT_USER\\Control Panel\\Desktop\\OriginalWallpaper
HKEY_CURRENT_USER\\Control Panel\\Desktop\\ConvertedWallpaper

REBOOT IMMEDIATELY AFTER DOING THESE STEPS!

Pissed Off

  • Guest
smartsecurity
« Reply #157 on: March 23, 2005, 08:31:25 AM »
Well, I ran the "Free Clean Utility" they provided and no luck...the adds still there.

I also went through the registry and followed their directions...and the adds still there.  I did get my Icons back, and my Right Click works now, but the adds still there.

Maybe some of you will have better luck, but I think if you tried to remove it with Spyware or Antivirus Programs, your going to run into the same thing I did.

Microsoft will provide Free Support for those of us that have had the unfortunate displeasure of running into this company.

You'll go through Teir 1 Virus Support, and be transfered to the Virus Escalation Department quickly.  At least that's how it's going for me.  I found out quickly that just because the screens gone, it doesn't mean the program is gone.

Best of luck to you all.

Techie From Canada

  • Guest
smartsecurity
« Reply #158 on: March 23, 2005, 04:27:16 PM »
DO NOT CHANGE

HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User shell folders\\Common Desktop

IF YOU DO IT WILL MAKE DOUBLE ICONS ALL OVER AGAIN

also be sure to delete

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Wallpaper

John Smith Jr.

  • Guest
smartsecurity
« Reply #159 on: March 28, 2005, 03:03:56 PM »
Still got that problem.

You guys tell me to do smthn in that customize desktop, but i dont even have that 'web' thing.

I tried that official remover from homepage, but now the screen is gone and my background is blue and i cant change wallpapers.

All stays blue.