i had a similar problem back in 2009 took me a week to get rid
if you think a yawn is bad check this out this post is coppied from proxy fire.com 2009
suffered that desktop pic for a week.
proxygo 2009
some d1ck posted a file on my site yesterday some proxie scanner..i sent it to virus total and
it said clean, so i opened it and got this lol even altered my desktop pic to lol nice touch
i felt like ide tripped acid for a month lookin at this
Malwarebytes' Anti-Malware 1.30
Database version: 1341
Windows 5.1.2600 Service Pack 1
11/8/2008 2:47:29 AM
mbam-log-2008-11-08 (02-47-29).txt
Scan type: Quick Scan
Objects scanned: 40882
Time elapsed: 2 minute(s), 29 second(s)
Memory Processes Infected: 7
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 18
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 31
Memory Processes Infected:
C:\WINDOWS\runsql.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\sv.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svzip.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\vlc.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\wdmon.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svx.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\svw.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
C:\Documents and Settings\tony\Local Settings\Temp\wndutl32.dll (Trojan.FakeAlert) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{020487cc-fc04-4b1e-863f-d9801796230b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\updatewin (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\updatewin (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runsql (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\netsv32 (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\netzip (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\vlc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wdmon (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\netx (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\netw (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{020487cc-fc04-4b1e-863f-d9801796230b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\net64 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\UpdateWin (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\UpdateWin (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SYSTEM\CurrentControlSet\Control\Lsa\UpdateWin (Worm.Sdbot) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\3076v.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\WINDOWS\runsql.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\sv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svzip.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\vlc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\wdmon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svx.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\svw.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Local Settings\Temp\wndutl32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc47.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc49.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc50.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc51.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc52.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc53.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc54.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc55.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc56.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc61.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc62.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc63.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc68.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1547161642-261478967-839522115-1003\Dc48.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\sv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\svw.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\svx.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\svzip.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\vlc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Desktop\wdmon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Application Data\config.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\tony\Application Data\~tmp.html (Malware.Trace) -> Quarantined and deleted successfully.
NOW PLEASE IF YA GONNA POST CRAP FILES THINK THAT SOME OF US HAVE THE BACKUP
TOOLS TO REMOVE THEM 5 HRS TO REMOVE, BUT REMOVED NEVER THE LESS...
REMOVAL TOOLS USED
mcafee / malwarebytes / smithfraud / nod / hijackthis /
think u could own me > U WISH ..
UPDATE
fixed the final piece of the jigsaw the fixed destop pic problem
now resolved..destop background is now unlocked and that
**** is gone .. see fix below...
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ Windows\CurrentVersion\policies
"NoChangingWallPaper", double-click the DWORD value and set it to "0". Otherwise, you need to create a new DWORD value of "NoChangingWallPaper" and set it to "0".
my normal desktop is back..