This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Wallpaper "your system is infected"

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I seemed to have downloaded a virus from facebook. my desktop says. YOUR SYSTEM IS INFECTED! System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed. Symptoms: The desktop Properties will not allow me to change wallpaper. Also the TaskManager has been disabled. There is also a White X in a red circle in the taskbar tray that every 30 seconds or so flashes Click here to protect your computer from spyware. Isee that multiple people have had this problem, please help!
Hi,

Please do the following:


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\system32\winupdate86.exe (YKiKkxaDyhFiaxaUmysSI)
    MOD - C:\WINDOWS\system32\yiwuyipa.dll ()
    MOD - C:\WINDOWS\system32\hajifagu.dll ()
    MOD - C:\WINDOWS\system32\dajifuji.dll ()
    O2 - BHO: (no name) - {b104f357-8884-4e58-9573-958585cf1378} - C:\WINDOWS\System32\hajifagu.dll ()
    O4 - HKLM..\Run: [vuzazihedu] C:\WINDOWS\System32\dajifuji.dll ()
    O4 - HKLM..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe (YKiKkxaDyhFiaxaUmysSI)
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O20 - AppInit_DLLs: (yiwuyipa.dll) - C:\WINDOWS\System32\yiwuyipa.dll ()
    O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\winlogon86.exe) - C:\WINDOWS\system32\winlogon86.exe (YKiKkxaDyhFiaxaUmysSI)
    O33 - MountPoints2\{b68ba9e1-d0c3-11de-9545-001fd09c16fa}\Shell - "" = AutoRun
    O33 - MountPoints2\{b68ba9e1-d0c3-11de-9545-001fd09c16fa}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{b68ba9e1-d0c3-11de-9545-001fd09c16fa}\Shell\AutoRun\command - "" = E:\Windows\CHECK\DriveNavigator.exe – File not found
    [2009/12/30 09:25:36 | 00,000,000 | —D | C] – C:\Program Files\InternetSecurity2010
    [2009/12/30 09:25:05 | 00,024,576 | —- | C] (YKiKkxaDyhFiaxaUmysSI) – C:\WINDOWS\System32\winupdate86.exe
    [2009/12/30 09:25:05 | 00,024,576 | —- | C] (YKiKkxaDyhFiaxaUmysSI) – C:\WINDOWS\System32\winlogon86.exe
    [2009/12/30 09:24:53 | 00,024,576 | —- | C] (YKiKkxaDyhFiaxaUmysSI) – C:\waxfhosk.exe
    [2009/12/30 10:32:55 | 00,707,072 | —- | M] () – C:\WINDOWS\System32\drivers\mqkuu.sys
    [2009/12/30 10:32:53 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\nitaroda
    [2009/12/30 10:29:51 | 00,000,419 | —- | M] () – C:\WINDOWS\System32\uses32.dat
    [2009/12/30 10:29:51 | 00,000,100 | —- | M] () – C:\WINDOWS\System32\flags.ini
    [2009/12/30 10:22:30 | 00,002,854 | —- | M] () – C:\WINDOWS\System32\critical_warning.html
    [2009/12/30 09:25:25 | 00,016,896 | —- | M] () – C:\WINDOWS\System32\winhelper86.dll
    [2009/12/30 09:24:56 | 00,052,736 | —- | M] () – C:\uwlwfa.exe
    [2009/12/30 09:24:54 | 00,024,576 | —- | M] (YKiKkxaDyhFiaxaUmysSI) – C:\WINDOWS\System32\winupdate86.exe
    [2009/12/30 09:24:54 | 00,024,576 | —- | M] (YKiKkxaDyhFiaxaUmysSI) – C:\WINDOWS\System32\winlogon86.exe
    [2009/12/30 09:24:54 | 00,024,576 | —- | M] (YKiKkxaDyhFiaxaUmysSI) – C:\waxfhosk.exe
    [2009/12/30 10:29:51 | 00,000,419 | —- | C] () – C:\WINDOWS\System32\uses32.dat
    [2009/12/30 10:29:51 | 00,000,100 | —- | C] () – C:\WINDOWS\System32\flags.ini
    [2009/12/30 09:25:24 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\winhelper86.dll
    [2009/12/30 09:25:23 | 00,707,072 | —- | C] () – C:\WINDOWS\System32\drivers\mqkuu.sys
    [2009/12/30 09:25:14 | 00,002,854 | —- | C] () – C:\WINDOWS\System32\critical_warning.html
    [2009/12/30 09:24:55 | 00,052,736 | —- | C] () – C:\uwlwfa.exe
    [2009/09/30 09:25:07 | 00,052,736 | -HS- | C] () – C:\WINDOWS\System32\yiwuyipa.dll
    [2009/09/30 09:25:07 | 00,052,736 | -HS- | C] () – C:\WINDOWS\System32\hajifagu.dll
    [2009/09/30 09:25:07 | 00,052,736 | -HS- | C] () – C:\WINDOWS\System32\dajifuji.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • OTL Log
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI