Windows OS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsSystem AdministrationWindows OS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old November 12th, 2007, 08:44 PM
asptips asptips is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Location: asian
Posts: 389 asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 4 Days 1 h 45 m 12 sec
Reputation Power: 16
C:\WINDOWS background image

Hello,

After removing the worms Win32:VB-FHP and Win32:Sohara-T on my PC then looking around at some folders, a repeated image is pasted at the background of C:\WINDOWS folder.

Because I did not check the content of C:\WINDOWS folder before the infection, does the worm persisting or this image have nothing to do with the worm?

Although using HiJack, Keylogger, Anti-virus scan results are back from normal after the infection, I still got second thoughts. Do I need to format?



cheers,
asptips

Reply With Quote
  #2  
Old November 13th, 2007, 02:02 PM
Nilpo's Avatar
Nilpo Nilpo is online now
Click here for more information.
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 841 Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Days 15 h 37 m 2 sec
Reputation Power: 385
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo
MySpace
The ability to add wallpapers to folders in Windows XP was removed, but not entirely.

You can still do this via the desktop.ini file located in any system folder.

Just as you can add them, they may also be removed. Open the following file in any text editor. It is set to both hidden and system.

C:\Windows\desktop.ini

Now remove the lines similar to the following:
Code:
[ExtShellFolderViews]
{BE098140-A513-11D0-A3A4-00C04FD706EC}={BE098140-A513-11D0-A3A4-00C04FD706EC}
[{BE098140-A513-11D0-A3A4-00C04FD706EC}]
IconArea_Image=C:\My Folder Background.jpg 
You may optionally wish to delete the image file from the path you find.

Since JPG files can be used to transfer viruses, the possibility exists, however, unlikely. Still, be sure to run a full AV scan after removing the image, just in case.
Comments on this post
asptips agrees!
__________________
Click the image if at any point you don't like my decision.

Scripting problems? Windows questions? Ask the Windows Guru!


Reply With Quote
  #3  
Old November 13th, 2007, 10:48 PM
asptips asptips is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Location: asian
Posts: 389 asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 4 Days 1 h 45 m 12 sec
Reputation Power: 16
Hi Nilpo,

This is the content of desktop.ini

Quote:
[ExtShellFolderViews]
{BE098140-A513-11D0-A3A4-00C04FD706EC}={BE098140-A513-11D0-A3A4-00C04FD706EC}
[{BE098140-A513-11D0-A3A4-00C04FD706EC}]
Attributes = 1
IconArea_Image = c:\windows\system32\WindXP.ini
[.ShellClassInfo]
InfoTip=How are you COMPUTERNAME, nice to meet you!


Because the WinXP.ini is not an image file, I replace the extension to .JPG and indeed, it was the background image.
I know nothing about these INI files, so I will do a full system scan. Thanks!


Furthermore, the image was an anime character, Kenshin (Samurai X).


cheers,
asptips

Reply With Quote
  #4  
Old November 13th, 2007, 11:10 PM
Nilpo's Avatar
Nilpo Nilpo is online now
Click here for more information.
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 841 Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Days 15 h 37 m 2 sec
Reputation Power: 385
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo
MySpace
Please post the contents of c:\windows\system32\WindXP.ini

Reply With Quote
  #5  
Old November 13th, 2007, 11:12 PM
Nilpo's Avatar
Nilpo Nilpo is online now
Click here for more information.
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 841 Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Days 15 h 37 m 2 sec
Reputation Power: 385
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo
MySpace
For the record, this is a third infection. The W32.Mysamurai worm.

More info here.

Reply With Quote
  #6  
Old November 13th, 2007, 11:13 PM
Nilpo's Avatar
Nilpo Nilpo is online now
Click here for more information.
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 841 Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Days 15 h 37 m 2 sec
Reputation Power: 385
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo
MySpace
Deleting the file alone will not remove this infection. It also creates a series of registry entries and edits other system files.

I will create a WSH script for you that will remove it. Will post back.
Comments on this post
sbenj69 agrees: go Shaolin Scripter GO!!! Kind of you to take time out to write a script to help asptips. You have
my vote for most helpful poster!!

Reply With Quote
  #7  
Old November 14th, 2007, 08:11 PM
asptips asptips is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Location: asian
Posts: 389 asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level)asptips User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 4 Days 1 h 45 m 12 sec
Reputation Power: 16
Quote:
Originally Posted by Nilpo
Please post the contents of c:\windows\system32\WindXP.ini


Hi Nilpo,

The moment you made the first reply, I deleted afterwards the WinXP.INI. Am I at lost now?

However, I did check the content and if I can remember, it has special characters and numbers in it and the first word in the line was either GIF or GIF32, sort of.

I appreciate your help and cannot wait when Kenshin will get slice from your sword Nilpo!


cheers,
asptips

Reply With Quote
  #8  
Old November 14th, 2007, 08:15 PM
Nilpo's Avatar
Nilpo Nilpo is online now
Click here for more information.
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 841 Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Days 15 h 37 m 2 sec
Reputation Power: 385
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo
MySpace
Quote:
Originally Posted by asptips
Hi Nilpo,

The moment you made the first reply, I deleted afterwards the WinXP.INI. Am I at lost now?

However, I did check the content and if I can remember, it has special characters and numbers in it and the first word in the line was either GIF or GIF32, sort of.

I appreciate your help and cannot wait when Kenshin will get slice from your sword Nilpo!


cheers,
asptips
It was full of weird characters because it's actually a binary jpg file that has been renamed with an INI extension. An no, it's okay that you deleted that. I'll make sure the script checks for its existence before moving on to remove the rest. I'm working on it now.

Reply With Quote
  #9  
Old November 15th, 2007, 08:50 AM
Nilpo's Avatar
Nilpo Nilpo is online now
Click here for more information.
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 841 Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)Nilpo User rank is Major (30000 - 40000 Reputation Level)  Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1Folding Points: 189481 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 4 Days 15 h 37 m 2 sec
Reputation Power: 385
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo
MySpace
Just an update. This requires a lot of registry editing. This is quickly becoming a massive script.

In any case, I'm working on it and will post as soon as it's ready.

Reply With Quote
Reply

Viewing: ASP Free ForumsSystem AdministrationWindows OS > C:\WINDOWS background image


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |