We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Help - Unable to change desktop background or view thumbnails of photos after spybot

Dear All,

I ran a spybot scan as an administrator yesterday to remove Playpickle (Playpickle4.zip and Playpickle5.zip) from the registry. Now that it has been removed I can no longer change my desktop background to a photo and when I open my picture or music folder all I can see it the title of the folder or photo but I cannot see the thumbnail. It you double click on it the photo does come up in the preview.

Can anyone give me any advice on how to fix this?

Thank you!
Mortgage-free wannabe 2026 £1130/4000
«1

Comments

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    System Restore to a point before you ran spybot.

    Do you have Avira installed by any chance?
  • becky170
    becky170 Posts: 886 Forumite
    Part of the Furniture 500 Posts Photogenic Name Dropper
    Thanks Waddler!

    I haven't got Avira installed.

    If I do the system restore, when I restore It will also restore the adware....how can I then get rid of it safely?
    Mortgage-free wannabe 2026 £1130/4000
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Do the restore, confirm everything is as it should be and then post me a DDS log - should take 2-3 minutes.

    Download DDS from the link below and save it to your desktop:

    Link

    After you've downloaded it and saved it to your desktop:
    • Double click DDS to run it.
    • Click Start
    • When it's finished, DDS will open two logs:
    1. DDS.txt
    2. Attach.txt
    Save both reports to your desktop.

    Copy & paste the contents of just DDS.txt for now and post it here (you may need to split the log over separate posts)
  • becky170
    becky170 Posts: 886 Forumite
    Part of the Furniture 500 Posts Photogenic Name Dropper
    I've done a system restore and here is the DDS report:

    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 9.0.8112.16470 BrowserJavaVersion: 10.17.2
    Run by Bec at 11:36:22 on 2013-04-07
    .
    ============== Running Processes ================
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\STacSV.exe
    C:\Windows\system32\SLsvc.exe
    C:\Program Files\Dell\DellDock\DockLogin.exe
    C:\Windows\System32\WLTRYSVC.EXE
    C:\Windows\System32\bcmwltry.exe
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\RUNDLL32.EXE
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\DellTPad\Apoint.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\System32\WLTRAY.EXE
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files\Zune\ZuneLauncher.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Program Files\DellTPad\ApMsgFwd.exe
    C:\Program Files\DellTPad\HidFind.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe
    C:\Program Files\DellTPad\Apntex.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://uk.yahoo.com/?fr=fp-yie9
    uWindow Title = Windows Internet Explorer provided by Yahoo!
    uDefault_Page_URL = hxxp://uk.yahoo.com/?fr=fp-yie9
    dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
    BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - <orphaned>
    BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
    BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Nectar Search Toolbar BHO: {B7C2F0D8-2209-4693-A15D-5A537211D48B} - c:\program files\nectar search toolbar\Toolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
    BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
    TB: Nectar Search Toolbar: {8020143D-5926-4394-A04D-DD0B649DA121} - c:\program files\nectar search toolbar\Toolbar.dll
    TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
    mRun: [Apoint] c:\program files\delltpad\Apoint.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
    mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
    mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
    mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell2.exe" /mode2
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    uPolicies-Explorer: NoDrives = dword:0
    mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0
    mPolicies-Explorer: NoDrives = dword:0
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/70.11/uploader2.cab
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    TCP: NameServer = 192.168.1.1 192.168.1.1
    TCP: Interfaces\{50FD40CF-D8DD-4F08-A4DF-9FAFF7F3E253} : DHCPNameServer = 192.168.1.1 192.168.1.1
    TCP: Interfaces\{F912857E-CFC4-4B66-8DED-1C924BB3CE66} : DHCPNameServer = 192.168.1.1 192.168.1.1
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
    Notify: igfxcui - igfxdev.dll
    LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.43\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
    .
    Mortgage-free wannabe 2026 £1130/4000
  • becky170
    becky170 Posts: 886 Forumite
    Part of the Furniture 500 Posts Photogenic Name Dropper
    ============= SERVICES / DRIVERS ===============
    .
    R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
    R? PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver
    R? SkypeUpdate;Skype Updater
    R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
    S? AESTFilters;Andrea ST Filters Service
    S? aswFsBlk;aswFsBlk
    S? aswMonFlt;aswMonFlt
    S? aswRvrt;aswRvrt
    S? aswSnx;aswSnx
    S? aswSP;aswSP
    S? aswVmm;aswVmm
    S? avast! Antivirus;avast! Antivirus
    S? CtClsFlt;Creative Camera Class Upper Filter Driver
    S? DockLoginService;Dock Login Service
    S? FontCache;Windows Font Cache Service
    S? OA009Ufd;Creative Camera OA009 Upper Filter Driver
    S? OA009Vid;Creative Camera OA009 Function Driver
    S? SBSDWSCService;SBSD Security Center Service
    S? yksvc;Marvell Yukon Service
    .
    =============== Created Last 30 ================
    .
    2013-03-21 19:54:14 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
    2013-03-10 08:32:07 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    .
    ==================== Find3M ====================
    .
    2013-03-13 19:33:55 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2013-03-13 19:33:54 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2013-03-10 08:31:14 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
    2013-03-10 08:31:14 782240 ----a-w- c:\windows\system32\deployJava1.dll
    2013-03-06 22:33:24 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2013-03-06 22:33:24 49248 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
    2013-03-06 22:33:24 164736 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2013-03-06 22:33:23 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2013-03-06 22:32:51 41664 ----a-w- c:\windows\avastSS.scr
    2013-02-02 03:38:35 1800704 ----a-w- c:\windows\system32\jscript9.dll
    2013-02-02 03:30:32 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
    2013-02-02 03:30:21 1129472 ----a-w- c:\windows\system32\wininet.dll
    2013-02-02 03:26:47 142848 ----a-w- c:\windows\system32\ieUnatt.exe
    2013-02-02 03:26:21 420864 ----a-w- c:\windows\system32\vbscript.dll
    2013-02-02 03:23:28 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    .
    ============= FINISH: 11:46:51.37 ===============
    Mortgage-free wannabe 2026 £1130/4000
  • becky170
    becky170 Posts: 886 Forumite
    Part of the Furniture 500 Posts Photogenic Name Dropper
    P.S. Thank you for your help Waddler!
    Mortgage-free wannabe 2026 £1130/4000
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    There's nothing there to suggest that anything related to PlayPickle is having any affect on the system, so if it's just orphaned registry keys spybot is detecting I'd ignore them if their removal is causing problems.
  • becky170
    becky170 Posts: 886 Forumite
    Part of the Furniture 500 Posts Photogenic Name Dropper
    Thanks for the advice Waddler. I wasn't actually sure what PlayPickle does and as I use my Computer for internet banking etc I'm a bit cautious about adware/viruses etc
    Mortgage-free wannabe 2026 £1130/4000
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Internet Games - nothing particularly malicious.

    http://forums.spybot.info/showthread.php?t=64777
    PlayPickle is a game provider that is sponsored via adware.
    http://playpickle.com/terms-and-conditions/
    PlayPickle is a very popular gaming site sponsored by a free Game Center Application and/or Game Toolbar (“Software”)
  • becky170
    becky170 Posts: 886 Forumite
    Part of the Furniture 500 Posts Photogenic Name Dropper
    That's great to know, thank you for all your help!
    Mortgage-free wannabe 2026 £1130/4000
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.6K Banking & Borrowing
  • 254.4K Reduce Debt & Boost Income
  • 455.5K Spending & Discounts
  • 247.4K Work, Benefits & Business
  • 604.3K Mortgages, Homes & Bills
  • 178.5K Life & Family
  • 261.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.