• 0

I cant change my desktop wallpaper


Question

hey

My compuer was recently infected by spysherif however i followed some removal instructions and i think i managed to get rid of some of it.

First i did a full anti-virus system scan using SymantecAntivirus and then i used Ad-Aware SE Personal, Spybot S&D and Ewido anti-malware. After i thought i got rid of it, there was a red circle with a white x in it that kept appearing in my taskbar beside the clock and a message above it saying "your computer is infect!....please download the latest anti-spyware....". Also my desktop background has been changed. It is now all blue with a black box in the middle and red text saying "Spyware Infection" and under this red writing theres more writing in white text that says "Your system is infected with spyware. Windows recomends you to use spyware removal tools..."

I restarted my computer in safe mode and ran all the programs again and deleted any infections.

I restarted my computer in normal mode and the red circle with the white x and "your computer is infect!" message above it have now gone. However the "Spyware Infection" desktop background is still there and when i try to change it under the desktop tab in display properties, the wallpaper section is disabled. I cant scroll down or select any wallpaper.

Also when i try to open a webpage its taking alot longer then usual, so i think i still have some sort of spyware/adware or something on it still. :cry:

I also have hijack this in which i saved a logfile but i dont know what to do with it. =/

I very much appreciate any help or advice on this problem

thanks

please help

Link to comment
https://www.neowin.net/forum/topic/413150-i-cant-change-my-desktop-wallpaper/
Share on other sites

Recommended Posts

  • 0

i had the same problem... found this googling (http://www.opentechsupport.net/forums/showthread.php?t=37820&page=2)

might help..

"Hi again i fixed the background tiles thingy.. i went to the registry(regedit) and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer and deleted all exept "Deafult" and "NoDriveTypeAutoRun" and rebooted and it worked... i'm not very skilled with the registry but i don't think u have t have other directories than Explorer(i don't) in the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\

hope you make it. and also i installed this really good program called XoftSpy 4.16 that removed alot. anyways..."

  • 0

i deleted the things in regedit and restarted my comp but no change... im still having the problem

heres the log from hijack this: please help me out someone

Logfile of HijackThis v1.99.1

Scan saved at 1:26:01 PM, on 28/12/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Symantec AntiVirus\DefWatch.exe

C:\Program Files\ewido anti-malware\ewidoctrl.exe

C:\Program Files\ewido anti-malware\ewidoguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Symantec AntiVirus\Rtvscan.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\VIAudioi\SBADeck\ADeck.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\E-Color\Common\IconMgr.exe

C:\Program Files\E-Color\Colorific\hgcctl95.exe

C:\Program Files\E-Color\E-Color Indicator\TICIcon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\Internet Explorer\iexplore.exe

D:\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigpond.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"

O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Global Startup: E-Color.lnk = C:\Program Files\E-Color\Common\IconMgr.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{451875C3-5A78-42C7-BA32-1C3C6528D017}: Domain = nsw.bigpond.net.au

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

  • 0

man, i recently came into that problem, but i cant remember the name of the program i used to fix it. Its something in the reg, thats all i know right now. Sry, maybe ill be able to find it, ill look for it right now.

okay, i dont know how much u know about computers, but i found the program that will solve ur problem, its http://www.softheap.com/how-to/dont_allow_to.html

it will work, u have to play around with the settings, like, disable to change wallapaper, and then restart, then enable it again, and restart again, hope it helps u, it helped me a lot with someones computer which had been infected with some crazy spyware. BE CAREFUL THO. when playing with the reg, u must make sure to back up any important files in case anything goes wrong. Good luck

this is my 3d edit, just wanted to say, its a trial, but totally worked for me. (bookmarked it this time)

Edited by s0nic69
  • 0

thanks you guy and once again sry about the repost slimy.... i'll try anything and everything and im pretty good with computers so i'll be able to understand a fair bit of the instructions you give me. im gonna download that thing now and let you know what happened.

  • 0

thanks you guy and once again sry about the repost slimy.... i'll try anything and everything and im pretty good with computers so i'll be able to understand a fair bit of the instructions you give me. im gonna download that thing now and let you know what happened.

yeah let us know

  • 0

ok, i did everything you guys advised, i even deleted a few things from my registry

"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer and deleted all exept "Deafult" and "NoDriveTypeAutoRun" and rebooted and it worked... i'm not very skilled with the registry but i don't think u have t have other directories than Explorer(i don't) in the HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ "

Once again i rebooted in safe mode and did the scans, found a few cookies that were spyware and got rid of them.

I restarted in normal and the problem is still there, i cant change my desktop background and the wallpaper under the desktop tab in display properties is still not allowing me to scroll or click on any wallapapers.

I dont know what else to do.

Here's a fresh hijack this log:

Logfile of HijackThis v1.99.1

Scan saved at 9:09:16 PM, on 28/12/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Symantec AntiVirus\DefWatch.exe

C:\Program Files\ewido anti-malware\ewidoctrl.exe

C:\Program Files\ewido anti-malware\ewidoguard.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

C:\Program Files\Symantec AntiVirus\Rtvscan.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\PROGRA~1\SYMANT~1\VPTray.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\VIAudioi\SBADeck\ADeck.exe

C:\Program Files\1st Security Agent\newadmin.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\E-Color\Common\IconMgr.exe

C:\Program Files\E-Color\Colorific\hgcctl95.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\E-Color\E-Color Indicator\TICIcon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\Internet Explorer\iexplore.exe

D:\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigpond.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"

O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1

O4 - HKLM\..\Run: [00saskda] "C:\Program Files\1st Security Agent\newadmin.exe" saskda

O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Global Startup: E-Color.lnk = C:\Program Files\E-Color\Common\IconMgr.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{451875C3-5A78-42C7-BA32-1C3C6528D017}: Domain = nsw.bigpond.net.au

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

  • 0

Hi,

Goto run and type gpedit.msc

You get a window. Find 'Administrative Templates' under User Configuration. Expand that and then find 'Display' and click on that. In the right pane you should see 'Prevent Changing Wallpaper'. Set that value to Not Configured. Then reboot or type gpupdate /force in a command prompt.

Cheers

Rich

  • 0

I have the exact same problem. I'm confident I've removed every trace of virus/spyware on my computer, and I also managed to get rid of the box in the middle of the screen, but its now just plain navy blue and my only existing problem is that i can't change it back to normal. I got rid of most of the crap by booting into safemode and then deleting the exes it had installed. This might be a bit risky if you dont know what you're doing, but look around C:, C:\Windows, and C:\Windows\System32 and also Program files, i right clicked and sorted the icons by "Modified" and it showed the newest created/modified files. DO NOT just delete anything though, search on google and you should be avle to find out what it is, and if not, its probably part of the virus/spyware but still be cautious.

Anyway If anyone knows how to fix the desktop it would be greatly appreciated.

  • 0

I also had this problem 2 days ago. To remove it just do this:

Use Microsoft Antispyware/Defender to get rid of all Spyware first!

Use a virus scanner to delete the Trojans/Virusses (if present) use Sophos 5 (great app).

Goto regedit, search for "desktop.htm(l)" and change it to normal and play the regedit to enablewallpapers

Thats worked for me!

  • 0

Spysheriff is malware It's pretty bad e.g. if you try to use System Restore you will find that Spysheriff erased your restore points, and do lots more damage like changing your whole desktop settings etc.

Instead follow these steps:

Open task manager by pressing Ctrl-Alt-Del, and click on the "Processes" tab. Look for Spysheriff there and kill the process if you see it. If you see a process named "winstall" (winstall.exe) then delete this one also.

In the control panel goto "Add/ Remove Programs" and remove the "SpySheriff" program. If it says that it cannot uninstall, then you still have it running. It will uninstall once it's not running.

Your desktop background will not be restored by that uninstall. Go into the registry by starting RegEdit.exe from the start button

Look for this key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop

It will have about 6 values stored that disable certain things. Delete this whole branch ActiveDesktop - the system will work with default values afterwards.

Also delete this branch in your registry:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

Look in your root directory for a file named winstall.exe. Most of the time it is found in in c:\ and 24064 Bytes in size.

This file is scheduled to execute each time you boot and it will re-install Spysheriff.

Delete that file.

there may also be additional executable files that were created at the same time as winstall.exe. Those files may be named 'winstall.exe' and 'ibm00001.exe'. You should delete those files as well.

You should search on your system for any files with "ibm000" or "Tool"on their name, This virus also creates files with names and executables such as "Tool.exe", "Tools2.exe" "tools3.exe" etc and also go to your Windows and System32 folders and organize your files view by "Dated Modified" look carefully for ANY files created or modified the day you were infected, remove any suspicious ones, they shouldnt be there if you havent installed anything that day, If any system file was modified DO NOT remove it but watch it carefully, There should probably be some .html files too called something like secure32.html, desktop.html or wallpaper.html those should also be look for and removed, You can find them by searching by date created.

This virus also drops files at:

C:\Program Files\Common Files\Microsoft Shared\Web Folders\

So search carefully into this folder and delete any suspicious files created in the day of the infection.

Restart your system.

Done.

Edited by Ely
  • 0

Sorry Mate haven't read all the replies so forgive if someone has already said this

Try right clicking on your desktop > properties > desktop > customize desktop > pick web from the tab at the top and you might find that the virus has set your background to a webpage, it happened to me too just delete the current setting :D

  • 0

Thanks for the help Ely, much appreciated - it worked fine for me.

No problem, Make sure you re-read my post as I have updated it with some extra info on files created and the such.

  • 0

ok first of all, thanks all for trying to help and im trying the advice/tips.

Rick i do have Windows xp Home edition. uglydan after my first few scans i went through every file and got rid of anything suspicious or that was created on the 28/12/05 but nothing much happened.

cai_sebas i dont really know what you mean. Which hkey and sub folders to i go to?

And now Ely. Firstly i have already done the following:

- alt ctrl del to end those processes and then i unistalled spysherif from add/remove

- i deletd those 6 items in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer except for one which is called NoDriveAutoRun which has the type REG_DWORD and the data 0x00000091 (145). Do i delete this?

+ In the following HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System i have a file called Wallpaper with type REG_SZ and the data C:\WINDOWS\desktop.html. Should i delete this? Can i somehow modify it? Why is it html?

- You said to delete the whole branch in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop. Does that also mean i should delete the file called (Default) with the typ REG_SZ and data (value not set)?

I did a search on the computer for anything with winstall, tool and ibm0000 in it but came up with no results.

I also look in here C:\Program Files\Common Files\Microsoft Shared\Web Folders\ but didnt find anything that was created/modified recently or that looked suspicious.

One last thing:

The part where i circled in red and have the question mark beside it is an unknown wallpaper which i assume is my current background. Notice how it looks like a webpage format file :unsure:

wallpaperproblem.jpg

  • 0

Check my post you MUST delete all the entries I told you they are all part of the virus, the wallpaper.html is probably on your System32 or Windows folders. it should have a name such as: desktop.html , wallpaper.html or secure32.html it could have other names too. yes delete the whole branch of the registry keys I told you about however Im NOT sure about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer I have to investigate more about it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Maybe it's just my old-school soul talking, but I’ve always felt that games aren't 'real' games until they hit the PC. Leaving the PC community out at launch just doesn't sit right with me. That being said, I'm probably going to buy the PS5 just for the fun of trying it out.
    • The Vibe Coding Playbook: Building Your Tech Business with AI —was $35, now FREE by Steven Parker Claim your complimentary copy (worth $35) of "The Vibe Coding Playbook: Building Your Tech Business with AI" for free, before the offer ends on June 23. Description A detailed and up-to-date walkthrough for entrepreneurs with limited (or non-existent) coding skills who want to build profitable software companies using new gen-AI tools. In The Vibe Coding Playbook: Building Your Tech Business With AI, renowned AI and data science educator Siraj Raval walks you through exactly what you need to do to build a technology business with generative AI-powered code assistants. Raval offers step-by-step guidance for non-technical professionals and entrepreneurs interested in creating scalable, profitable enterprises without spending years learning how to code. This book conceives of new artificial intelligence tools, like Cursor, as “co-founders,” lighting your way to constructing valuable software products and services. You’ll learn to build minimally viable products (MVPs), iterate on your software products as you develop and after launch, and grow your company while maintaining a lean, efficient, solopreneur-focused structure. Inside the book: Detailed guidance for entrepreneurs interested in creating powerful tech solutions for niche problems and markets without hiring expensive software developers Strategies for using generative AI tools to substitute for traditional technical co-founders Illustrative case studies from real-world founders who built successful technology businesses without learning to code Useful tools for non-technical entrepreneurs, including prompt libraries, decision trees, QR codes linking to video tutorials demonstrating key techniques, and access to an exclusive online community of like-minded founders Perfect for ambitious professionals and entrepreneurs who want to build a successful technology company now – using commercially available AI tools – The Vibe Coding Playbook is your personal roadmap to creating useful and profitable software for customers without learning how to code. How to download for free Please ensure you read the terms and conditions to claim this offer. Complete and verifiable information is required in order to receive this free offer. If you have previously made use of these offers, you will not need to re-register. Was $35, but is now FREE | Below free offer link expires on June 23. The Vibe Coding Playbook: Building Your Tech Business with AI The below offers are also available for free in exchange for your (work) email: The Vibe Coding Playbook: Building Your Tech Business with AI ($35 Value) FREE - Expires 6/23 The Persuasion Engine: How Any Business Can Use AI-Powered Neuromarketing to Understand and Win Customers ($28 Value) FREE - Expires 6/24 How to Do More with Less: Future-Proofing Yourself in an AI-driven Economy ($28 Value) FREE - Expires 6/30 Cloud Security Fundamentals: Building the Foundations for Secure Cloud Platforms ($131.95 Value) FREE - Expires 7/1 The Complete Free AI Learning: Master ChatGPT, Claude, Gemini & More ($21 Value) FREE How to Build an AI Design Workflow with Gamma ($21 Value) FREE The Ultimate Linux Newbie Guide – Featured Free content Python Notes for Professionals – Featured Free content Learn Linux in 5 Days – Featured Free content Quick Reference Guide for Cybersecurity – Featured Free content We post these because we earn commission on each lead so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. Other ways to support Neowin The above deal not doing it for you, but still want to help? Check out the links below. Check out our partner software in the Neowin Store Buy a T-shirt at Neowin's Threadsquad Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: An account at Neowin Deals is required to participate in any deals powered by our affiliate, StackCommerce. For a full description of StackCommerce's privacy guidelines, go here. Neowin benefits from shared revenue of each sale made through the branded deals site.
    • Rockstar confirms Grand Theft Auto VI pre-orders begin next week, unveils cover art by Pulasthi Ariyasinghe The release date of Grand Theft Auto VI has moved quite a lot since its original announcement in 2023, but it finally looks like the game has found its final launch slot. Rockstar today had a new video upload on its YouTube channel, and while it wasn't a new trailer for the game, the company revealed two things. This was the pre-order kickoff date for Grand Theft Auto VI as well as the game's official cover art. The company revealed that June 25 is when fans of the series will be able to pre-order their copy of Grand Theft Auto VI. Pre-orders will be available both digitally and in retail stores. The newly unveiled cover art shows off the two new protagonists, as well as a few more characters that are probably vital to the campaign storyline. Shots of vehicles players can use like a light helicopter, motorcycle, sports car, and speed boat are also seen here, alongside a shot of a crocodile. "Jason and Lucia have always known the deck is stacked against them," says Rockstar describing the campaign's protagonist duo. "But when an easy score goes wrong, they find themselves on the darkest side of the sunniest place in America, in the middle of a conspiracy stretching across the state of Leonida — forced to rely on each other more than ever if they want to make it out alive." Grand Theft Auto VI is coming to Xbox Series X|S and PlayStation 5 on November 19, 2026. A PC version has not been confirmed yet, though it's expected by many to land after the console release. When asked about this, the Take-Two CEO says it considers the core audience for the Grand Theft Auto franchise to be on consoles.
  • Recent Achievements

    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      553
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      72
    4. 4
      Michael Scrip
      64
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!