• 0

I cant change my desktop wallpaper


Question

hey

My compuer was recently infected by spysherif however i followed some removal instructions and i think i managed to get rid of some of it.

First i did a full anti-virus system scan using SymantecAntivirus and then i used Ad-Aware SE Personal, Spybot S&D and Ewido anti-malware. After i thought i got rid of it, there was a red circle with a white x in it that kept appearing in my taskbar beside the clock and a message above it saying "your computer is infect!....please download the latest anti-spyware....". Also my desktop background has been changed. It is now all blue with a black box in the middle and red text saying "Spyware Infection" and under this red writing theres more writing in white text that says "Your system is infected with spyware. Windows recomends you to use spyware removal tools..."

I restarted my computer in safe mode and ran all the programs again and deleted any infections.

I restarted my computer in normal mode and the red circle with the white x and "your computer is infect!" message above it have now gone. However the "Spyware Infection" desktop background is still there and when i try to change it under the desktop tab in display properties, the wallpaper section is disabled. I cant scroll down or select any wallpaper.

Also when i try to open a webpage its taking alot longer then usual, so i think i still have some sort of spyware/adware or something on it still. :cry:

I also have hijack this in which i saved a logfile but i dont know what to do with it. =/

I very much appreciate any help or advice on this problem

thanks

please help

Link to comment
https://www.neowin.net/forum/topic/413150-i-cant-change-my-desktop-wallpaper/
Share on other sites

Recommended Posts

  • 0

Dude read my post, god! I can see there things such as secure32 which is part of the virus, right click EVERY file which was created on that date and check its version and date created and date modified, remove ANY file created on that day, not the ones just modified. looks to me that the one called isRS-000.temp is also part of the virus, check it out and probably remove it too.

PS: Please notice that I originally said to remove: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System I didnt say anything about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer though this one looks suspicious I think it at least the branch should be there, do a search on google for that key and you will see, the branch should be there but not sure about all of its items to the right.

Edited by Ely
  • 0

k slimy i deleted that 0 file. Would you have any idea what it is? I opend it and it was empty... :huh:

hehe sry Ely (by the way im a girl, not a dude). I deleted the secure file and some of the others that were created on the 28/12/05. The rest were created either months ago or a year ago but have been modified on the 28/12/05 so i was to scared to delete those and just left them. These are the ones i left (do i still delete them even though they were created a whiiile back):

window.jpg

and slimy heres what my C:\WINDOWS\system32 looks like in modified order:

system32problem.jpg

  • 0

lol sorry for calling you dude, ok if they were not created that day but just modified then do not delete the ones that were just modified, do the same for C:\WINDOWS\system32 but I think that folder is safe for you I only see one that was modified on 28/12 and that is a system file, you should NOT delete it. Also be sure that you have Windows explorer set to show hidden files too. dont forget to do this whole check on your root folder too that is C:\

  • 0

yayayayay Elyyy you did it... I deleted that that file in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

about the wallpaper thing and my desktop went this weird grey colour. This time however when i went into the desktop tab in display properties i was able to choose and modify my background again.

Once again heres the file:

(what i typed earlier when i found this)

"In the following HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System i have a file called Wallpaper with type REG_SZ and the data C:\WINDOWS\desktop.html "

And this is my new display properties, =D see how everything is enabled again like the scroll on the side and the buttons

displayprop.jpg

Thankyou sooo much Ely and slimy and uglydan and everyone else..Thanks so much Ely. Im going to do a spyware, malware and addware clean once again in safe mode and normal mode.

God this thing was driving me crazy. Ely how can i be sure that i got rid of it all? As in theres no file hiding somewhere in my computer?

  • 0

God this thing was driving me crazy. Ely how can i be sure that i got rid of it all? As in theres no file hiding somewhere in my computer?

You cannot be 100% sure but you can remove basically everything. A few registry keys or a file may still lingerbut as long as it's not an exe, it won't do you any harm.

Glad you got it fixed. Good work Ely ;)

  • 0

LOL Ck10 I'm glad you got it fixed, you are probably now fine, but its not a bad idea to do full scans with different programs, for the time being while Microsoft puts up a patch make sure you DO NOT go to untrusted sites using Internet Explorer. and be sure to update your anti virus, there's supposely a command you can type to fix the vulnerability momentarily but it will break some things check it Here however that will break Picture Viewer, paint and others and you wont be able to see authentic files with that extension if you use that command.

  • 0

:huh:

I read that post and clicked on the link he posted to but im soo confused. I didnt understand anything.

Is it something to do with stopping bugs, spyware, adware or malware from opening in different software/programs and saving itself as that software/programs file format (like .html or .jpeg or fax viewer format) and onto your computer? and if so does this stop the bug (for example spysherif) from being executed onto your computer?

lol if none of this made sense to anyone then just ignore this post, i think i confused myself more to :rofl:

:yes: :shiftyninja: :whistle: <<< heh their so cute

  • 0

Hey if you type that command (which supposedly stops the vulnerability) you will not automatically get infected anymore when you browse a site which contains the infection, however when you type that command it will protect you but it will break things such as Windows Picture & Fax viewer and Paint or any program which attempts to open or use WMF files, I dont think it will break them totally but just when you try to see those types of files, so for the time being the best suggestion is DO NOT use Internet Explorer to visit untrusted sites till Microsoft puts out a patch, otherwise type the command but your system will be unable to view WMF files till that patch comes out and fixes it back.

  • 0

I didnt checked if this topic is new/old

But i have a problem with this Spyware and need some help

I followed the instructions and deleted all this **** and reestarted with no problems

But when the windows load, i have a Error Message saying the file ibm000....exe was not found, but i deleted

And with Tune Up StartUP Manager, i dont foudn this ibm there..

The other problem: My WIN is SP2 and after that **** i cant Enable the WIN Firewall.. No way

People this is my first message so sorry for anything..

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Latest Rufus update improves new Windows 11 install method by Taras Buria Pete Batard, the maker of Rufus, a very popular app for creating bootable Windows (and other OS) media, has released a new beta version of its app. Rufus 4.15 beta is now out, and while it offers no new features, there are all sorts of improvements and fixes, including for the new Windows 11 installation method that was introduced in version 4.14 in early May. The "Silent Windows 11 installation" is a new feature whose goal is to automate operating system installation. All you have to do is boot from the drive, and then Rufus takes over, doing all things for you, such as setting up a new account, skipping ads and prompts, and more. It is a very handy tool, but initially, it had some bugs and issues that required addressing. With version 4.15 beta, Rufus is fixing that, particularly a bug with installation failing at 75%, crashes on Snapdragon X-based PCs, and more. Here is the changelog: Rufus 4.15 beta is now available for download from its GitHub repository. If you have never used Rufus before, you can check out our guide here. It is a very useful utility to have, as it allows you to deal with plenty of Windows 11's annoyances, which are still there, despite Microsoft's ongoing efforts to fix them.
    • Microsoft fixes one of Excel Copilot's most frustrating limitations by Usama Jawad Microsoft began integrating Copilot into Excel a couple of years ago and has been upgrading it with new functionalities since then. While some changes have been controversial, Microsoft is hoping to win over users by allowing them to be more productive via Copilot. To that end, it has now announced a Copilot improvement that may actually be appreciated by people who use it regularly. Excel customers often use the Copilot prompt box to issue instructions to format and customize their data, but it can become quite tiring to keep repeating the same instructions again and again. Microsoft now allows you to define Copilot personalization rules for formatting, naming conventions, formulas, and report styles. These can be accessed via Settings > Personalization, where you can explain your rules in natural language like "Always format currency in USD with no decimals", and just let Copilot take care of the rest. Microsoft is going a step further in this direction by allowing you to set workbook rules too. These rules are stored as a .Rules sheet, and are preserved while the workbook is shared. This fosters collaboration while making sure that standard rules govern the Copilot editing experience across the organization. Other advantages of this capability include pointing it to specific examples, defining dynamic formulas, and referencing an entire sheet and asking Copilot to infer rules based on that. You can leverage this feature by opening Copilot in Excel, clicking on "+", and selecting Create workbook rules. If you have an existing .Rules sheet, you can simply start listing the rules in column A as well. Personalization features are available to all Copilot in Excel users across the web, Mac, and Windows. Meanwhile, workbook rules are currently being previewed for Windows and Mac customers on the Insiders channel. General availability is scheduled after a few weeks, but a concrete date is currently unknown. Overall, the Excel capability is quite similar to ChatGPT's memory features, which allow you to permanently store items in the AI model's context window.
    • Imagine you still haven't discovered Total Commander that is doing all those things for three decades already...
    • This sounds like underneath the nice marketing spin, either someone at Adobe got tired of their lazy devs and asked Microsoft to help them sort at least some of Adobe's ancestral spaghetti code to make it go faster, or Microsoft wanted Adobe's crap to run better on Windows to make it look better when compared to Apple, so they offered to intervene. Either way, GOOD.
    • My favorite file manager for Windows 11 finally gets a long-requested feature by Taras Buria Files is among the best File Explorer alternatives for Windows 10 and 11. This free app is packed with all sorts of features and conveniences, but there is one crucial feature that is still missing—Tree View. Fortunately, the latest update in the Preview channel finally delivers it. With version 4.1.4, which is now available for download in the Preview channel, developers implemented Tree View, a new mode that displays folders in an expandable hierarchy. Windows 11's stock File Explorer always had this feature, but it was nowhere to be found in Files until now. Starting with the latest preview update, you can expand each drive and its nested folders without leaving the current location and then open the folder you need in the main view. To try Tree View in Files, update the app to the latest preview version, then click the small arrow next to a drive to expand its content. The developers say they are rolling out Tree View in Preview first to gather feedback from users and improve the feature before bringing it to all in the stable channel. In addition to Tree View, Files 4.1.14 improves the Windows Fonts folder. You can now preview each font directly in Files with no need to open the built-in font viewer. For now, these two features are only available in the Preview channel. For those using the stable release, developers recently released version 4.1.3, with improvements for the built-in tag system, on-demand folder size calculation, and plenty of various fixes. You can check out the full release notes here. You can download Files from the Microsoft Store (paid version) or its official website (free).
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      90
    4. 4
      Steven P.
      79
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!