• 0

I cant change my desktop wallpaper


Question

hey

My compuer was recently infected by spysherif however i followed some removal instructions and i think i managed to get rid of some of it.

First i did a full anti-virus system scan using SymantecAntivirus and then i used Ad-Aware SE Personal, Spybot S&D and Ewido anti-malware. After i thought i got rid of it, there was a red circle with a white x in it that kept appearing in my taskbar beside the clock and a message above it saying "your computer is infect!....please download the latest anti-spyware....". Also my desktop background has been changed. It is now all blue with a black box in the middle and red text saying "Spyware Infection" and under this red writing theres more writing in white text that says "Your system is infected with spyware. Windows recomends you to use spyware removal tools..."

I restarted my computer in safe mode and ran all the programs again and deleted any infections.

I restarted my computer in normal mode and the red circle with the white x and "your computer is infect!" message above it have now gone. However the "Spyware Infection" desktop background is still there and when i try to change it under the desktop tab in display properties, the wallpaper section is disabled. I cant scroll down or select any wallpaper.

Also when i try to open a webpage its taking alot longer then usual, so i think i still have some sort of spyware/adware or something on it still. :cry:

I also have hijack this in which i saved a logfile but i dont know what to do with it. =/

I very much appreciate any help or advice on this problem

thanks

please help

Link to comment
https://www.neowin.net/forum/topic/413150-i-cant-change-my-desktop-wallpaper/
Share on other sites

Recommended Posts

  • 0

Dude read my post, god! I can see there things such as secure32 which is part of the virus, right click EVERY file which was created on that date and check its version and date created and date modified, remove ANY file created on that day, not the ones just modified. looks to me that the one called isRS-000.temp is also part of the virus, check it out and probably remove it too.

PS: Please notice that I originally said to remove: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System I didnt say anything about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer though this one looks suspicious I think it at least the branch should be there, do a search on google for that key and you will see, the branch should be there but not sure about all of its items to the right.

Edited by Ely
  • 0

k slimy i deleted that 0 file. Would you have any idea what it is? I opend it and it was empty... :huh:

hehe sry Ely (by the way im a girl, not a dude). I deleted the secure file and some of the others that were created on the 28/12/05. The rest were created either months ago or a year ago but have been modified on the 28/12/05 so i was to scared to delete those and just left them. These are the ones i left (do i still delete them even though they were created a whiiile back):

window.jpg

and slimy heres what my C:\WINDOWS\system32 looks like in modified order:

system32problem.jpg

  • 0

lol sorry for calling you dude, ok if they were not created that day but just modified then do not delete the ones that were just modified, do the same for C:\WINDOWS\system32 but I think that folder is safe for you I only see one that was modified on 28/12 and that is a system file, you should NOT delete it. Also be sure that you have Windows explorer set to show hidden files too. dont forget to do this whole check on your root folder too that is C:\

  • 0

yayayayay Elyyy you did it... I deleted that that file in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

about the wallpaper thing and my desktop went this weird grey colour. This time however when i went into the desktop tab in display properties i was able to choose and modify my background again.

Once again heres the file:

(what i typed earlier when i found this)

"In the following HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System i have a file called Wallpaper with type REG_SZ and the data C:\WINDOWS\desktop.html "

And this is my new display properties, =D see how everything is enabled again like the scroll on the side and the buttons

displayprop.jpg

Thankyou sooo much Ely and slimy and uglydan and everyone else..Thanks so much Ely. Im going to do a spyware, malware and addware clean once again in safe mode and normal mode.

God this thing was driving me crazy. Ely how can i be sure that i got rid of it all? As in theres no file hiding somewhere in my computer?

  • 0

God this thing was driving me crazy. Ely how can i be sure that i got rid of it all? As in theres no file hiding somewhere in my computer?

You cannot be 100% sure but you can remove basically everything. A few registry keys or a file may still lingerbut as long as it's not an exe, it won't do you any harm.

Glad you got it fixed. Good work Ely ;)

  • 0

LOL Ck10 I'm glad you got it fixed, you are probably now fine, but its not a bad idea to do full scans with different programs, for the time being while Microsoft puts up a patch make sure you DO NOT go to untrusted sites using Internet Explorer. and be sure to update your anti virus, there's supposely a command you can type to fix the vulnerability momentarily but it will break some things check it Here however that will break Picture Viewer, paint and others and you wont be able to see authentic files with that extension if you use that command.

  • 0

:huh:

I read that post and clicked on the link he posted to but im soo confused. I didnt understand anything.

Is it something to do with stopping bugs, spyware, adware or malware from opening in different software/programs and saving itself as that software/programs file format (like .html or .jpeg or fax viewer format) and onto your computer? and if so does this stop the bug (for example spysherif) from being executed onto your computer?

lol if none of this made sense to anyone then just ignore this post, i think i confused myself more to :rofl:

:yes: :shiftyninja: :whistle: <<< heh their so cute

  • 0

Hey if you type that command (which supposedly stops the vulnerability) you will not automatically get infected anymore when you browse a site which contains the infection, however when you type that command it will protect you but it will break things such as Windows Picture & Fax viewer and Paint or any program which attempts to open or use WMF files, I dont think it will break them totally but just when you try to see those types of files, so for the time being the best suggestion is DO NOT use Internet Explorer to visit untrusted sites till Microsoft puts out a patch, otherwise type the command but your system will be unable to view WMF files till that patch comes out and fixes it back.

  • 0

I didnt checked if this topic is new/old

But i have a problem with this Spyware and need some help

I followed the instructions and deleted all this **** and reestarted with no problems

But when the windows load, i have a Error Message saying the file ibm000....exe was not found, but i deleted

And with Tune Up StartUP Manager, i dont foudn this ibm there..

The other problem: My WIN is SP2 and after that **** i cant Enable the WIN Firewall.. No way

People this is my first message so sorry for anything..

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I just looked on my computer and there are settings and log files for utilities I have never even turned on!
    • O&O ShutUp10 3.1.1104 by Razvan Serea O&O ShutUp10 offers a simple yet effective way to take control of your Windows privacy. It provides access to almost 50 privacy-related tweaks, most of them hidden or not easily accessible to the average computer users. Using a very simple interface, you decide how Windows 10/11 should respect your privacy by deciding which unwanted functions should be deactivated. Using ShutUp10 you can easily disable Windows Defender, turn off telemetry, disable peer-to-peer updates, turn off Wi-Fi Sense, disable automatic Windows updates, turn off and reset Cortana and more. ShutUp10 allows you to create a System Restore point before you apply any changes, so that you can revert your system at any time if you run into problems. O&O ShutUp10 is entirely free and does not have to be installed – it can be simply run directly and immediately on your PC. And it will not install or download retrospectively unwanted or unnecessary software, like so many other programs do these days! O&O ShutUp10 Free and Premium The latest version brings O&O ShutUp10 Premium, expanding the app’s long-standing privacy controls with automatic enforcement of user-defined settings. Instead of manually rechecking options after every Windows update, users can set their preferred privacy configuration once—or apply recommended settings in a single click—and the tool continuously monitors them in the background. If Windows 10 or 11 re-enables disabled features or introduces new data collection paths, Premium restores the chosen settings automatically without user intervention. The free version remains available and fully functional for manual adjustments, offering the same core privacy controls for Windows. However, the Premium tier is aimed at users who want long-term, hands-off protection, adding automatic reapplication after updates, ongoing monitoring, and optional notifications to ensure privacy settings remain consistent over time. O&O ShutUp10 3.1.1104 changelog: Added “Show Differences” button in the overview panel “Don’t show again” option for the restore point prompt Ctrl+F keyboard shortcut for search/filter functionality Detection and linking of system-wide and user-specific setting associations Automatic search while typing PREM: Option to preserve notification counters and timestamps across application restarts PREM: Reset blocked settings button in the Settings dialog PREM: Informational message when no settings are blocked PREM: Update check can also be triggered from the menu PREM: Notification deduplication and activity log summary feature Improved L005 “Disable Windows Location Service”: Version-specific split (up to Windows 11 23H2) and new variant for Windows 11 24H2+ L001 (Disable Location): Added Night Light warning to the description in all languages Search now detects setting IDs even when ID display is disabled and offers to enable it Detection and removal of Copilot/AI desktop apps in RecallTerminator Optimized High DPI support PREM: Reset button is now only enabled when blocked items exist – setting IDs are shown in the confirmation dialog PREM: Updated tray icons with higher-resolution versions PREM: Activity Log timestamps now use localized date and time formats PREM: Tray icon status now uses OK/Warning indicators and localized tooltips PREM: Recall folder detection switched to service-based detection PREM: Copilot uninstallation now provides UI feedback and improved verification Fixed Description text was not displayed correctly for the last item and disappeared when clicking the scrollbar Crash when clicking a search result heading or the […] button PREM: Installation path is now correctly preserved during upgrades PREM: Tray icon was not reliably removed when exiting the application PREM: Main window was not displayed correctly in single-instance mode PREM: Incorrect display of the & symbol in tray icon tooltips on Windows 10 PREM: Fixed notification flooding after sleep/standby PREM: Dashboard was not refreshed after applying recommended settings during onboarding PREM: Progress bar was not reset after deleting Recall folders PREM: Fixed service startup failures PREM: Fixed incorrect drift detection when Automatic Protection was disabled PREM: Notifications now correctly count all deviating settings when protection is enabled PREM: Registration Wizard was shown after sleep/standby despite a valid license Download: O&O ShutUp10 3.1.1104 | 76.4 MB (Freeware) Download: O&O ShutUp10 32-bit | ARM64 View: O&O ShutUp10 Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Fascinating...W h i t e P o w e r is now also asterisks out.  
    • In the past few days I have noticed two odd moderation activities. First, when I posted the term 'White Nationist Christian' it was asterisk's out. When I changed it to **** it was allowed! Second, in the Politics is a ###business thread I was allowed to post that the GOP is a party of p e d ophiles but I was censored  when I posted the GOP are a party of p e d ophile protectors. Wtf Neowin. Please explain.
  • Recent Achievements

    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      546
    2. 2
      +Edouard
      165
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Steven P.
      66
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!