• 0

I cant change my desktop wallpaper


Question

hey

My compuer was recently infected by spysherif however i followed some removal instructions and i think i managed to get rid of some of it.

First i did a full anti-virus system scan using SymantecAntivirus and then i used Ad-Aware SE Personal, Spybot S&D and Ewido anti-malware. After i thought i got rid of it, there was a red circle with a white x in it that kept appearing in my taskbar beside the clock and a message above it saying "your computer is infect!....please download the latest anti-spyware....". Also my desktop background has been changed. It is now all blue with a black box in the middle and red text saying "Spyware Infection" and under this red writing theres more writing in white text that says "Your system is infected with spyware. Windows recomends you to use spyware removal tools..."

I restarted my computer in safe mode and ran all the programs again and deleted any infections.

I restarted my computer in normal mode and the red circle with the white x and "your computer is infect!" message above it have now gone. However the "Spyware Infection" desktop background is still there and when i try to change it under the desktop tab in display properties, the wallpaper section is disabled. I cant scroll down or select any wallpaper.

Also when i try to open a webpage its taking alot longer then usual, so i think i still have some sort of spyware/adware or something on it still. :cry:

I also have hijack this in which i saved a logfile but i dont know what to do with it. =/

I very much appreciate any help or advice on this problem

thanks

please help

Link to comment
https://www.neowin.net/forum/topic/413150-i-cant-change-my-desktop-wallpaper/
Share on other sites

Recommended Posts

  • 0

Dude read my post, god! I can see there things such as secure32 which is part of the virus, right click EVERY file which was created on that date and check its version and date created and date modified, remove ANY file created on that day, not the ones just modified. looks to me that the one called isRS-000.temp is also part of the virus, check it out and probably remove it too.

PS: Please notice that I originally said to remove: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System I didnt say anything about HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer though this one looks suspicious I think it at least the branch should be there, do a search on google for that key and you will see, the branch should be there but not sure about all of its items to the right.

Edited by Ely
  • 0

k slimy i deleted that 0 file. Would you have any idea what it is? I opend it and it was empty... :huh:

hehe sry Ely (by the way im a girl, not a dude). I deleted the secure file and some of the others that were created on the 28/12/05. The rest were created either months ago or a year ago but have been modified on the 28/12/05 so i was to scared to delete those and just left them. These are the ones i left (do i still delete them even though they were created a whiiile back):

window.jpg

and slimy heres what my C:\WINDOWS\system32 looks like in modified order:

system32problem.jpg

  • 0

lol sorry for calling you dude, ok if they were not created that day but just modified then do not delete the ones that were just modified, do the same for C:\WINDOWS\system32 but I think that folder is safe for you I only see one that was modified on 28/12 and that is a system file, you should NOT delete it. Also be sure that you have Windows explorer set to show hidden files too. dont forget to do this whole check on your root folder too that is C:\

  • 0

yayayayay Elyyy you did it... I deleted that that file in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

about the wallpaper thing and my desktop went this weird grey colour. This time however when i went into the desktop tab in display properties i was able to choose and modify my background again.

Once again heres the file:

(what i typed earlier when i found this)

"In the following HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System i have a file called Wallpaper with type REG_SZ and the data C:\WINDOWS\desktop.html "

And this is my new display properties, =D see how everything is enabled again like the scroll on the side and the buttons

displayprop.jpg

Thankyou sooo much Ely and slimy and uglydan and everyone else..Thanks so much Ely. Im going to do a spyware, malware and addware clean once again in safe mode and normal mode.

God this thing was driving me crazy. Ely how can i be sure that i got rid of it all? As in theres no file hiding somewhere in my computer?

  • 0

God this thing was driving me crazy. Ely how can i be sure that i got rid of it all? As in theres no file hiding somewhere in my computer?

You cannot be 100% sure but you can remove basically everything. A few registry keys or a file may still lingerbut as long as it's not an exe, it won't do you any harm.

Glad you got it fixed. Good work Ely ;)

  • 0

LOL Ck10 I'm glad you got it fixed, you are probably now fine, but its not a bad idea to do full scans with different programs, for the time being while Microsoft puts up a patch make sure you DO NOT go to untrusted sites using Internet Explorer. and be sure to update your anti virus, there's supposely a command you can type to fix the vulnerability momentarily but it will break some things check it Here however that will break Picture Viewer, paint and others and you wont be able to see authentic files with that extension if you use that command.

  • 0

:huh:

I read that post and clicked on the link he posted to but im soo confused. I didnt understand anything.

Is it something to do with stopping bugs, spyware, adware or malware from opening in different software/programs and saving itself as that software/programs file format (like .html or .jpeg or fax viewer format) and onto your computer? and if so does this stop the bug (for example spysherif) from being executed onto your computer?

lol if none of this made sense to anyone then just ignore this post, i think i confused myself more to :rofl:

:yes: :shiftyninja: :whistle: <<< heh their so cute

  • 0

Hey if you type that command (which supposedly stops the vulnerability) you will not automatically get infected anymore when you browse a site which contains the infection, however when you type that command it will protect you but it will break things such as Windows Picture & Fax viewer and Paint or any program which attempts to open or use WMF files, I dont think it will break them totally but just when you try to see those types of files, so for the time being the best suggestion is DO NOT use Internet Explorer to visit untrusted sites till Microsoft puts out a patch, otherwise type the command but your system will be unable to view WMF files till that patch comes out and fixes it back.

  • 0

I didnt checked if this topic is new/old

But i have a problem with this Spyware and need some help

I followed the instructions and deleted all this **** and reestarted with no problems

But when the windows load, i have a Error Message saying the file ibm000....exe was not found, but i deleted

And with Tune Up StartUP Manager, i dont foudn this ibm there..

The other problem: My WIN is SP2 and after that **** i cant Enable the WIN Firewall.. No way

People this is my first message so sorry for anything..

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Same Internet Archive seemed to grab the new version https://web.archive.org/web/20...d/Setup_MakeMKV_v1.18.4.exe Here's the link to an additional file it periodically downloads https://web.archive.org/web/20260213092148/https://www.makemkv.com/sdf.bin I think update's keys, etc. To manually trigger this update, put the sdf.bin file in the root of where the program is installed. When you launch the program it will pick up the file and import it. Typically put it here: C:\Program Files (x86)\MakeMKV\sdf.bin
    • Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft's fault by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. Although the tech giant did not acknowledge any major problems, some users online reported various issues ranging from OneDrive and Dropbox access problems, BitLocker recovery lockouts, to blue screens and BSODs. You can read about them in this dedicated piece. While there is still no confirmation about those problems from Microsoft the company has admitted to another bug which we did not report on. The tech giant has confirmed it has received reports of an issue in which certain third-party applications may be unable to launch Microsoft Office apps or open Office documents after installing the Patch Tuesday. This affects both Windows 11 as well as Windows 10. The company says the problem impacts a subset of applications that rely on OLE (Object Linking and Embedding) automation to communicate with Microsoft Office programs. According to Microsoft, affected scenarios involve third-party software attempting to open Office applications or documents from within their own interface. In such cases, the Office program may fail to launch altogether, or the requested document may not open. Oddly there may not be any error message, which probably makes the issue difficult to diagnose. The bug affects several Office products, including Word, Excel, PowerPoint, Access, and other apps in the Microsoft Office suite when they are launched through the affected software. These include tax and accounting software such as CCH Engagement and Workpaper Manager, dental practice management solutions like Dentrix and Softdent, as well as the popular research and reference management tool Zotero. Microsoft adds that other applications using similar Office integration methods could also experience the same problematic behavior. To understand the issue it is important to look at OLE, the Microsoft technology involved. OLE allows different applications to work together and share data, while its Automation feature lets one program control another. Thus this enables third-party software to launch Microsoft Office apps, open documents, and perform tasks automatically without requiring users to switch between programs. Because many accounting, healthcare, research, and business applications rely on OLE automation to interact with Word, Excel, PowerPoint, and other Office apps, any disruption can break those workflows. As a result, affected software may be unable to open Office documents or launch Office applications even though the programs themselves continue to work normally. At the moment the company has not provided a permanent fix though it has confirmed that engineers are actively working on a resolution, which will be delivered through a future Windows update. As such additional details will be shared once more information becomes available. In the meantime, Microsoft recommends a simple workaround for affected users whic is to open the Office application or document directly rather than launching it through the third-party program. For enterprise customers and organizations managing larger deployments, Microsoft says an additional mitigation is available. Admins experiencing the problem on their managed devices are advised to contact Microsoft Support for business to obtain and apply the workaround.
    • It saddens me when cars are such dull colours now. Mine is bright metallic blue and I absolutely adore it for standing out in contrast to that depressing backdrop of traffic.
    • Sparkle 2.20.0 by Razvan Serea Sparkle is a free, open-source Windows optimization tool designed to make your PC faster, cleaner, and more private. With Sparkle, you can easily debloat Windows by removing unnecessary apps and services, disable Microsoft tracking to enhance privacy, and apply performance tweaks to boost speed. Its cleaner removes junk and temporary files, while every change is safe and fully reversible. Sparkle also features a modern, user-friendly interface with automatic updates, making system maintenance simple. Explore over 39 tweaks, from disabling telemetry and hibernation to optimizing network and game settings, all aimed at customizing and enhancing your Windows experience. Sparkle supports Windows 10 and 11. Sparkle 2.20.0 changelog: Debloat Tweak has animated border New homepage loading UI New Tweak Modal (Markdown Supported) Refactored GPU Detection Added Tests with vitest Added foobar2000 to apps Added Localsend to apps Updated Modal Styles Added styles for disabled inputs Added Animated Border to debloat-windows tweak Bumped dependencies Refactor System info logic for speed Tweak info modals now support Markdown Added Clear System info cache to settings Redesigned Home Page Loading UI Changed Some Icons around the app Download: Sparkle 2.20.0 | Portable | ~100.0 MB (Open Source) Links: Sparkle Website | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • lol it was a typo, fixed! haha imagine an actual 4TB Gen4 NVMe for $40 in 2026
  • Recent Achievements

    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!