I can't change my desktop from a black background to a picture(Even if I Right click the picture from a website and put it as background). Whenever I log out though I can see the pic I put for a few seconds, but as soon as the computer is loaded it goes back to black. I wanna get back the the option that is greyed out on the desktop tab under background.

Screen:
[IMG][/IMG]

Dani AI

Generated

Short diagnosis and what likely happened
The fact that the picture flashes at logoff but the desktop is black after you sign in means something that runs during or after logon is removing or blocking the wallpaper. That can be a policy or display-setting lock, a disabled visual/theme service, or (as several people here found) malware that replaces or prevents the normal desktop behavior. , and pointed to each of those three causes in different posts — combine their ideas when you troubleshoot.

Practical, safe troubleshooting (in order)

  1. See if it’s user-specific: create a new local user account and sign in. If the wallpaper works there, the problem is in the original user profile.
  2. Try Safe Mode. If wallpaper appears in Safe Mode, a startup program or non-Microsoft service is the culprit. Use a startup-management tool (or the Services/Startup applet in Administrative Tools) to disable nonessential entries and reboot one at a time.
  3. Scan with reputable, up‑to‑date anti‑malware tools (use an offline/rescue scanner if the system blocks tools). If utilities or consoles close immediately, that’s a red flag for active malware.
  4. If Display/Appearance controls are disabled in your UI, that usually means a policy or registry restriction was applied. Undoing those settings requires a backup first — export the affected keys or create a restore point before changing anything.
  5. If you’re comfortable with advanced tools, use Autoruns/Process Explorer to find and remove suspicious startup executables and registered DLLs; otherwise get help from the spyware forum and post logs there.

Notes and cautions
Do not run random registry tweaks from untrusted sites without backing up. If you’re unsure how to use Command Prompt or registry editors, prefer GUI removal tools or ask for step‑by‑step help. If removal succeeds but Visual Styles are broken, run the system file repair utilities or create a fresh user profile and migrate data. This thread already shows two successful resolutions (policy removal and malware cleanup), so follow the ordered checks above to isolate which case you have.

Recommended Answers

All 17 Replies

Go to Start-Run and type "services.msc" without quotes and press ok

From the list select Themes and check whether it is disabled and stopped, if disabled, enable and start it

Go to Start-Run and type "services.msc" without quotes and press ok

From the list select Themes and check whether it is disabled and stopped, if disabled, enable and start it

Thanks, I'm gonna try that. Whenever I click run > services.msc the window juss' closes itself. It stays up for a few seconds.

-Merch™

Start-Run-msconfig, click on services tab and then from the list themes and start

Start-Run-msconfig, click on services tab and then from the list themes and start

Nothing happend. No window popped up. The pointer did it's lil' load animation then it went back to normal. Somethin' twisted is goin' on in my computer :)

-Merch™

dear merch,
click on this link:- http://www.kellys-korner-xp.com/xp_tweaks.htm
go to Line 128. Restore Desktop and Screensaver Tabs then click on it a windows would come up
click on save and save it on the desktop and then run it,it would ask u whether you want to add this info to the registry click on yes and restart the system. its a registry tweak and that should solve the prob.
thanks

Doesn't seem to do anything.

-Merch™

now merch had you installed any software after which you started getting this prob.for ex spysherrif and just curious have u tried system restore.
u can also try :- click on start->run->type regedit->enter
click on the folder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html
delete this key(I suggest backing it up first),
hope this works.

sounds like a worm or virus is causing this... post hijackthis log and winpfind logs...
hijackthis
winpfind

hey everyone one im new.Im having this exact same problem.This happened right after getting a virus so im sure thats what caused it.I downloaded the hijackthis and this is what it came up with.Thanks for the help
Logfile of HijackThis v1.99.1
Scan saved at 2:37:53 AM, on 1/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\kernels64.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Grisoft\AVG Free\avgwb.dat
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\matt\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: - {96b679e0-057c-4c2c-a9a9-883ef56d1921} - C:\WINDOWS\System32\mw.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels64.exe
O4 - HKLM\..\Run: [PPClean RunOnce insertion] "C:\Program Files\Yahoo!\YPSR\ppclean.exe" "clean" "cws" "2" "configreboot"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: Yahoo! Chat -
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) -
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
O20 - Winlogon Notify: nuclabdll - nuclabdll.dll (file missing)
O21 - SSODL: dIGJGkEIf - {EC5E7513-46F4-DFB9-A688-2F96BFC53D5B} - C:\WINDOWS\System32\ubiwm.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe

trapperj1986 please create a new post if you have a problem. furthermore, all hijackthis logs belong in the spyware forum.

any way, I found the following problems:
kill running:
kernels64.exe
ibm00001.exe ->

unregister:
ubiwm.dll

start > run > cmd
regsvr32 /u ubiwm.dll

remove using hjt:

O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels64.
eO4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O20 - Winlogon Notify: nuclabdll - nuclabdll.dll (file missing)
O21 - SSODL: dIGJGkEIf - {EC5E7513-46F4-DFB9-A688-2F96BFC53D5B} - C:\WINDOWS\System32\ubiwm.dll

Ok sorry bout that.Thank you for the help I downloaded "spybot search and destroy"and that worked the origanal poster might wanna try to do this.Ill also do what you said .thanks again for the help

now merch had you installed any software after which you started getting this prob.for ex spysherrif and just curious have u tried system restore.
u can also try :- click on start->run->type regedit->enter
click on the folder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html
delete this key(I suggest backing it up first),
hope this works.

Awesome. This worked. Thanks alot.

-Merch™

lolz, this post is old. :)

-Merch™

yeah. i know that. but this happend to me yesterday so i decided to google and i have found this

Exactly what I did when it happend to me. It pissed me right off.

-Merch™

now merch had you installed any software after which you started getting this prob.for ex spysherrif and just curious have u tried system restore.
u can also try :- click on start->run->type regedit->enter
click on the folder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
"Wallpaper"=SZ:C:\WINDOWS\desktop.html
delete this key(I suggest backing it up first),
hope this works.

trapperj1986 please create a new post if you have a problem. furthermore, all hijackthis logs belong in the spyware forum.

any way, I found the following problems:
kill running:
kernels64.exe
ibm00001.exe ->

unregister:
ubiwm.dll

start > run > cmd
regsvr32 /u ubiwm.dll

remove using hjt:

O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels64.
eO4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O20 - Winlogon Notify: nuclabdll - nuclabdll.dll (file missing)
O21 - SSODL: dIGJGkEIf - {EC5E7513-46F4-DFB9-A688-2F96BFC53D5B} - C:\WINDOWS\System32\ubiwm.dll

actually I haven't tried this cause I didn't understood this (bolded). I did ->run->type regedit->enter
click on the folder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

but there's no

"Wallpaper"=SZ:C:\WINDOWS\desktop.html
there is:
NoColorChoice
NoDispAppearancePage
NoDispBackgroundPage
NoDispCPL
NoDispScrSavPage
NoDispSettingsPage
NoSizeChoice
NoVisualStyleChoice

and I dont understand cmd step. it opens cmd but i dont know how to use it please help

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.