Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 17-12-2007, 06:14 PM   #1 (permalink)
*
 
bajaj151's Avatar
 
Join Date: May 2006
Location: India
Posts: 866
Default Folder on Desktop


A folder named as:

Abn.gpc, Cef.gpc, gbieh.gmd, gbiehuni.dll , GBIEHCEF.DLL , gbiehabn.dll, gbpdist.dll', PChar('Abn.gpc, Cef.gpc, gbieh.gmd, gbiehuni.dll , GBIEHCEF.DLL , gbiehabn.dll, gbpdist.dll

is there on my desktop , I dont know how....
But I am not able to delete the folder as it is shared. Also I am not able to remove the sharing.
So, what should I do to get rid of this folder ?
__________________
Phenom x6 1055T 3.75 GHz | MSI 890GXM G65 | Corsair XMS3 2*4GB 1600mhz | BenQ E2200HD | Xbox 360 Controller | Seagate 2TB | CM HAF 922 | Corsair VX 550 | Logitech MX 518 | Logitech Wireless Keyboard | Sapphire 7850 OC
bajaj151 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 17-12-2007, 10:01 PM   #2 (permalink)
Wise Old Owl
 
alib_i's Avatar
 
Join Date: Jun 2004
Location: omnipresent
Posts: 1,191
Default Re: Folder on Desktop

From what I could research on google .. it's a Trojan called "Win32.banker"

More info and removal (kinda complicated and confusing)
http://www.threatexpert.com/report.a...f-22f1ec29133c
http://www.viruslist.com/en/viruses/...sid=49771#doc2
http://www.spywaredb.com/remove-trojan-win32-banker-j/

Easier way out ..
Install Ad-Aware : http://www.lavasoftusa.com/software/adaware/
__________________
What I've felt, What I've known; Never shined through in what I've shown
Never free, Never me; So I dub thee unforgiven
-Metallica
alib_i is offline  
Old 17-12-2007, 10:41 PM   #3 (permalink)
TechTin.com
 
ravi_9793's Avatar
 
Join Date: Jun 2005
Location: www.TechTin.com
Posts: 4,090
Default Re: Folder on Desktop

U can delete them in safe mode.
But make sure to turn off system restore before U do scan..and delete those files.

Last edited by ravi_9793; 18-12-2007 at 08:58 AM.
ravi_9793 is offline  
Old 18-12-2007, 05:40 AM   #4 (permalink)
Right Off the Assembly Line
 
Join Date: Dec 2007
Posts: 1
Default Re: Folder on Desktop

I had the same problem:

Here is what I did:

Log in as ADMIN:.

Stopped sharing all the folders .

Right click on the folder you want to delete.

Go to the advance security and Change the owner to yourself.

now go to sharing and stop sharing.

Now delete the folder.
thegreathemant is offline  
Old 19-12-2007, 07:05 PM   #5 (permalink)
*
 
bajaj151's Avatar
 
Join Date: May 2006
Location: India
Posts: 866
Default Re: Folder on Desktop

Ad-Aware is not detecting any threats ....
__________________
Phenom x6 1055T 3.75 GHz | MSI 890GXM G65 | Corsair XMS3 2*4GB 1600mhz | BenQ E2200HD | Xbox 360 Controller | Seagate 2TB | CM HAF 922 | Corsair VX 550 | Logitech MX 518 | Logitech Wireless Keyboard | Sapphire 7850 OC
bajaj151 is offline  
Old 19-12-2007, 09:25 PM   #6 (permalink)
SivaChand
 
Join Date: Dec 2007
Location: TamilNadu
Posts: 108
Default Re: Folder on Desktop

Try avast and login as admin in the safe mode
kpmsivachand is offline  
Old 20-12-2007, 10:45 AM   #7 (permalink)
*
 
bajaj151's Avatar
 
Join Date: May 2006
Location: India
Posts: 866
Default Re: Folder on Desktop

Quote:
Originally Posted by kpmsivachand
Try avast and login as admin in the safe mode
Avast too not able to delete that folder.What should I do now ?
__________________
Phenom x6 1055T 3.75 GHz | MSI 890GXM G65 | Corsair XMS3 2*4GB 1600mhz | BenQ E2200HD | Xbox 360 Controller | Seagate 2TB | CM HAF 922 | Corsair VX 550 | Logitech MX 518 | Logitech Wireless Keyboard | Sapphire 7850 OC
bajaj151 is offline  
Old 20-12-2007, 11:16 AM   #8 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Default Re: Folder on Desktop

There might be process(es) assosciated with it. In safe mode, what processes do you see?
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
phreak0ut is offline  
Old 20-12-2007, 02:19 PM   #9 (permalink)
*
 
bajaj151's Avatar
 
Join Date: May 2006
Location: India
Posts: 866
Default Re: Folder on Desktop

Check my log file:


Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvSvc] "RUNDLL32.EXE" C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [bdmreg] C:\Windows\system32\bdmreg.exe
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [PMCLoader] C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - C:\PROGRA~1\Stardock\OBJECT~2\DESKSC~1\deskscapes. dll
O22 - SharedTaskScheduler: Stardock Vista ControlPanel Extension - {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - C:\PROGRA~1\Stardock\OBJECT~2\DESKSC~1\DesktopCont rolPanel.dll
O22 - SharedTaskScheduler: StardockDreamController - {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - C:\PROGRA~1\Stardock\OBJECT~2\DESKSC~1\DreamContro l.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: setup_7.0.0.180_18.12.2007_17-34 - Kaspersky Lab - C:\Users\Public\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_18.12.2007_17-34.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8565 bytes
__________________
Phenom x6 1055T 3.75 GHz | MSI 890GXM G65 | Corsair XMS3 2*4GB 1600mhz | BenQ E2200HD | Xbox 360 Controller | Seagate 2TB | CM HAF 922 | Corsair VX 550 | Logitech MX 518 | Logitech Wireless Keyboard | Sapphire 7850 OC
bajaj151 is offline  
Old 20-12-2007, 04:51 PM   #10 (permalink)
*
 
bajaj151's Avatar
 
Join Date: May 2006
Location: India
Posts: 866
Default Re: Folder on Desktop

I think, its due to virus video on orkut...
__________________
Phenom x6 1055T 3.75 GHz | MSI 890GXM G65 | Corsair XMS3 2*4GB 1600mhz | BenQ E2200HD | Xbox 360 Controller | Seagate 2TB | CM HAF 922 | Corsair VX 550 | Logitech MX 518 | Logitech Wireless Keyboard | Sapphire 7850 OC
bajaj151 is offline  
Old 20-12-2007, 04:59 PM   #11 (permalink)
Wire muncher!
 
infra_red_dude's Avatar
 
Join Date: Nov 2003
Posts: 6,164
Default Re: Folder on Desktop

Plz confirm this: O4 - HKLM\..\Run: [bdmreg] C:\Windows\system32\bdmreg.exe

I dunno what it is. Other than that hijackthis log is clean.
__________________
"The true measure of a man is how he treats someone who can do him absolutely no good."

http://phoenix-ani.blogspot.com
infra_red_dude is offline  
Old 20-12-2007, 09:11 PM   #12 (permalink)
ico
.
 
ico's Avatar
 
Join Date: Jun 2007
Location: New Delhi
Posts: 8,929
Default Re: Folder on Desktop

Quote:
Originally Posted by infra_red_dude
Plz confirm this: O4 - HKLM\..\Run: [bdmreg] C:\Windows\system32\bdmreg.exe

I dunno what it is. Other than that hijackthis log is clean.
yeah! Its a Trojan

see this http://www.fileresearchcenter.com/B/...EXE-11122.html
__________________
.
ico is offline  
Old 22-12-2007, 03:32 PM   #13 (permalink)
*
 
bajaj151's Avatar
 
Join Date: May 2006
Location: India
Posts: 866
Default Re: Folder on Desktop

Quote:
Originally Posted by gagandeep
How to remove this trojan....I used Trojan remover...but no trojan found....
__________________
Phenom x6 1055T 3.75 GHz | MSI 890GXM G65 | Corsair XMS3 2*4GB 1600mhz | BenQ E2200HD | Xbox 360 Controller | Seagate 2TB | CM HAF 922 | Corsair VX 550 | Logitech MX 518 | Logitech Wireless Keyboard | Sapphire 7850 OC
bajaj151 is offline  
Old 22-12-2007, 05:41 PM   #14 (permalink)
ico
.
 
ico's Avatar
 
Join Date: Jun 2007
Location: New Delhi
Posts: 8,929
Default Re: Folder on Desktop

Try using Trojan Hunter 5. Also try NOD32 and Kaspersky 7.
__________________
.
ico is offline  
Old 23-12-2007, 08:08 AM   #15 (permalink)
vaibhavtek
Guest
 
Posts: n/a
Default Re: Folder on Desktop

Just Trojan Virus
Scan PC with Antivirus AVG and u can also delete that file in Safe Mode or use Unlocker software.
 
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Remove Desktop.ini & Folder.htt virus HTML.Redlof.A binoyxj Software Q&A 2 10-12-2007 06:04 PM
folder on desktop with target on another drive saurabh kakkar QnA (read only) 3 09-06-2007 10:13 PM
Custom folder icons with desktop.ini casanova Software Q&A 2 02-04-2007 12:33 AM
Folder.htt and desktop.ini...! Is it a virus...? ramprasad Software Q&A 8 28-02-2005 11:45 AM

 
Latest Threads
- by abhidev
- by clmlbx
- by Sarath
- by ico

Advertisement




All times are GMT +5.5. The time now is 02:56 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2