 |
20-02-2008, 12:08 PM
|
#1 (permalink)
|
|
Broken In
Join Date: Jan 2006
Posts: 109
|
help cant delete exe file from desktop
heres my hijack this Log
Quote:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:47, on 20/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Sunny\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=022108 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 7915 bytes
|
please help me out
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
20-02-2008, 01:38 PM
|
#2 (permalink)
|
|
Human Spambot
Join Date: Jan 2007
Location: Lat 28.38°N , Longt 77.13°E
Posts: 2,431
|
Re: help cant delete exe file from desktop
try unlocker
|
|
|
20-02-2008, 01:39 PM
|
#3 (permalink)
|
|
-----ATi-----
Join Date: May 2007
Location: Bangalore
Posts: 2,322
|
Re: help cant delete exe file from desktop
Did you try to delete the file from Safe mode?
__________________
http://twitter.com/akshayms
|
|
|
20-02-2008, 01:43 PM
|
#4 (permalink)
|
|
Broken In
Join Date: Jan 2006
Posts: 109
|
Re: help cant delete exe file from desktop
whats unlocker? O_O
and no i didnt tried in safemode
i had a worm from file nvcpl.dll
i deleted it and i was able to delte exe from desktop until recently same problem occured again
|
|
|
20-02-2008, 01:57 PM
|
#5 (permalink)
|
|
Human Spambot
Join Date: Nov 2004
Location: Madurai
Posts: 2,349
|
Re: help cant delete exe file from desktop
Unlocker is a free software that helps you delete locked files... Get it at http://ccollomb.free.fr/unlocker/
Arun
|
|
|
20-02-2008, 02:27 PM
|
#6 (permalink)
|
|
-----ATi-----
Join Date: May 2007
Location: Bangalore
Posts: 2,322
|
Re: help cant delete exe file from desktop
Quote:
Originally Posted by anonymusneo
i had a worm from file nvcpl.dll
|
Is nvcpl a worm??? 
__________________
http://twitter.com/akshayms
|
|
|
20-02-2008, 03:33 PM
|
#7 (permalink)
|
|
Broken In
Join Date: Jan 2006
Posts: 109
|
Re: help cant delete exe file from desktop
yea . thats what google search told me
after that i was able to delete exe files from desktop .
but the same problem has come again
i tried unlocked but its not helping me out
|
|
|
20-02-2008, 07:53 PM
|
#8 (permalink)
|
|
Wise Old Crow
Join Date: Apr 2005
Location: Inside the Pixel
Posts: 1,227
|
Re: help cant delete exe file from desktop
Nvcpl.dll is nVidia control panel file. It is a driver file tht is needed by your OS if you have nVidia based Mobo.
Why and which EXE files are on the desktop?? Did u checked Security permissions on Desktop folder?
Updating your drivers(nVidia) drivers may help.
__________________
http://twitter.com/blueshift155
Last edited by blueshift; 20-02-2008 at 07:53 PM.
Reason: Automerged Doublepost
|
|
|
20-02-2008, 07:59 PM
|
#9 (permalink)
|
|
-----ATi-----
Join Date: May 2007
Location: Bangalore
Posts: 2,322
|
Re: help cant delete exe file from desktop
^^Google it. There are some worms with the same name.. I never knew that before
__________________
http://twitter.com/akshayms
|
|
|
20-02-2008, 08:14 PM
|
#10 (permalink)
|
|
Wise Old Crow
Join Date: Apr 2005
Location: Inside the Pixel
Posts: 1,227
|
Re: help cant delete exe file from desktop
^ I can't find anything that says nvcpl.dll is a worm.
I have nVidia based mobo and there is this file in System32 folder.
Check these lines from his log.
Quote:
C:\WINDOWS\system32\nvsvc32.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
|
So I am assuming he has nVidia based mobo.
If thats not the case, then it is sure a worm.
__________________
http://twitter.com/blueshift155
|
|
|
22-02-2008, 09:24 AM
|
#11 (permalink)
|
|
Broken In
Join Date: Jan 2006
Posts: 109
|
Re: help cant delete exe file from desktop
you are righgt i have a nvidia based mobo
but is my system clean? :s
|
|
|
22-02-2008, 09:45 AM
|
#12 (permalink)
|
|
Alter Bridge=GOD
Join Date: Jun 2006
Location: Deep Inside Of Nowhere
Posts: 1,850
|
Re: help cant delete exe file from desktop
don't u have Kaspersky installed?
is there a threat warning?
__________________
Apple Macbook Pro 17 :cool:
|
|
|
22-02-2008, 12:28 PM
|
#13 (permalink)
|
|
-----ATi-----
Join Date: May 2007
Location: Bangalore
Posts: 2,322
|
Re: help cant delete exe file from desktop
Quote:
Originally Posted by blueshift
^ I can't find anything that says nvcpl.dll is a worm.
|
Check THIS
__________________
http://twitter.com/akshayms
|
|
|
22-02-2008, 01:03 PM
|
#14 (permalink)
|
|
Broken In
Join Date: Jan 2006
Posts: 109
|
Re: help cant delete exe file from desktop
no there is no threat warning :/
|
|
|
22-02-2008, 01:18 PM
|
#15 (permalink)
|
|
Alter Bridge=GOD
Join Date: Jun 2006
Location: Deep Inside Of Nowhere
Posts: 1,850
|
Re: help cant delete exe file from desktop
then why do u want to delete this file? its Nvidia control panel and it can only be uninstalled
__________________
Apple Macbook Pro 17 :cool:
|
|
|
22-02-2008, 07:09 PM
|
#16 (permalink)
|
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
Re: help cant delete exe file from desktop
folks, dont just go by the name of any file. location matters too  so check that also. else rt click on the file to check its properties...
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
|
|
|
22-02-2008, 09:23 PM
|
#17 (permalink)
|
|
In The Zone
Join Date: Oct 2006
Location: Mumbai
Posts: 430
|
Re: help cant delete exe file from desktop
If it's nvidia control panel's file, then it should be located here:
C:\WINDOWS\system32\nvcpl.dll
__________________
The statistics on sanity are that 1 out of every 4 humans is suffering from some form of mental illness:shock:
Think of your 3 best friends. If they are OK, then it's YOU:grin::grin::grin:
|
|
|
23-02-2008, 03:50 PM
|
#18 (permalink)
|
|
Fresh Stock Since 2005
Join Date: Feb 2005
Posts: 1,015
|
Re: help cant delete exe file from desktop
Does not look like a virus. BTW, what exe are you trying to delete?
__________________
http://www.khattam.info
|
|
|
23-02-2008, 05:55 PM
|
#19 (permalink)
|
|
Alter Bridge=GOD
Join Date: Jun 2006
Location: Deep Inside Of Nowhere
Posts: 1,850
|
Re: help cant delete exe file from desktop
if it were a virus kaspersky would have bugged u a lot-its very good at it
still check the file location and if its in system32 then no need to be paranoid
try another antivirus-some 30 day trial one-norton or something just to double check a threat
__________________
Apple Macbook Pro 17 :cool:
Last edited by nish_higher; 23-02-2008 at 06:32 PM.
|
|
|
26-02-2008, 08:40 AM
|
#20 (permalink)
|
|
Wise Old Crow
Join Date: Apr 2005
Location: Inside the Pixel
Posts: 1,227
|
Re: help cant delete exe file from desktop
Quote:
Originally Posted by nvidia
|
Thats nvcpl .exe file dude. Not a dll file. And its location is in System folder.
Quote:
|
Originally Posted by anonymusneo
but is my system clean?
|
It must be.
Is your problem solved?
__________________
http://twitter.com/blueshift155
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|