While trying to delete, rename, move, or copy and paste a file I get the message:
Cannot delete file: Cannot read from the source file or disk.
While trying to use a program called Mboot (which can move or delete, move, etc files that don't start up when booting, I was informed the "File either does not exist or is locked."
I cannot copy the file, while pasting I get the same message when trying to delete it.
This (see screenshot below) is the file and its location (I changed it to a WMP file as many other types but notice it isn't recognized as such).
This file behaves the same way in both locations, the "shortcut" on my desktop (shown below) and in C:Documents and SettingsXaminorDesktop.
(Click to View Screenshot)[http://img.photobucket.com/albums/v160/Xaminor/Website%20Screens/badfile.jpg][/b]
Here is a start up log using Silent Runners.
"Silent Runners.vbs", revision 39, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by `"{++}"`
Startup items buried in registry:
---------------------------------
HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"LDM" = "Program" [file not found]
"RemoteCenter" = "C:Program FilesCreativeMediaSourceRemoteControlRcMan.exe" ["Creative Technology Ltd"]
"seticlient" = "C:Program FilesSETI@homeSETI@home.exe -min" ["University of California, Berkeley"]
"NBJ" = ""C:Program FilesAheadNero BackItUpNBJ.exe"" ["Ahead Software AG"]
"Yahoo! Pager" = "C:Program FilesYahoo!Messengerypager.exe -quiet" ["Yahoo! Inc."]
"ctfmon.exe" = "C:WINDOWSsystem32ctfmon.exe" [MS]
"RemoteControl" = (empty string)
"Creative Detector" = "C:Program FilesCreativeMediaSourceDetectorCTDetect.exe /R" ["Creative Technology Ltd"]
"MtdAcq" = "C:Program FilesCreativeShared FilesMedia SnifferMtdAcq.EXE /s" ["Creative Technology Ltd"]
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun {++}
"Logitech Utility" = "Logi_MwX.Exe" ["Logitech Inc."]
"CTHelper" = "CTHELPER.EXE" ["Creative Technology Ltd"]
"SBDrvDet" = "C:Program FilesCreativeSB Drive DetSBDrvDet.exe /r" ["Creative Technology Ltd"]
"UpdReg" = "C:WINDOWSUpdReg.EXE" ["Creative Technology Ltd."]
"ADUserMon" = "C:Program FilesIomegaAutoDiskADUserMon.exe" ["Iomega Corporation"]
"Iomega Drive Icons" = "C:Program FilesIomegaDriveIconsImgIcon.exe" ["Iomega"]
"Deskup" = "C:Program FilesIomegaDriveIconsdeskup.exe /IMGSTART" ["Iomega"]
"SunJavaUpdateSched" = "C:Program FilesJavajre1.5.0_02binjusched.exe" ["Sun Microsystems, Inc."]
"AVG7_CC" = "C:PROGRA~1GrisoftAVGFRE~1avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"AVG7_EMC" = "C:PROGRA~1GrisoftAVGFRE~1avgemc.exe" ["GRISOFT, s.r.o."]
"TkBellExe" = ""C:Program FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot" ["RealNetworks, Inc."]
"QuickTime Task" = ""C:Program FilesQuickTimeqttask.exe" -atboottime" ["Apple Computer, Inc."]
"NeroFilterCheck" = "C:WINDOWSsystem32NeroCheck.exe" ["Ahead Software Gmbh"]
"RemoteCenter" = (empty string)
"Zone Labs Client" = "C:Program FilesZone LabsZoneAlarmzlclient.exe" ["Zone Labs, LLC"]
"NvCplDaemon" = "RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"NvMediaCenter" = "RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit" [MS]
"DAEMON Tools-1033" = ""C:Program FilesD-Toolsdaemon.exe" -lang 1033" ["DAEMON'S HOME"]
HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects
{02478D38-C3F9-4efb-9B51-7695ECA05670}(Default) = "Yahoo! Companion BHO" [from CLSID]
-> {CLSID}InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0ycomp5_5_7_0.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}InProcServer32(Default) = "C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}(Default) = (no title provided)
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1SPYBOT~1SDHelper.dll" ["Safer Networking Limited"]
HKLMSoftwareMicrosoftWindowsCurrentVersionShell ExtensionsApproved
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}InProcServer32(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSSystem32hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32Audiodev.dll" [MS]
"{c7745760-8ead-11ce-b750-02608ca5202c}" = "IomegaWare Shell Extension"
-> {CLSID}InProcServer32(Default) = "C:Program FilesIomegaShellImgMenu.dll" ["Iomega Corp."]
"{c7745761-8ead-11ce-b750-02608ca5202c}" = "IomegaWare Shell Extension"
-> {CLSID}InProcServer32(Default) = "C:Program FilesIomegaShellImgProp.dll" ["Iomega Corp."]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {CLSID}InProcServer32(Default) = "C:Program FilesGrisoftAVG Freeavgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {CLSID}InProcServer32(Default) = "C:Program FilesGrisoftAVG Freeavgse.dll" ["GRISOFT, s.r.o."]
"{32020A01-506E-484D-A2A8-BE3CF17601C3}" = "AlcoholShellEx"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1ALCOHO~1ALCOHO~1AXShlEx.dll" ["Alcohol Soft Development Team"]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1MICROS~2OFFICE11MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1MICROS~2OFFICE11OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}InProcServer32(Default) = "C:Program FilesMicrosoft OfficeOFFICE11msohev.dll" [MS]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}InProcServer32(Default) = "C:Program FilesRealRealPlayerrpshell.dll" ["RealNetworks, Inc."]
"{08267B21-223F-11d3-ACD4-004F4902B913}" = "Desktop Architect"
-> {CLSID}InProcServer32(Default) = "C:Program FilesDesktop Architectdadesk.dll" ["Ken Foster"]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]
"{19F500E0-9964-11cf-B63D-08002B317C03}" = "Desktop Icon Layout"
-> {CLSID}InProcServer32(Default) = "Layout.dll" [file not found]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32nvcpl.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> {CLSID}InProcServer32(Default) = "C:WINDOWSsystem32nvshell.dll" ["NVIDIA Corporation"]
HKLMSystemCurrentControlSetControlSession Manager
INFECTION WARNING! "BootExecute" = "autocheck autochk * OODBS" [file not found], [MS], [file not found], ["O&O Software GmbH"]
HKLMSoftwareClassesPROTOCOLSFilter
INFECTION WARNING! text/xmlCLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesCommon FilesMicrosoft SharedOFFICE11MSOXMLMF.DLL" [MS]
HKLMSoftwareClasses*shellexContextMenuHandlers
AVG7 Shell Extension(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesGrisoftAVG Freeavgse.dll" ["GRISOFT, s.r.o."]
HESHELL(Default) = "{F3E65D01-A4B0-4899-985A-CEBA145D2887}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesHacker EliminatorHESHELL.dll" [file not found]
IMMenuShellExt(Default) = "{F8984111-38B6-11D5-8725-0050DA2761C4}"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1INCRED~1binImShExt.dll" ["IncrediMail, Ltd."]
moveonboot_delete(Default) = "{12B23346-6BD8-4812-BF8C-75E7C386ACB8}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesGiPo@UtilitiesGiPo@MoveOnBootmboot.dll" ["Gibin Software House ([url="http://www.gibinsoft.net/"]http://www.gibinsoft.net[/url])"]
TheCleaner(Default) = "{2DE506B9-4320-11d3-8E42-002035221EDA}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesThe Cleanertcshellex.dll" ["MooSoft Development"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
Yahoo! Mail(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1Yahoo!Commonymmapi.dll" ["Yahoo! Inc."]
HKLMSoftwareClassesDirectoryshellexContextMenuHandlers
TheCleaner(Default) = "{2DE506B9-4320-11D3-8E42-002035221EDA}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesThe Cleanertcshellex.dll" ["MooSoft Development"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
HKLMSoftwareClassesFoldershellexContextMenuHandlers
AVG7 Shell Extension(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesGrisoftAVG Freeavgse.dll" ["GRISOFT, s.r.o."]
HESHELL(Default) = "{F3E65D01-A4B0-4899-985A-CEBA145D2887}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesHacker EliminatorHESHELL.dll" [file not found]
IconLayout(Default) = "{19F500E0-9964-11cf-B63D-08002B317C03}"
-> {CLSID}InProcServer32(Default) = "Layout.dll" [file not found]
TheCleaner(Default) = "{2DE506B9-4320-11D3-8E42-002035221EDA}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesThe Cleanertcshellex.dll" ["MooSoft Development"]
WinRAR(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesWinRARrarext.dll" [null data]
WinZip(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}InProcServer32(Default) = "C:PROGRA~1WINZIPWZSHLSTB.DLL" ["WinZip Computing, Inc."]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is disabled at this entry:
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShellState
HKCUControl PanelDesktop
"Wallpaper" = "C:Documents and SettingsXaminorApplication DataMicrosoftInternet ExplorerInternet Explorer Wallpaper.bmp"
Enabled Screen Saver:
---------------------
HKCUControl PanelDesktop
"SCRNSAVE.EXE" = "C:WINDOWSSystem32ssflwbox.scr" [MS]
Startup items in "Xaminor" & "All Users" startup folders:
---------------------------------------------------------
C:Documents and SettingsXaminorStart MenuProgramsStartup
"Clipboard Genie" -> shortcut to: "C:Program FilesClipboard GenieClipG.exe" [file not found]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersNameSpace_Catalog5Catalog_Entries {++}
000000000001LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
000000000002LibraryPath = "%SystemRoot%System32winrnr.dll" [MS]
000000000003LibraryPath = "%SystemRoot%System32mswsock.dll" [MS]
Transport Service Providers
HKLMSystemCurrentControlSetServicesWinsock2ParametersProtocol_Catalog9Catalog_Entries {++}
0000000000##PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%system32mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%system32rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Companion" [from CLSID]
-> {CLSID}InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0ycomp5_5_7_0.dll" ["Yahoo! Inc."]
HKLMSoftwareMicrosoftInternet ExplorerToolbar
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Companion" [from CLSID]
-> {CLSID}InProcServer32(Default) = "C:Program FilesYahoo!CompanionInstallscpn0ycomp5_5_7_0.dll" ["Yahoo! Inc."]
Explorer Bars
Dormant Explorer Bars in "View, Explorer Bar" menu
HKLMSoftwareClassesCLSID{FF059E31-CC5A-4E2E-BF3B-96E929D65503} = "&Research"
Implemented Categories{00021493-0000-0000-C000-000000000046} [vertical bar]
InProcServer32(Default) = "C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLMSoftwareMicrosoftInternet ExplorerExtensions
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}"
-> {CLSID}InProcServer32(Default) = "C:Program FilesJavajre1.5.0_02binnpjpi150_02.dll" ["Sun Microsystems, Inc."]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}
"ButtonText" = "Research"
{FB5F1910-F110-11D2-BB9E-00C04F795683}
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:Program FilesMessengermsmsgs.exe" [file not found]
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
AVG7 Alert Manager Server, Avg7Alrt, "C:PROGRA~1GrisoftAVGFRE~1avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:PROGRA~1GrisoftAVGFRE~1avgupsvc.exe" ["GRISOFT, s.r.o."]
Creative Service for CDROM Access, Creative Service for CDROM Access, "C:WINDOWSsystem32CTSvcCDA.EXE" ["Creative Technology Ltd"]
Iomega Active Disk, _IOMEGA_ACTIVE_DISK_SERVICE_, ""C:Program FilesIomegaAutoDiskADService.exe"" ["Iomega Corporation"]
Iomega App Services, Iomega App Services, ""C:PROGRA~1IomegaSystem32AppServices.exe"" ["Iomega Corporation"]
Machine Debug Manager, MDM, ""C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE"" [MS]
NVIDIA Display Driver Service, NVSvc, "C:WINDOWSsystem32nvsvc32.exe" ["NVIDIA Corporation"]
O&O Defrag, O&O Defrag, "C:WINDOWSsystem32oodag.exe" ["O&O Software GmbH"]
SoundMAX Agent Service, SoundMAX Agent Service (default), "C:Program FilesAnalog DevicesSoundMAXSMAgent.exe" ["Analog Devices, Inc."]
TrueVector Internet Monitor, vsmon, "C:WINDOWSsystem32ZoneLabsvsmon.exe -service" ["Zone Labs, LLC"]
Windows Service Pack Installer update service, spupdsvc, "C:WINDOWSsystem32spupdsvc.exe" [MS]
Windows User Mode Driver Framework, UMWdf, "C:WINDOWSsystem32wdfmgr.exe" [MS]
WMDM PMSP Service, WMDM PMSP Service, "C:WINDOWSsystem32MsPMSPSv.exe" [MS]
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 20 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 12 seconds.
---------- (total run time: 58 seconds)