NCLAUNCH.exe
Page 1 of 3 123 LastLast
Results 1 to 15 of 38

Thread: NCLAUNCH.exe

  1. #1
    Join Date
    Jun 2004
    Posts
    27

    NCLAUNCH.exe

    Can anyone tell me What NCLAUNCH.exe is, What it does, Where it came from and if its bad or good

  2. #2
    Join Date
    Feb 2003
    Location
    Minneapolis, MN USA
    Posts
    3,733
    NCLAUNCH.EXE is a "File launcher used by SWF Studio screensavers on Windows NT, 2000 and XP." Did you download a screensaver recently? NCLaunch can be removed by running the "un-launcher" which you can download from: www.northcode.com/misc/unlauch.exe

  3. #3
    Join Date
    Jun 2004
    Posts
    27

    reply

    Can you tell me anything about it?

    What is does?

    Where it came from?

    Is it bad?

  4. #4
    Join Date
    Jun 2004
    Posts
    27

    northcode

    the link didnt work to get to northcode,

    got another?

  5. #5
    Join Date
    Jun 2004
    Posts
    27

    NCLAUNCH.exe

    HELP!!!

    I ran ad ware and spybot and norton antivirus and also manually deleted NCLAUNCH.exe from my process tree.

    Yet when i restart my computor, nclaunch.exe comes back.

    Also when i run adaware again and and i found that eaccelleration, virtual bouncer, and adDestroyer keep showing up in the registry

    Oh wise ones, any thoughts?

  6. #6
    Join Date
    Oct 2002
    Location
    Here, there and everywhere
    Posts
    7,355
    In Adaware make sure you remove the items in quarintine.

    Download HijackThis and unzip it to its own permanent folder, not directly on the desktop and not directly on the C: drive then run a scan, save the log and copy and paste it into your next reply.

    You can download HijackThis from my sig below.
    Who are you? Introduce yourself here

    P3-450 powered by

    Intel Core 2 Duo E6600
    Gigabyte 965P DQ6
    4 Gig Crucial Ballistix PC6400
    Gainward Nvidia Geforce 7950GT
    2X Western Digital Caviar 320GB SATA2
    Soundblaster X-Fi XtremeMusic
    Samsung SH-D162C DVD Rom
    Lite-On SHM-165P6S DVDRW
    Samsung 20" LCD Syncmaster 206BW
    Thermaltake Kandalf VA9000SWA Tower
    Tagan Dual Engine 700W PSU
    XP PRO SP3/Windows 7 64-bit
    --------------
    Samsung NC10 2GB Ram
    Windows 7 32-bit

  7. #7
    Join Date
    Jun 2004
    Posts
    27

    hijack this

    what is hijack this?

    Is it reputable?

  8. #8
    Join Date
    Jun 2004
    Posts
    27

    virus help

    how can i get rid of nclaunch.exe permantley


    HELLLLLPP!!1

  9. #9
    Join Date
    Oct 2002
    Location
    Here, there and everywhere
    Posts
    7,355
    HijackThis is reputable and a very good program that we use to get solve problem with spyware and malware.

    As i said in my previous post, download and post the log here so we can look and see what you can remove.
    Who are you? Introduce yourself here

    P3-450 powered by

    Intel Core 2 Duo E6600
    Gigabyte 965P DQ6
    4 Gig Crucial Ballistix PC6400
    Gainward Nvidia Geforce 7950GT
    2X Western Digital Caviar 320GB SATA2
    Soundblaster X-Fi XtremeMusic
    Samsung SH-D162C DVD Rom
    Lite-On SHM-165P6S DVDRW
    Samsung 20" LCD Syncmaster 206BW
    Thermaltake Kandalf VA9000SWA Tower
    Tagan Dual Engine 700W PSU
    XP PRO SP3/Windows 7 64-bit
    --------------
    Samsung NC10 2GB Ram
    Windows 7 32-bit

  10. #10
    Join Date
    Jun 2004
    Posts
    27
    okay i did that. will this get rid of northcode's nclaunch?

    is this the post you wanted?

    Logfile of HijackThis v1.97.7
    Scan saved at 6:19:55 PM, on 7/6/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINDOWS\System32\MsgSys.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Winamp\Winampa.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\NavNT\vptray.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\NCLAUNCH.EXe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\cidaemon.exe
    C:\Program Files\Hijack this\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchant.com/sp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchant.com/r=6&s=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
    O1 - Hosts: 69.20.16.183 ieautosearch
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: SuperBar - {519A213F-9ADB-4388-AC8C-7A7076C8C9BF} - (no file)
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
    O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\internetfeatures.exe
    O4 - HKLM\..\Run: [iefeatures] C:\WINDOWS\System32\iefeatures.exe
    O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\version.exe
    O4 - HKLM\..\Run: [pnwsockd] C:\WINDOWS\System32\pnwsockd.exe
    O4 - HKLM\..\Run: [mdskresd] C:\WINDOWS\System32\mdskresd.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBouncer.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &IE Toolbar search - res://C:\Program Files\Internet Explorer\Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: SEARCH_PAGE_URL=
    O14 - IERESET.INF: START_PAGE_URL=
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} (RdxIE Class) - http://www.grokster.com/rdx/RdxIE.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab

  11. #11
    Join Date
    Jun 2004
    Posts
    27
    the link didnt work for northcode. ive gotten it from other help sites and it never works. says page not found

  12. #12
    Join Date
    Apr 2002
    Posts
    1,840
    Press CTRL+ALT+DEL at the same time, in the window that appears, click on Processes. End this one.
    C:\WINDOWS\NCLAUNCH.EXe

    Have all browsers and Windows Explorer closed, and remove these in HJT.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchant.com/sp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchant.com/r=6&s=%s
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about :blank
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 69.20.16.183 ieautosearch
    O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\internetfeatures.exe
    O4 - HKLM\..\Run: [iefeatures] C:\WINDOWS\System32\iefeatures.exe
    O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\version.exe
    O4 - HKLM\..\Run: [pnwsockd] C:\WINDOWS\System32\pnwsockd.exe
    O4 - HKLM\..\Run: [mdskresd] C:\WINDOWS\System32\mdskresd.exe
    O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
    O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBouncer.exe
    O8 - Extra context menu item: &IE Toolbar search - res://C:\Program Files\Internet Explorer\Toolbar\toolbar.dll/SEARCH.HTML
    O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} (RdxIE Class) - http://www.grokster.com/rdx/RdxIE.cab

    Reboot, and delete these files.
    C:\WINDOWS\System32\internetfeatures.exe
    C:\WINDOWS\System32\iefeatures.exe
    C:\WINDOWS\System32\version.exe
    C:\WINDOWS\System32\pnwsockd.exe
    C:\WINDOWS\System32\mdskresd.exe
    C:\WINDOWS\NCLAUNCH.EXe
    Delete these folders.
    C:\Program Files\Internet Explorer\Toolbar
    C:\Program Files\VBouncer
    If you have a problem deleting, install MoveOnBoot. Creates a new item to the right click menu, target a file with it, reboot and the file is deleted.

  13. #13
    Join Date
    Jun 2004
    Posts
    27
    Thanks markp62!!

    A problem: something went wrong with deleting woth hijack this. It couldnt do something. I couldn't find were it was that it saved the log of what it couldnt do. i rebooted, made all (even hidden files) visible, and delelted the files and folders. however files

    O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\internetfeatures.exe
    O4 - HKLM\..\Run: [iefeatures] C:\WINDOWS\System32\iefeatures.exe
    O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\version.exe
    O4 - HKLM\..\Run: [pnwsockd] C:\WINDOWS\System32\pnwsockd.exe
    O4 - HKLM\..\Run: [mdskresd] C:\WINDOWS\System32\mdskresd.exe

    and folder

    C:\Program Files\VBouncer

    all didnt show up to delete. Theres was a version.dll in windows/system32 Do i delete it?

    also norton cant fixed a trojan

    virus name: Download.Trojan
    file name : ~GLH0002.TMP
    location : C:\WINDOWS\

    please continue to save my computor man!

  14. #14
    Join Date
    Jun 2004
    Posts
    27
    this is the new log after all of that

    Logfile of HijackThis v1.97.7
    Scan saved at 6:30:18 PM, on 7/7/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Winamp\Winampa.exe
    C:\Program Files\NavNT\vptray.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\MsgSys.EXE
    C:\Program Files\Hijack this\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: SuperBar - {519A213F-9ADB-4388-AC8C-7A7076C8C9BF} - (no file)
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: SEARCH_PAGE_URL=
    O14 - IERESET.INF: START_PAGE_URL=
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} -
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab

  15. #15
    Join Date
    Apr 2002
    Posts
    1,840
    Do not delete Version.Dll, it is a system file.
    If you used something like Ad-Aware or Spybot, or maybe an AV virus program, those files and folders may have already been deleted by them, but the startups for these files were left behind.
    In any case, remove these.

    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O3 - Toolbar: SuperBar - {519A213F-9ADB-4388-AC8C-7A7076C8C9BF} - (no file)
    O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} -

    If the 01 items can not be removed, this may because you have used Spybot's security features, and are running Teatimer. This will prevent editing of the HOSTS file, as it is marked as Read Only, and HJT cannot remove the 01 items.
    Usually for this file to exist, it must either be user created or something else did.
    You can right click on HOSTS, uncheck Read Only and edit out those three lines with Notepad, if you have any entries there that you may entered yourself.
    If you didn't create it, just delete the file. HOSTS is the complete name, it does not have an extension.

    C:\Windows\System32\Drivers\Etc\HOSTS

    FYI, a HOSTS file is a way to direct or misdirect certain IE traffic to a specific address. It can be a good thing, or a bad thing. You have 3 bad things in it. When you do a search from the address bar in IE or Netscape, you are misdirected to somebody renting a server from a company named RackShack.Com in San Antonio.
    Last edited by markp62; July 8th, 2004 at 10:23 PM.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •