NvCpl.dll worm xp

Anonymous
2011-12-03T00:25:26+00:00

I have a slow running XP machine.  While troubleshooting, I remove all startup items with msconfig by the disable all button and restarted the machine.

Upon a msconfig a checked MvCpl.dll command line was there.  The original on was also there uncheck.  I searched my C-drive for NvCpl.* and received:

   NvCpl     C:\Windows\Help  Help File

  NvCpl.dll  C:\Windows\System32 

  NvCpl       C:\Dell\Drivers\R65699 Help File

  NvCpl.dll   C:\Dell\Drivers\R65699

  NvCpl       C:\Dell\Drivers\R89437   DL_File

  NvCpl        C:\Dell\Drivers\R89437   HL_File

Bounced around on the internet and learned that a rwiz.exe seem to belong to this worm.  It is also in my msconfig startup page.

Any help with removing this Worm would be appreciated.

Avalonfv

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2012-01-05T03:06:41+00:00

I just re-read the entire thread. I was struck by two things:

  1. This PC was once on a domain.
  2. This PC had trojans.

I am aware you reconfigured the PC to change it from Domain to Workgroup, but there still might be something in the profile that is searching for something on the domain. I suppose you could create a fresh profile, but I'm not sure I'd waste my time since...

I believe the PC is still compromised. Malware can sometimes be VERY tricky to remove. Sometimes it might APPEAR to be gone, but there will still be a nasty, almost-impossible-to-detect rootkit present (or maybe even a "bootkit" hiding out in the boot sector). The symptoms you describe certainly indicate the presence of malware; the PC might very well be a part of the "botnet" right now.

I recommend that you make sure all the data is backed up and nuke the drive and start from scratch. It's a hassle, but it would probably still be the quickest (and surely be the most effective) way to deal with this mess.

If you had unlimited time and wished to experiment and explore (but I believe you said this PC belongs to a friend), you could search the web for Process Explorer tutorials and start a thread on Bleeping Computer or a similar site to get guided help. But I truly think you'll be better off if you flatten and rebuild.

Good luck and Happy New Year!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

42 additional answers

Sort by: Newest
  1. Anonymous
    2011-12-18T05:12:26+00:00

    Daavee,

    The Clean Boot is for Normal Mode. That's the only way you can tell which process is messing you up.

    I booted the machine using a clean boot configuration (only XP services running and no startup items checked).  It took 10min for CPU useage to drop to 20%. CPU usage stayed around 20% only for two minutes then Useage back to 100% with MsMpEng was the largest hog.

    This pattern has continued for 45 minutes or so with varying time slices on 100% the drop to even 4%

    I have a word picture that I could email you to illustrate what I am trying to say.

    I don't know if we can attach into this forum.

    I will wait for word from you.  Remember this is happening with just Windows.

    Avalonfv

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2011-12-17T21:47:10+00:00

    If your system is idle, you want the figure for System Idle Process to be as close to 100 as possible. The other processes are important to know, though.

    The Clean Boot is for Normal Mode. That's the only way you can tell which process is messing you up.

    Some systems have a problem with Automatic Updates set to use Microsoft Update (but Windows Update is okay). For starters, go into Control Panel and double-click Automatic Updates. TEMPORARILY turn off automatic updates and reboot.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2011-12-17T18:37:58+00:00

    Daavee,

    To catch up

    My intent was to see what changed. That list was posted before you removed Windows Search 4.0. I was curious to know what the hogs were AFTER the change.

    Svchost

    nwiz

    MsMpEng

    csrss

    Wuauclt

    System idle process (this doesn't count correct?)

    Does Safe Mode get rid of the high CPU usage? If so, configure a Clean Boot and systematically add back processes until the problem reappears:

    The CPU usage is better under Safe Mode after configuring a clean boot including step 4

    I must start up processes one at a time in the Safe Mode? 

    Still in the process of in safe mode putting in one start up process at a time.  Have a good weekend, Daavee

    Avalonfv

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2011-12-16T15:54:05+00:00

    You may have missed in a previous post

     

    Go back to the Processes tab of Task Manager and sort by CPU cycles in descending order. tell us which processes are the CPU hogs.

    The big ones are:

    cisve.exe This can take >85%

    Exporer.exe This one can take >80%

    MsMpeng.exe This one can take >90%

    searchprotocallhost.exe

    searchfilterhost.exe

    csrss.exe

    Wltry.exe

    My intent was to see what changed. That list was posted before you removed Windows Search 4.0. I was curious to know what the hogs were AFTER the change.

    Was this answer helpful?

    0 comments No comments