Author Topic: Help me! rdriv is driving me nuts!  (Read 2194 times)

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« on: November 06, 2005, 11:56:26 PM »
Logfile of HijackThis v1.99.1
Scan saved at 10:55:58 PM, on 11/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
H:\WINDOWS\dbg32hlp.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
H:\WINDOWS\System32\hkcmd.exe
H:\WINDOWS\BCMSMMSG.exe
H:\Program Files\Common Files\Symantec Shared\ccApp.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
H:\Program Files\HP\hpcoretech\hpcmpmgr.exe
H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
H:\Program Files\Messenger\msmsgs.exe
H:\Program Files\AIM\aim.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
H:\DOCUME~1\MEGANR~1\LOCALS~1\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] H:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] H:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "H:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] H:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "H:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "H:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "H:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] H:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = H:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - H:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'h:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125935343498
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1125958987187
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - Unknown owner - H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoctrl.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Msdebugsrv1 (Msdebugsrv) - Unknown owner - H:\WINDOWS\dbg32hlp.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - H:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Help me! rdriv is driving me nuts!
« Reply #1 on: November 07, 2005, 12:07:52 AM »
Can you redownload hijackthis from my signature below and save it too a permanent folder on your harddrive
Only run hijackthis from this new location

Can I see a startup log from Hijackthis please
Open Hijackthis
Open Misc tools section
Put a check in the following

List all minor sections (full)
and
List empty sections (complete)


Then afterwards click the "Generate startup listlog"

A text file will open
Can you copy and paste the whole contents back here please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #2 on: November 07, 2005, 12:15:23 AM »
StartupList report, 11/6/2005, 11:14:09 PM
StartupList version: 1.52.2
Started from : H:\hijackthis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
H:\WINDOWS\dbg32hlp.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
H:\WINDOWS\System32\hkcmd.exe
H:\WINDOWS\BCMSMMSG.exe
H:\Program Files\Common Files\Symantec Shared\ccApp.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
H:\Program Files\HP\hpcoretech\hpcmpmgr.exe
H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
H:\Program Files\Messenger\msmsgs.exe
H:\Program Files\AIM\aim.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\hijackthis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[H:\Documents and Settings\Megan Rose\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[H:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Microsoft Office.lnk = H:\Program Files\Microsoft Office\Office10\OSA.EXE

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = H:\WINDOWS\System32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IgfxTray = H:\WINDOWS\System32\igfxtray.exe
HotKeysCmds = H:\WINDOWS\System32\hkcmd.exe
BCMSMMSG = BCMSMMSG.exe
ccApp = "H:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Norton Ghost 9.0 = H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
Symantec NetDriver Monitor = H:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
HPDJ Taskbar Utility = H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
HP Software Update = "H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
HP Component Manager = "H:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
DeviceDiscovery = H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
QuickTime Task = "H:\Program Files\QuickTime\qttask.exe" -atboottime
SunJavaUpdateSched = H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Norton SystemWorks = "H:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
MSMSGS = "H:\Program Files\Messenger\msmsgs.exe" /background
AIM = H:\Program Files\AIM\aim.exe -cnetwait.odl

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = H:\WINDOWS\System32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = H:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection H:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection H:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection H:\WINDOWS\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = H:\WINDOWS\System32\Rundll32.exe H:\WINDOWS\System32\mscories.dll,Install

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from H:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from H:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=H:\WINDOWS\System32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

H:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
H:\WINDOWS\Explorer\Explorer.exe: not present
H:\WINDOWS\System\Explorer.exe: not present
H:\WINDOWS\System32\Explorer.exe: not present
H:\WINDOWS\Command\Explorer.exe: not present
H:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in H:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - H:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Norton AntiVirus - Scan my computer - Megan Rose.job
Norton SystemWorks One Button Checkup.job
Symantec Drmc.job
Symantec NetDetect.job

--------------------------------------------------

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = H:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[Shockwave ActiveX Control]
InProcServer32 = H:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa...director/sw.cab

[WUWebControl Class]
InProcServer32 = H:\WINDOWS\System32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/...b?1125935343498

[MUWebControl Class]
InProcServer32 = H:\WINDOWS\System32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat...b?1125958987187

[Java Plug-in 1.5.0_04]
InProcServer32 = H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[ZoneIntro Class]
InProcServer32 = H:\WINDOWS\Downloaded Program Files\ZIntro.ocx
CODEBASE = http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab

[Java Plug-in 1.5.0_04]
InProcServer32 = H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[Facebook Photo Uploader Control]
InProcServer32 = H:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.ocx
CODEBASE = http://upload.facebook.com/controls/Facebo...otoUploader.cab

[Shockwave Flash Object]
InProcServer32 = H:\WINDOWS\system32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab

[PopCapLoader Object]
InProcServer32 = H:\WINDOWS\Downloaded Program Files\popcaploader.dll
CODEBASE = http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: H:\WINDOWS\System32\mswsock.dll
NameSpace #2: H:\WINDOWS\System32\winrnr.dll
NameSpace #3: H:\WINDOWS\System32\mswsock.dll
NameSpace #4: H:\Program Files\Bonjour\mdnsNSP.dll (file MISSING)
Protocol #1: H:\WINDOWS\system32\mswsock.dll
Protocol #2: H:\WINDOWS\system32\mswsock.dll
Protocol #3: H:\WINDOWS\system32\mswsock.dll
Protocol #4: H:\WINDOWS\system32\rsvpsp.dll
Protocol #5: H:\WINDOWS\system32\rsvpsp.dll
Protocol #6: H:\WINDOWS\system32\mswsock.dll
Protocol #7: H:\WINDOWS\system32\mswsock.dll
Protocol #8: H:\WINDOWS\system32\mswsock.dll
Protocol #9: H:\WINDOWS\system32\mswsock.dll
Protocol #10: H:\WINDOWS\system32\mswsock.dll
Protocol #11: H:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
aeaudio: system32\drivers\aeaudio.sys (manual start)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
Broadcom 440x 10/100 Integrated Controller XP Driver: System32\DRIVERS\bcm4sbxp.sys (manual start)
BCM V.92 56K Modem: System32\DRIVERS\BCMSM.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Symantec Event Manager: "H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" (autostart)
Symantec Password Validation: "H:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" (manual start)
Symantec Settings Manager: "H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" (autostart)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: H:\WINDOWS\System32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
COM+ System Application: H:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sys (system)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: H:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
ewido security suite control: H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoctrl.exe (autostart)
ewido security suite driver: \??\H:\Documents and Settings\Megan Rose\Desktop\security suite\guard.sys (system)
ewido security suite guard: H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoguard.exe (disabled)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\drivers\fltmgr.sys (system)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
ialm: System32\DRIVERS\ialmnt5.sys (manual start)
InstallDriver Table Manager: "H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
IMAPI CD-Burning COM Service: H:\WINDOWS\System32\imapi.exe (manual start)
Intel Processor Driver: System32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\drivers\ip6fw.sys (manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Msdebugsrv1: "H:\WINDOWS\dbg32hlp.exe" (autostart)
Distributed Transaction Coordinator: H:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: H:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: System32\DRIVERS\mssmbios.sys (manual start)
Norton AntiVirus Auto-Protect Service: "H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe" (autostart)
NAVENG: \??\H:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20051102.019\NAVENG.Sys (manual start)
NAVEX15: \??\H:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20051102.019\NavEx15.Sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Norton Ghost: H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe (autostart)
Norton Unerase Protection Driver: \??\H:\WINDOWS\System32\Drivers\NPDRIVER.SYS (manual start)
Norton AntiVirus Firewall Monitor Service: H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe (autostart)
Norton Unerase Protection: H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE (autostart)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
PCIIde: System32\DRIVERS\pciide.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: H:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SAVRT: \??\H:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVRT.SYS (manual start)
SAVRTPEL: \??\H:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVRTPEL.SYS (system)
SAVScan: H:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe (manual start)
ScriptBlocking Service: H:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SDdriver: \??\H:\WINDOWS\System32\Drivers\sddriver.sys (manual start)
Secdrv: System32\DRIVERS\secdrv.sys (manual start)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
smwdm: system32\drivers\smwdm.sys (manual start)
Symantec Network Drivers Service: H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (autostart)
SPBBCDrv: \??\H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (system)
Symantec SPBBCSvc: H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (autostart)
Speed Disk service: H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: System32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: H:\WINDOWS\System32\dllhost.exe /Processid:{EE3C9EDE-213D-4B26-826B-66904D6265E8} (manual start)
Symantec Core LC: H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (autostart)
SYMDNS: \SystemRoot\System32\Drivers\SYMDNS.SYS (manual start)
SymEvent: \??\H:\Program Files\Symantec\SYMEVENT.SYS (manual start)
SYMFW: \SystemRoot\System32\Drivers\SYMFW.SYS (manual start)
SYMIDS: \SystemRoot\System32\Drivers\SYMIDS.SYS (manual start)
SYMIDSCO: \??\H:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20050901.036\symidsco.sys (manual start)
symlcbrd: \??\H:\WINDOWS\System32\drivers\symlcbrd.sys (autostart)
SYMNDIS: \SystemRoot\System32\Drivers\SYMNDIS.SYS (manual start)
SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start)
SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Telnet: H:\WINDOWS\System32\tlntsvr.exe (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: System32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
VGA Display Controller.: \SystemRoot\System32\drivers\vga.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: H:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Intel® Graphics Platform (SoftBIOS) Driver: system32\drivers\ialmsbw.sys (manual start)
Intel® Graphics Chipset (KCH) Driver: system32\drivers\ialmkchw.sys (manual start)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: H:\WINDOWS\system32\SHELL32.dll
CDBurn: H:\WINDOWS\system32\SHELL32.dll
WebCheck: H:\WINDOWS\System32\webcheck.dll
SysTray: H:\WINDOWS\System32\stobject.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

End of report, 35,503 bytes
Report generated in 0.157 seconds

Command line options:
   /verbose  - to add additional info on each section
   /complete - to include empty sections and unsuspicious data
   /full     - to include several rarely-important sections
   /force9x  - to include Win9x-only startups even if running on WinNT
   /forcent  - to include WinNT-only startups even if running on Win9x
   /forceall - to include all Win9x and WinNT startups, regardless of platform
   /history  - to list version history only

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Help me! rdriv is driving me nuts!
« Reply #3 on: November 07, 2005, 12:43:40 AM »
Did you uninstall Ewido?

We may need it again

Can you do the following
To your H:Drive
Download and save rdrivrem.zip
UNZIP the contents to your desktop

==Download and then Install
Ewido Security Suite

When installing, under "Additional Options" Uncheck "Install background guard" and "Install scan via context menu".

From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link after you have Ewido installed
http://www.ewido.net/en/download/updates/

==Download and Install this small program
to help clean your temp folders,cookies, etc...
Windows Cleanup! 4.0
Don't run it yet

Please  save these instructions to a Notepad file and save it to your Desktop for reference
RESTART your Computer in SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads, or use the link I supplied for a more detailed explanation

Go to START>>RUN>>Copy and paste the next line in bold to the open field then hit OK

sc stop Msdebugsrv

Do the same thing for this one

sc delete Msdebugsrv

Find and delete this file
H:\WINDOWS\dbg32hlp.exe <-this file

Go into the rdrivrem folder and double-click rdrivRem.bat to run the program - follow the instructions on the screen. After it's complete, rdriv.txt will be created in the rdrivRem folder
I'll want to see this later

==Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):

    * Empty Recycle Bins
    * Delete Cookies
    * Delete Prefetch files
    * Cleanup! All Users

Click OK
Press the CleanUp! button to start the program.
When it's done, decline to log off or restart the computer

==Open Ewido Security Suite
Click on the Scanner button on the left menu
Select Complete System Scan
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
  *1. Perform Action = Remove
  *2. Create Encrypted Backup in Quarantine (Recommended)
  *3. Perform action with all infections
  Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido

Reboot back to Normal mode
I need to see a few logs
1. Run hijackthis again and post a fresh log
2. Post the whole report from Ewido's
3. Post the rdriv.txt in the rdrivRem folder

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Guest

  • Guest
Help me! rdriv is driving me nuts!
« Reply #4 on: November 07, 2005, 10:45:41 AM »
---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         9:41:21 AM, 11/7/2005
 + Report-Checksum:      1B4278FF

 + Scan result:

   C:\System Volume Information\_restore{410D8E36-B84C-4FCB-BB58-76F16090C936}\RP2\A0000053.exe -> Backdoor.Rbot : Cleaned with backup


::Report End





      ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~


      ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~



      ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~


      ~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~

rdriv.sys present!


      ~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~

Guest

  • Guest
Help me! rdriv is driving me nuts!
« Reply #5 on: November 07, 2005, 10:47:22 AM »
Logfile of HijackThis v1.99.1
Scan saved at 9:46:42 AM, on 11/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoctrl.exe
H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoguard.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\System32\hkcmd.exe
H:\WINDOWS\BCMSMMSG.exe
H:\Program Files\Common Files\Symantec Shared\ccApp.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
H:\Program Files\HP\hpcoretech\hpcmpmgr.exe
H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
H:\Program Files\Messenger\msmsgs.exe
H:\Program Files\AIM\aim.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\WINDOWS\system32\wuauclt.exe
H:\DOCUME~1\MEGANR~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] H:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] H:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "H:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] H:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "H:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "H:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "H:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] H:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = H:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - H:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'h:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125935343498
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1125958987187
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - H:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #6 on: November 07, 2005, 10:49:58 AM »
It said there were no files named H:\WINDOWS\dbg32hlp.exe
so???

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #7 on: November 07, 2005, 05:03:04 PM »
help???? anyone?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Help me! rdriv is driving me nuts!
« Reply #8 on: November 07, 2005, 08:51:11 PM »
Quote
It said there were no files named H:\WINDOWS\dbg32hlp.exe
Not sure what you meant by this???

I wanted you to manually look for this file and delete it

Double click MyComputer>>Open Your H:\Drive
Open WINDOWS folder
Find and remove dbg32hlp.exe

From my signature below
Can you run an online virus scan at PANDA's please
Select to scan "MyComputer"
When the scan is done, Save a report and post it back here

You may want to disable Norton's before running the scan

I meant to say select to scan "Local Disks"
When scanning at Panda's, but if you already started, the MyComputer option will work
« Last Edit: November 07, 2005, 11:24:15 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #9 on: November 07, 2005, 10:54:39 PM »
I did manually look for it and couldn't find it so i searched for it and there are no files by that name

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #10 on: November 08, 2005, 01:05:51 AM »
Panda is running. So do you still not understand what i meant? I went and looked in H:\Windows and didn't find anything called dbg32hlp.exe. So i searched for it and it wasn't anywhere...

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #11 on: November 08, 2005, 01:34:36 AM »
Incident                      Status                        Location                                                                                                                                                                                                                                                        

Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\CMEII\GAppMgr.dll                                                                                                                                                                                                                
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\CMEII\GMTProxy.dll                                                                                                                                                                                                                
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\CMEII\GObjs.dll                                                                                                                                                                                                                  
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\CMEII\Gtools.dll                                                                                                                                                                                                                  
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\GMT\EGGCEngine.dll                                                                                                                                                                                                                
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\GMT\egIEEngine.dll                                                                                                                                                                                                                
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\GMT\EGIEProcess.dll                                                                                                                                                                                                              
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\GMT\EGNSEngine.dll                                                                                                                                                                                                                
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\GMT\GatorStubSetup.exe                                                                                                                                                                                                            
Adware:Adware/Gator           No disinfected                C:\Program Files\Common Files\GMT\GUninstaller.exe                                                                                                                                                                                                              
Adware:Adware/WinTools        No disinfected                C:\Program Files\Common Files\WinTools\WToolsS.exe                                                                                                                                                                                                              
Adware:Adware/SaveNow         No disinfected                C:\Program Files\Save\Save.exe                                                                                                                                                                                                                                  
Virus:Bck/Wisdoor.gen         Disinfected                   C:\System Volume Information\_restore{410D8E36-B84C-4FCB-BB58-76F16090C936}\RP2\A0000293.exe                                                                                                                                                                    
Virus:Bck/Wisdoor.gen         Disinfected                   C:\System Volume Information\_restore{410D8E36-B84C-4FCB-BB58-76F16090C936}\RP2\A0000297.exe                                                                                                                                                                    
Spyware:Spyware/New.net       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP154\A0019377.exe                                                                                                                                                                  
Adware:Adware/IPInsight       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP200\A0020562.inf                                                                                                                                                                  
Adware:Adware/IPInsight       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP203\A0020648.inf                                                                                                                                                                  
Adware:Adware/IPInsight       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP207\A0020750.inf                                                                                                                                                                  
Adware:Adware/IPInsight       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP208\A0020764.inf                                                                                                                                                                  
Virus:Trojan Horse            Disinfected                   C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP212\A0020793.exe                                                                                                                                                                  
Adware:Adware/Opensite        No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP215\A0020892.exe                                                                                                                                                                  
Adware:Adware/WinTools        No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP218\A0020942.dll                                                                                                                                                                  
Adware:Adware/IPInsight       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP222\A0021416.inf                                                                                                                                                                  
Adware:Adware/IPInsight       No disinfected                C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP222\A0021425.inf                                                                                                                                                                  
Virus:Bck/Wisdoor.gen         Disinfected                   H:\RECYCLER\S-1-5-21-1343024091-1303643608-839522115-1003\Dh24.bak

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Help me! rdriv is driving me nuts!
« Reply #12 on: November 08, 2005, 01:39:14 AM »
Can you redownload Hijackthis from my signature below
Save it too a permanent folder on your harddrive
ONLY run hijackthis from this new location

Open Hijackthis>>Open Misc tools section>>Open Uninstall manager
Click the SAVE LIST button
Save this list to desktop and then copy and paste the whole contents back here please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #13 on: November 08, 2005, 01:55:25 AM »
Ad-Aware SE Personal
Adobe Reader 6.0.1
AOL Instant Messenger
Application name
BCM V.92 56K Modem
ccCommon
CCleaner (remove only)
CleanUp!
ewido security suite
HijackThis 1.99.1
hp deskjet 3600
HP Memories Disc
HP Photo and Imaging 2.0 - Deskjet Series
hp print screen utility
Intel® Extreme Graphics Driver
Internet Worm Protection
J2SE Runtime Environment 5.0 Update 4
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Office XP Media Content
Microsoft Office XP Professional
MSRedist
Norton AntiVirus 2005
Norton AntiVirus Parent MSI
Norton Ghost 9.0
Norton SystemWorks
Norton SystemWorks 2005 Premier (Symantec Corporation)
Norton Utilities
Norton WMI Update
NSW_DRM_COLLECTION
Panda ActiveScan
QuickTime
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
SPBBC
Spybot - Search & Destroy 1.4
Symantec Script Blocking Installer
SymNet
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Viewpoint Media Player
Winamp (remove only)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Service Pack 2

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Help me! rdriv is driving me nuts!
« Reply #14 on: November 08, 2005, 02:11:23 AM »
Can you look for these folders and delete them
May have to be done in safe mode

Also,
Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

C:\Program Files\Common Files\CMEII <-this folder
C:\Program Files\Common Files\GMT <-folder
C:\Program Files\Common Files\WinTools <-folder
C:\Program Files\Save <-folder

Can you run one more scan please
Download the trial version of Spy Sweeper from HERE
Click on the Free trial link

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Under What to Sweep, check every box.

(It's best to close all open windows before running this scan, including this window)

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

If  prompted , allow Spy Sweeper to restart your computer

Back in Windows

Copy and paste the SpySweeper log together with a fresh hijackthis log into this thread.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Help me! rdriv is driving me nuts!
« Reply #15 on: November 08, 2005, 02:22:54 AM »
I just noticed that Panda's found the earlier bad folders in the C:Folder

But your running on the H: Drive
Do you have another copy of XP on your C: drive?
Or what's running on your C?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #16 on: November 08, 2005, 11:07:42 AM »
I have XP also on my C drive. H was my backup but for some reason i made C my backup.

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #17 on: November 08, 2005, 11:10:01 AM »
9:31 AM: |       Start of Session, Tuesday, November 08, 2005       |
9:31 AM: Spy Sweeper started
9:31 AM: Sweep initiated using definitions version 569
9:31 AM: Starting Memory Sweep
9:33 AM: Memory Sweep Complete, Elapsed Time: 00:02:04
9:33 AM: Starting Registry Sweep
9:34 AM:   Found Adware: coolwebsearch (cws)
9:34 AM:   HKU\WRSS_Profile_S-1-5-21-1343024091-1303643608-839522115-501\software\microsoft\windows\currentversion\run\ || quicktime task (ID = 112405)
9:34 AM: Registry Sweep Complete, Elapsed Time:00:00:15
9:34 AM: Starting Cookie Sweep
9:34 AM:   Found Spy Cookie: 2o7.net cookie
9:34 AM:   megan rose@2o7[1].txt (ID = 1957)
9:34 AM:   Found Spy Cookie: adrevolver cookie
9:34 AM:   megan rose@adrevolver[2].txt (ID = 2088)
9:34 AM:   megan rose@adrevolver[3].txt (ID = 2088)
9:34 AM:   Found Spy Cookie: addynamix cookie
9:34 AM:   megan [email protected][1].txt (ID = 2062)
9:34 AM:   Found Spy Cookie: pointroll cookie
9:34 AM:   megan [email protected][2].txt (ID = 3148)
9:34 AM:   Found Spy Cookie: atwola cookie
9:34 AM:   megan rose@atwola[1].txt (ID = 2255)
9:34 AM:   Found Spy Cookie: banner cookie
9:34 AM:   megan rose@banner[1].txt (ID = 2276)
9:34 AM:   Found Spy Cookie: casalemedia cookie
9:34 AM:   megan rose@casalemedia[1].txt (ID = 2354)
9:34 AM:   megan [email protected][1].txt (ID = 1958)
9:34 AM:   Found Spy Cookie: nextag cookie
9:34 AM:   megan rose@nextag[1].txt (ID = 5014)
9:34 AM:   Found Spy Cookie: questionmarket cookie
9:34 AM:   megan rose@questionmarket[1].txt (ID = 3217)
9:34 AM:   Found Spy Cookie: realmedia cookie
9:34 AM:   megan rose@realmedia[2].txt (ID = 3235)
9:34 AM:   Found Spy Cookie: serving-sys cookie
9:34 AM:   megan rose@serving-sys[1].txt (ID = 3343)
9:34 AM:   Found Spy Cookie: trafficmp cookie
9:34 AM:   megan rose@trafficmp[2].txt (ID = 3581)
9:34 AM:   Found Spy Cookie: tribalfusion cookie
9:34 AM:   megan rose@tribalfusion[1].txt (ID = 3589)
9:34 AM:   Found Spy Cookie: adserver cookie
9:34 AM:   megan [email protected][1].txt (ID = 2142)
9:34 AM:   Found Spy Cookie: zedo cookie
9:34 AM:   megan rose@zedo[2].txt (ID = 3762)
9:34 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
9:34 AM: Starting File Sweep
9:35 AM:   Found Adware: twain-tech
9:35 AM:   preinstt.exe (ID = 81866)
9:35 AM:   Found Adware: directrevenue-abetterinternet
9:35 AM:   alchem.cab (ID = 83107)
9:35 AM:   Found Adware: websearch toolbar
9:35 AM:   wintools.exe (ID = 84898)
9:36 AM:   biini.cab (ID = 83198)
9:36 AM:   Found Adware: clipgenie
9:36 AM:   main.html (ID = 53069)
9:36 AM:   preinstt.exe (ID = 81866)
9:36 AM:   Found Adware: exact cashback/bargain buddy
9:36 AM:   ub.dat (ID = 50877)
9:36 AM:   Found Adware: commonname
9:36 AM:   createbookmark.htm (ID = 53770)
9:36 AM:   createnote.htm (ID = 53771)
9:36 AM:   bi.inf (ID = 83179)
9:36 AM:   Found Adware: gsim
9:36 AM:   gsim.cab (ID = 61965)
9:36 AM:   gsim.cab (ID = 61965)
9:38 AM:   biprep.exe (ID = 83208)
9:38 AM:   twaintec.dll (ID = 81884)
9:38 AM:   preinstt.exe (ID = 81866)
9:38 AM:   bi.dll (ID = 83173)
9:39 AM:   Found Adware: ebates money maker
9:39 AM:   wsebate0.exe (ID = 59727)
9:40 AM:   Found Adware: gain-supported software
9:40 AM:   q0rfh7facqaaacxknc6-ildsiz0-5nocxae===.gdt2 (ID = 61572)
9:41 AM:   bi.ini (ID = 81893)
9:41 AM:   gsim.inf (ID = 61964)
9:42 AM:   wtoolsd.cfg (ID = 87617)
9:42 AM:   twaintec.dll (ID = 81884)
9:43 AM:   twtini.cab (ID = 81895)
9:43 AM:   wrdpreview.wmv (ID = 53093)
9:43 AM:   f1_2b_categories.html (ID = 53045)
9:43 AM:   twaintec.dll (ID = 81884)
9:45 AM:   gsim.inf (ID = 61964)
9:45 AM:   player.html (ID = 53078)
9:45 AM:   playerslices.htm (ID = 53080)
9:45 AM:   scroller.swf (ID = 53090)
9:46 AM:   gsim.dll (ID = 61963)
9:47 AM:   gsim.dll (ID = 61963)
9:47 AM:   bikpreview.wmv (ID = 53028)
9:47 AM:   casinopreview.wmv (ID = 53029)
9:47 AM:   celebpreview.wmv (ID = 53030)
9:47 AM:   extpreview.wmv (ID = 53042)
9:47 AM:   grvpreview.wmv (ID = 53061)
9:48 AM:   twaintec.ini (ID = 81893)
9:51 AM:   btiein.dll (ID = 84616)
9:51 AM:   bi.cab (ID = 83171)
9:51 AM:   alchem.exe (ID = 83108)
9:51 AM:   wsebate0.exe (ID = 59727)
9:51 AM:   wsebate0.exe (ID = 59727)
9:52 AM:   gatorstubsetup.exe (ID = 61412)
9:52 AM:   guninstaller.exe (ID = 61468)
9:52 AM:   Found Adware: delfin
9:52 AM:   delfinad.ebd (ID = 57676)
9:52 AM:   delfinlo.ebd (ID = 57688)
9:52 AM:   dfs.dat (ID = 53778)
9:53 AM:   Found Adware: whenu save
9:53 AM:   save.exe (ID = 74374)
9:53 AM:   date manager.lnk (ID = 61325)
9:53 AM:   gappmgr.dll (ID = 61377)
9:53 AM:   gmtproxy.dll (ID = 61439)
9:53 AM:   date manager.lnk (ID = 61325)
9:53 AM:   about gain.lnk (ID = 61269)
9:53 AM:   gatorres.dll (ID = 61405)
9:53 AM:   gstartup.lnk (ID = 61450)
9:53 AM:   egnsengine.dll (ID = 61346)
9:53 AM:   egieprocess.dll (ID = 61344)
9:53 AM:   eggcengine.dll (ID = 61340)
9:53 AM:   hfixcfg (ID = 61483)
9:53 AM:   appmgrgui.zip (ID = 61281)
9:53 AM:   precisiontime.lnk (ID = 61563)
9:53 AM:   gator.log (ID = 61386)
9:53 AM:   precisiontime.lnk (ID = 61563)
9:53 AM:   egieengine.dll (ID = 61343)
9:54 AM:   gatorsupportinfo.txt (ID = 61414)
9:54 AM:   delfined.edx (ID = 57683)
9:54 AM:   delfinid.edx (ID = 57691)
9:54 AM:   cmediagnostics.log (ID = 61291)
9:54 AM:   mepcme.dat (ID = 61517)
9:54 AM:   Found Adware: downloadware
9:54 AM:   1013.pid (ID = 59282)
9:54 AM:   gain website.url (ID = 61373)
9:54 AM:   delfindl.edx (ID = 57683)
9:54 AM:   delfinaf.edx (ID = 57679)
9:54 AM:   delfinco.edx (ID = 57683)
9:54 AM:   biini.inf (ID = 83199)
9:54 AM:   delfinld.edx (ID = 57683)
9:54 AM:   delfinbd.edx (ID = 57683)
9:54 AM:   syscfg (ID = 61590)
9:54 AM:   q0tasjbqbgaaaleq-tobgnpj.gdt2 (ID = 61574)
9:54 AM:   448.ga (ID = 61233)
9:54 AM:   750.ga (ID = 61238)
9:54 AM:   global.cfg (ID = 146968)
9:54 AM:   twaintec.inf (ID = 81890)
9:54 AM:   763.ga (ID = 61240)
9:54 AM:   emaillink.htm (ID = 53781)
9:54 AM:   navigate.htm (ID = 53803)
9:54 AM:   twaintec.inf (ID = 81890)
9:54 AM:   twaintec.inf (ID = 81890)
9:54 AM:   twtini.inf (ID = 81896)
9:54 AM:   rmhgxlmu.wzg (ID = 85808)
9:54 AM:   alchem.inf (ID = 83109)
9:54 AM:   alchem.ini (ID = 83112)
9:54 AM:   q0rfh7facqaaacxknc6-ildsiz0-5nocxae===.gbt2 (ID = 61571)
9:54 AM:   523.ga (ID = 61234)
9:54 AM:   content.js (ID = 53041)
9:54 AM:   channelstyles.css (ID = 53081)
9:54 AM:   channels.js (ID = 53036)
9:54 AM:   guistyles.css (ID = 53081)
9:54 AM:   launch.html (ID = 53068)
9:54 AM:   f1_1.html (ID = 53043)
9:54 AM:   f1_2a.html (ID = 53044)
9:54 AM:   f1_3.html (ID = 53046)
9:54 AM:   f2.html (ID = 53047)
9:54 AM:   f3_1.html (ID = 53048)
9:54 AM:   f3_2a_player.html (ID = 53049)
9:54 AM:   f3_2b.html (ID = 53050)
9:54 AM:   f3_3.html (ID = 53051)
9:54 AM:   f3_4a_files.html (ID = 53052)
9:54 AM:   f3_4b.html (ID = 53053)
9:54 AM:   f3_5.html (ID = 53054)
9:54 AM:   playerstyles.css (ID = 53081)
9:54 AM:   rws.dat (ID = 53812)
9:54 AM:   exit.dat (ID = 53783)
9:54 AM:   url8.dat (ID = 53834)
9:54 AM:   url9.dat (ID = 53835)
9:54 AM:   Warning: Failed to access drive D:
9:54 AM:   Warning: Failed to access drive E:
9:54 AM:   Warning: Failed to access drive F:
10:03 AM: File Sweep Complete, Elapsed Time: 00:29:27
10:03 AM: Full Sweep has completed.  Elapsed time 00:31:49
10:03 AM: Traces Found: 134
10:05 AM: Removal process initiated
10:05 AM:   Quarantining All Traces: directrevenue-abetterinternet
10:05 AM:   Quarantining All Traces: websearch toolbar
10:05 AM:   Quarantining All Traces: commonname
10:05 AM:   Quarantining All Traces: coolwebsearch (cws)
10:05 AM:   Quarantining All Traces: gain-supported software
10:05 AM:   Quarantining All Traces: clipgenie
10:05 AM:   Quarantining All Traces: delfin
10:05 AM:   Quarantining All Traces: downloadware
10:05 AM:   Quarantining All Traces: ebates money maker
10:05 AM:   Quarantining All Traces: exact cashback/bargain buddy
10:05 AM:   Quarantining All Traces: gsim
10:05 AM:   Quarantining All Traces: twain-tech
10:05 AM:   Quarantining All Traces: whenu save
10:05 AM:   Quarantining All Traces: 2o7.net cookie
10:05 AM:   Quarantining All Traces: addynamix cookie
10:05 AM:   Quarantining All Traces: adrevolver cookie
10:05 AM:   Quarantining All Traces: adserver cookie
10:05 AM:   Quarantining All Traces: atwola cookie
10:05 AM:   Quarantining All Traces: banner cookie
10:05 AM:   Quarantining All Traces: casalemedia cookie
10:05 AM:   Quarantining All Traces: nextag cookie
10:05 AM:   Quarantining All Traces: pointroll cookie
10:05 AM:   Quarantining All Traces: questionmarket cookie
10:05 AM:   Quarantining All Traces: realmedia cookie
10:05 AM:   Quarantining All Traces: serving-sys cookie
10:05 AM:   Quarantining All Traces: trafficmp cookie
10:05 AM:   Quarantining All Traces: tribalfusion cookie
10:05 AM:   Quarantining All Traces: zedo cookie
10:05 AM: Removal process completed.  Elapsed time 00:00:53
********
9:20 AM: |       Start of Session, Tuesday, November 08, 2005       |
9:20 AM: Spy Sweeper started
9:21 AM: Your spyware definitions have been updated.
9:31 AM: |       End of Session, Tuesday, November 08, 2005  




Logfile of HijackThis v1.99.1
Scan saved at 10:09:37 AM, on 11/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoctrl.exe
H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoguard.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
H:\WINDOWS\Explorer.EXE
H:\WINDOWS\System32\hkcmd.exe
H:\WINDOWS\BCMSMMSG.exe
H:\Program Files\Common Files\Symantec Shared\ccApp.exe
H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
H:\Program Files\HP\hpcoretech\hpcmpmgr.exe
H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
H:\Program Files\Messenger\msmsgs.exe
H:\Program Files\AIM\aim.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Documents and Settings\Megan Rose\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - H:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] H:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] H:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "H:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] H:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "H:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "H:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] H:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] H:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "H:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [Norton SystemWorks] "H:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "H:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] H:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = H:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - H:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1125935343498
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1125958987187
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O20 - Winlogon Notify: WRNotifier - H:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - H:\Documents and Settings\Megan Rose\Desktop\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - H:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - H:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - H:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - H:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - H:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - H:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Offline valent5

  • Newbie
  • *
  • Posts: 6
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #18 on: November 08, 2005, 01:45:05 PM »
REMOVED
« Last Edit: November 08, 2005, 10:58:12 PM by guestolo »

Offline MeganRose

  • Newbie
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Help me! rdriv is driving me nuts!
« Reply #19 on: November 08, 2005, 11:04:51 PM »
***