What is "rdr road ref\dent bows"?
Results 1 to 9 of 9

Thread: What is "rdr road ref\dent bows"?

  1. #1
    Registered User trevethen's Avatar
    Join Date
    Dec 2004
    Location
    South-West England
    Posts
    20

    What is "rdr road ref\dent bows"?

    Does anyone know what the application - "rdr road ref\dent bows" - is/does/what it is for??

    It is on my system configuration utility in the start-up - twice. I have tried to delete the file and directory, but am being denied access to it, and even trying to delete it in cmd.exe it cannot be found.

    This is one of the exe programs I cannot get rid of. So what is it, and what is it for or does it do?

    It is continually setting itself to start up.

    I'll start with this one and go onto the other one later.

    regards,
    Philip.

  2. #2
    Banned TripleRLtd's Avatar
    Join Date
    Aug 2003
    Location
    SW Florida...eye of the storm.
    Posts
    7,251
    I never heard of it, so, after searching the different variations of what you posted I found nothing either. So, we may be looking at malware. But, find the file and right click and choose properties and then, depending upon your os, tell us about who makes the version of the file. Look for any details.
    Tell us more about what you have: OS, what problems if any, etc. Have you done any virus or spyware scans?

  3. #3
    Registered User geoscomp's Avatar
    Join Date
    Apr 2002
    Location
    Minnesota
    Posts
    2,340
    I think TripleR is right...as I recall, the TrojanDownloader.Win32.Swizzor.bg has a bows.exe and variations thereof connected to it...and any time you are denied access to something that is not a system file, you should start thinking spyware/virus.

  4. #4
    Registered User trevethen's Avatar
    Join Date
    Dec 2004
    Location
    South-West England
    Posts
    20
    Quote Originally Posted by TripleRLtd
    I never heard of it, so, after searching the different variations of what you posted I found nothing either. So, we may be looking at malware. But, find the file and right click and choose properties and then, depending upon your os, tell us about who makes the version of the file. Look for any details.
    Tell us more about what you have: OS, what problems if any, etc. Have you done any virus or spyware scans?
    My OS is XP2.

    I have right clicked on the file, 238KB, and in properties, this is all that comes up:-
    Type of file - application
    Description - dent bows
    Location - C:\Documents and Settings\Default\Application Data\rdr road ref
    Created - 15 Feb 2005 19:43:07
    Modified - 15 Feb 2005 19:43:00
    Accessed - 24 Feb 2005
    Attributes - Archive.

    The file always has todays date as the date accessed.

    This is all the info I can give. Whatever the program is for, it will not allow me to delete it.

    I have Adaware that I run once a week, and also AVG 7, and with this I also do a virus check weekly. I run ZoneAlam Pro, and am on broadband.

    AVG has not found any virus.

    regards,
    Philip.

  5. #5
    Registered User geoscomp's Avatar
    Join Date
    Apr 2002
    Location
    Minnesota
    Posts
    2,340
    If you suspect any kind of infection..you cannot rely on your installed antivirus to find it. Likewise, adaware by itself..though a fine program..cannot find everything. My suggestion would be to run an online virus scan at housecall

    followed by downloading and updating Spybot S&D

    If those two do not get the files off, then try Hijack This and put the program in a folder of it's own. Do not remove anything with Hijack This..rather copy/paste the results here.

  6. #6
    Registered User trevethen's Avatar
    Join Date
    Dec 2004
    Location
    South-West England
    Posts
    20
    Quote Originally Posted by geoscomp
    If you suspect any kind of infection..you cannot rely on your installed antivirus to find it. Likewise, adaware by itself..though a fine program..cannot find everything. My suggestion would be to run an online virus scan at housecall

    followed by downloading and updating Spybot S&D

    If those two do not get the files off, then try Hijack This and put the program in a folder of it's own. Do not remove anything with Hijack This..rather copy/paste the results here.
    Right. I've done all the tests, and nothing found.

    The results of "hijackthis" are
    Logfile of HijackThis v1.99.1
    Scan saved at 22:01:43, on 24/02/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\tardisnt.exe
    C:\WINDOWS\System32\ZoneLabs\vsmon.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC 1.EXE
    C:\Program Files\Messenger Plus! 3\MsgPlus.exe
    C:\WINDOWS\SYSTEM32\qttask.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\SETI@home\[email protected]
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC 1.EXE
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\IMsecure\IMsecure.exe
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\DllHost.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Default\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.afmsnqpxuhtk.com/t7EWmHaj...KZdqUv01uD.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pdkwlcafzolzitsbzomimbvu....QCoKh9Jbc.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.co.uk/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
    O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\PROGRAM FILES\DAP\DAPBHO.DLL
    O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\PROGRAM FILES\DAP\DAPIEBAR.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {20E86610-D81F-64D2-9C30-B79D09BF5F42} - C:\DOCUME~1\Default\APPLIC~1\SLOWIN~1\Copy Chic.exe
    O2 - BHO: Pluslitebib - {2E5B9DAE-627E-B2A8-F14E-5A7C34E7AD68} - C:\PROGRA~1\SLOWIN~1\Active Bore.dll (file missing)
    O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\ADSHIELD\ADSHIELD\ADSHIELD.DLL
    O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4b\NHelper.dll (file missing)
    O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM32\NZDD0.DLL
    O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\PROGRAM FILES\DAP\DAPIEBAR.DLL
    O3 - Toolbar: List Lies Heart - {6CD50C01-89C5-CE3E-03E9-1894F38C133D} - C:\PROGRA~1\SLOWIN~1\Active Bore.dll (file missing)
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC 1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\[email protected] -min
    O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC 1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
    O4 - HKCU\..\Run: [freeblah] C:\DOCUME~1\Default\APPLIC~1\RDRROA~1\dent bows.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: IMsecure.lnk = C:\Program Files\IMsecure\IMsecure.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Maintain Block List... - C:\PROGRA~1\ADSHIELD\ADSHIELD\maintain.htm
    O8 - Extra context menu item: Add to &Block List... - C:\PROGRA~1\ADSHIELD\ADSHIELD\suppress.htm
    O8 - Extra context menu item: AdShield Option &Settings... - C:\PROGRA~1\ADSHIELD\ADSHIELD\settings.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: AdShield - {4FB6C25E-7B37-4c93-B592-16ECD8D18361} - C:\PROGRA~1\ADSHIELD\ADSHIELD\ADSHIELD.DLL (HKCU)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: Win32 Classes -
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
    O16 - DPF: {6AEFE48C-FB6C-4C27-A161-A0BF3438537E} - http://www.regenthotel.com/webcam/cab/Live.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://www1.getmapping.com/ecwplugins/ncs.cab
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/d...in/actxcab.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: Tardis time service (Tardis) - Unknown owner - C:\WINDOWS\System32\tardisnt.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\System32\ZoneLabs\vsmon.exe


    The file I cannot delete is freeblah - whatever that is.

    regards,
    Philip

    BTW, this is another I cannot delete or know what it is for.
    C:\DOCUME~1\Default\APPLIC~1\SLOWIN~1\Copy Chic.exe
    O2 - BHO: Pluslitebib - {2E5B9DAE-627E-B2A8-F14E-5A7C34E7AD68} -

    "SlowInterFunk" - any ideas.
    Last edited by trevethen; February 24th, 2005 at 05:45 PM.

  7. #7
    Registered User geoscomp's Avatar
    Join Date
    Apr 2002
    Location
    Minnesota
    Posts
    2,340
    K..you need to put HijackThis in it's own folder, run it again, and then check these items and then choose fix:

    c:\progra~1\intern~1\iexplore.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.afmsnqpxuhtk.com/t7EWmHa...eKZdqUv01uD.htm

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pdkwlcafzolzitsbzomimbvu...kQCoKh9Jbc.html


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm

    O2 - BHO: (no name) - {20E86610-D81F-64D2-9C30-B79D09BF5F42} - C:\DOCUME~1\Default\APPLIC~1\SLOWIN~1\Copy Chic.exe

    O2 - BHO: Pluslitebib - {2E5B9DAE-627E-B2A8-F14E-5A7C34E7AD68} - C:\PROGRA~1\SLOWIN~1\Active Bore.dll (file missing)

    O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4b\NHelper.dll (file missing)

    O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM32\NZDD0.DLL

    O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O3 - Toolbar: List Lies Heart - {6CD50C01-89C5-CE3E-03E9-1894F38C133D} - C:\PROGRA~1\SLOWIN~1\Active Bore.dll (file missing)

    O4 - HKCU\..\Run: [freeblah] C:\DOCUME~1\Default\APPLIC~1\RDRROA~1\dent bows.exe

    O16 - DPF: Win32 Classes -


    reboot after fixing into safe mode and try to remove the offending files again
    Computer Rescue Service

    "those who do not remember history are condemned to repeat it."

  8. #8
    Banned TripleRLtd's Avatar
    Join Date
    Aug 2003
    Location
    SW Florida...eye of the storm.
    Posts
    7,251
    Quote Originally Posted by trevethen
    Right. I've done all the tests, and nothing found.
    Sorry trev, but Geo is right. You've been infected.
    Follow his advice, and you must do these detections in safe mode.
    If you still have proplems, then follow the advise that I'll link to and let us know if that doesn't help. If it doesn't, then post another hijack this log.
    Good luck.
    http://forums.windrivers.com/showthread.php?t=57348

  9. #9
    Registered User trevethen's Avatar
    Join Date
    Dec 2004
    Location
    South-West England
    Posts
    20
    Quote Originally Posted by geoscomp
    K..you need to put HijackThis in it's own folder, run it again, and then check these items and then choose fix:

    I've done what you and TripleR advise, and have deleted the files, plus a couple more that I could not delete.

    So, how does it look now? (and another question at the end)

    Logfile of HijackThis v1.99.1
    Scan saved at 10:22:13, on 25/02/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    C:\Program Files\Messenger Plus! 3\MsgPlus.exe
    C:\WINDOWS\SYSTEM32\qttask.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\SETI@home\[email protected]
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\WINDOWS\System32\tardisnt.exe
    C:\Program Files\IMsecure\IMsecure.exe
    C:\WINDOWS\System32\ZoneLabs\vsmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\WINDOWS\system32\DllHost.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Default\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ygvzlnjrzcdwqtnrcinga.com...KZdqUv01uD.jpg
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tiscali.co.uk/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
    O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\PROGRAM FILES\DAP\DAPBHO.DLL
    O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\PROGRAM FILES\DAP\DAPIEBAR.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: AdShield.AdShield - {7559B76E-0222-4d77-9499-CCE9EB4EDC2F} - C:\PROGRA~1\ADSHIELD\ADSHIELD\ADSHIELD.DLL
    O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\PROGRAM FILES\DAP\DAPIEBAR.DLL
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC 1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\[email protected] -min
    O4 - HKCU\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC 1.EXE /P23 "EPSON Stylus C82 Series" /M "Stylus C82" /EF "HKCU"
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: IMsecure.lnk = C:\Program Files\IMsecure\IMsecure.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Maintain Block List... - C:\PROGRA~1\ADSHIELD\ADSHIELD\maintain.htm
    O8 - Extra context menu item: Add to &Block List... - C:\PROGRA~1\ADSHIELD\ADSHIELD\suppress.htm
    O8 - Extra context menu item: AdShield Option &Settings... - C:\PROGRA~1\ADSHIELD\ADSHIELD\settings.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0322.DLL
    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: AdShield - {4FB6C25E-7B37-4c93-B592-16ECD8D18361} - C:\PROGRA~1\ADSHIELD\ADSHIELD\ADSHIELD.DLL (HKCU)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
    O16 - DPF: {6AEFE48C-FB6C-4C27-A161-A0BF3438537E} - http://www.regenthotel.com/webcam/cab/Live.cab
    O16 - DPF: {7380B862-BA18-4529-8972-C66B82AA5D1D} (AccountTracking Class) - http://moneymanager.egg.com/customer...nttracking.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://www1.getmapping.com/ecwplugins/ncs.cab
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/d...in/actxcab.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: Tardis time service (Tardis) - Unknown owner - C:\WINDOWS\System32\tardisnt.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\System32\ZoneLabs\vsmon.exe


    The extra question loosely tied to the above.

    In the "msconfig" - start up - how do, or can, I remove unwanted and unused start-up items?

    Many thanks for your invaluable advice - both of you.

Similar Threads

  1. Road Runner question
    By asm481 in forum Spyware & Antivirus - Security
    Replies: 2
    Last Post: September 25th, 2003, 07:00 AM
  2. [RESOLVED] And the Angels lit the candles....
    By godofuq in forum Tech Lounge & Tales
    Replies: 3
    Last Post: September 20th, 2001, 09:35 AM
  3. Road Runner Cable and cable modems
    By Silverman in forum Internet and Networking
    Replies: 8
    Last Post: July 11th, 2001, 04:21 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •