My zone alarm keeps asking this " NDrv.exex is tring to access the internet. Of course i deny it all the time but I cant get rid of it so Heres a view log from HIJACK THIS , was wondering what can i get rid of.


-------------- HIJACK THIS LOG


Logfile of HijackThis v1.97.7
Scan saved at 8:24:12 PM, on 6/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sstray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\NDrv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijack this\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Curl - {A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} - C:\WINDOWS\System32\NDrv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Microsoft« JavaScript« Console (HKLM)
O9 - Extra 'Tools' menuitem: JavaScript Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Microsoft« JavaScript« Console (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console (HKCU)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Dani AI

Generated

posted a HijackThis log showing a suspicious NDrv process and gave the right basic removal idea (disable the startup entry and delete the file from Safe Mode). The steps below add safe verification and cleanup so deletion does not break a legitimate component or miss a browser helper object that keeps re-installing it.

Before you remove anything

  • Confirm identity: check the running process with a tool that shows image path, signer and parent process. Use Process Explorer to view who started it and whether the binary is digitally signed (Process Explorer).
  • Check the binary/hash online before removal. Upload the file or its hash to VirusTotal to see if multiple engines flag it (VirusTotal).
  • Inspect browser add-ons and startup items with Autoruns so you can disable associated BHOs or Run keys cleanly (Autoruns).

Safe removal workflow

  1. Make a full backup or create a System Restore point.
  2. Reboot to Safe Mode (F8 on boot) so the process isn't locked.
  3. Use Autoruns to uncheck and delete the startup entry and any BHO entry referencing the file.
  4. Kill the process if still running and rename the file (so rollback is easy). Example commands you can run from an elevated command prompt:
    taskkill /IM NDrv.exe /F
    ren C:\Windows\System32\NDrv.exe NDrv.exe.old
  5. Reboot normally and run a full scan with an up-to-date AV plus an anti-malware scanner (for example, Malwarebytes).

Follow-up and cautions
If the entry or file reappears, a helper/installer is reinstalling it — search for related services, scheduled tasks, or installer directories. If unsure whether the file is legitimate (driver or vendor-signed), do not delete it until verified. If removal fails or you suspect a deeper infection, use an offline rescue disk or post the file hash (not the file) for analysis.

Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe

Reboot into safe mode following the instructions & navigate to & delete the following if found:

C:\WINDOWS\System32\NDrv.exe<<<<

Reboot normally.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.