Hi michael5865,
A google search on the processes would give you information if it is a legitimate process or use this tool
http://www.sysinternals.co
SR..
Main Topics
Browse All TopicsIn Windows Task Manager - Processes, how do I distinguish ligitimate programs from illigitimate?
There are 55 processes running and I would like to screen them for bogus software.
Thanks,
Michael
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi michael5865,
A google search on the processes would give you information if it is a legitimate process or use this tool
http://www.sysinternals.co
SR..
This page will let you know about a good majority of them.
http://www.answersthatwork
For example, my Windows Task Manager indicates as process running called "suee.exe"
I did a Google search on it and nothing obvious appeared.
I looked on the list at "http://www.answersthatwor
How can I find out what it does and whether it is supposed to be running?
Michael
I would definetly get the program Sunray linked to as it will tell you more info about the process, including which folder it is currently stored in which may give you a clue.
In my experience, if Yahoo or Google don't have it on their site, it probably shouldn't be there unless it is related to a very specific application you have.
michael5865,
Yahoo and google not giving information on that necessarily mean they are bad programs
However, I would start here
a) First check using that process explorer program if it says anything
b) check for spywares using the following programs
**
Spybot : www.softpedia.com/public/c
Ad-Aware : http://download.com.com/30
CWshredder : http://www.softpedia.com/p
Hijackthis : http://www.softpedia.com/p
**
c) Scan for virus using these
http://vil.nai.com/vil/sti
http://housecall.trendmicr
http://security.symantec.c
Check how it goes
SR
Thank you. I hope you meant for me to post the saved log file from a HijackThis scan here at EE. Anyway, below is the log file. Can you advise me which items might be trojans or other items that should be deleted.
Thanks. Here's the log file"
Logfile of HijackThis v1.98.2
Scan saved at 10:30:44 AM, on 8/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\System32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\PROGRA~1\COMMON~1\AOL\A
C:\WINDOWS\system32\cisvc.
C:\WINDOWS\System32\inetsr
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\snmp.e
C:\WINDOWS\System32\svchos
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\AccessDirect\da
C:\Program Files\Dell\QuickSet\quicks
C:\WINDOWS\System32\DSentr
C:\WINDOWS\system32\dla\tf
C:\Program Files\MUSICMATCH\MUSICMATC
C:\Program Files\Common Files\Dell\EUSW\Support.ex
C:\Program Files\Common Files\Real\Update_OB\reals
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MUSICMATCH\MUSICMATC
C:\WINDOWS\System32\nivlps
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Looksmart\Grub 2\Grubgui.exe
C:\Documents and Settings\Michael Spalding\Application Data\suee.exe
C:\WINDOWS\System32\rwxu.e
C:\Program Files\Dell\AccessDirect\Da
C:\Program Files\AOL 8.0b\aoltray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
C:\Program Files\WINZIP\WZQKPICK.EXE
C:\Program Files\Dell\Support\Alert\b
C:\Program Files\ePrompter\ePrompter.
C:\WINDOWS\System32\wbem\w
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaem
C:\WINDOWS\system32\cidaem
C:\PROGRA~1\WINZIP\winzip3
C:\unzipped\hijackthis[1]\
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-2
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-7
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-8
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {3CDC3E25-B241-29C3-D321-6
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-0
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-A
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-E
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-1
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-F
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\da
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quicks
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentr
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [vptray] E:\Norton AntiVirus\vptray.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATC
O4 - HKLM\..\Run: [qstoliouhtf] C:\WINDOWS\System32\nivlps
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Grubclient] C:\Program Files\Looksmart\Grub 2\Grubgui.exe
O4 - HKCU\..\Run: [Oesb] C:\Documents and Settings\Michael Spalding\Application Data\suee.exe
O4 - HKCU\..\Run: [Anjfp] C:\WINDOWS\System32\rwxu.e
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0b\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WINZIP\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEA
O8 - Extra context menu item: Alexa Web Search - http://client.alexa.com/ho
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Get Alexa Data - http://client.alexa.com/ho
O8 - Extra context menu item: Mail to a Friend... - http://client.alexa.com/ho
O8 - Extra context menu item: See Related Links - http://client.alexa.com/ho
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Write a Review... - http://client.alexa.com/ho
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: Alexa - {9D74677A-E227-40fb-9511-F
O9 - Extra 'Tools' menuitem: Alexa Toolbar - {9D74677A-E227-40fb-9511-F
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-0
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.d
O16 - DPF: {1D6711C8-7154-40BB-8380-3
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0
O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9
O16 - DPF: {90C9629E-CD32-11D3-BBFB-0
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
O18 - Protocol: OWC11.mso-offdap - {32505114-5902-49B2-880A-1
I guess these would be the entries releated to those exe files.
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [qstoliouhtf] C:\WINDOWS\System32\nivlps
O4 - HKCU\..\Run: [Oesb] C:\Documents and Settings\Michael Spalding\Application Data\suee.exe
O4 - HKCU\..\Run: [Anjfp] C:\WINDOWS\System32\rwxu.e
O16 - DPF: {1D6711C8-7154-40BB-8380-3
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0
Remove these
C:\WINDOWS\System32\nivlps
C:\WINDOWS\System32\rwxu.e
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - Default URLSearchHook is missing
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-7
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-1
O2 - BHO: (no name) - {3CDC3E25-B241-29C3-D321-6
O4 - HKCU\..\Run: [Anjfp] C:\WINDOWS\System32\rwxu.e
O4 - HKLM\..\Run: [qstoliouhtf] C:\WINDOWS\System32\nivlps
That P2P networking is because you have kazaa or other p2p programs. totally removing them would help solve issues
NOT SURE WHERE THESE ALL CAME FROM
********
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-A
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-E
*********
Well I have now used HijackThis to delete the files you listed.
For my futire reference, can you tell me what it was about these files that indicated to you that they should be deleted?
Also, whenever I launch Internet Explorer, a second Internet Explorer appears as a minimized icon on the bottom toolbar. When I click on it, it won't maximize. Sometimes, it turns into an advertisement. I can right-click close it.
What do you think is causing this, and how can I get rid of it?
Michael
Most of them just didn't ring any bells with regular program and their directories give it away. Anything in windows\system32 that isn't a normal Windows program probably shouldn't be there. Any program in Program Files that you don't remember installing probably shouldn't be there.
Running something like Spybot or AdAware would probably help as well.
www.security.kolla.de
www.lavasoftusa.com
Business Accounts
Answer for Membership
by: tanelornPosted on 2004-08-20 at 08:54:02ID: 11852539
take a look here
e.com/Oper ating_Syst ems/WinXP/ Q_20817010 .html
http://www.experts-exchang