Link to home
Start Free TrialLog in
Avatar of nitro2gomike
nitro2gomike

asked on

Virus or Malware Issue on XP PRO

I am running on XP Pro Service Pack 2. I have AVG, AdAware SE, and Spybot. I am having some issues with my pc. Periodically my monitor will flicker and I may be running a program and it will freeze. I have run all three virus, spyware, and malware programs on my pc in normal mode and safe mode to no avail. I do notice when I am shutting down my pc I get a message stating a certain dll. file needs to close. I have not been able to get a good look at it and don't know enuff about these files to mess with them. If anyone has any suggestions or possible solutions they would be greatly appreciated.
ASKER CERTIFIED SOLUTION
Avatar of johnb6767
johnb6767
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of nitro2gomike
nitro2gomike

ASKER

Here is the log file

Logfile of HijackThis v1.99.1
Scan saved at 3:23:47 PM, on 6/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\MI1933~1\Office10\OUTLOOK.EXE
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
E:\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070509
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070509
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

Here is the analisys

  Logfile of HijackThis v1.99.1  
 This should be the newest version.  
  Platform: Windows XP SP2 (WinNT 5.01.2600)  
 
  MSIE: Internet Explorer v7.00 (7.00.6000.16441)  
 This should be the newest version.  
   C:\WINDOWS\System32\smss.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\winlogon.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\services.exe  
Safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\lsass.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\Ati2evxx.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\svchost.exe  
Safe
This entry was classified from our visitors as good.
   C:\WINDOWS\System32\svchost.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\ZoneLabs\vsmon.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\System32\WLTRYSVC.EXE  
Safe
Broadcom Corporation Wireless Network Tray Applet
   C:\WINDOWS\System32\bcmwltry.exe  
Safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\spoolsv.exe  
Safe
This entry was classified from our visitors as good.
   C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe  
Safe
Possibly nasty! According to our database this process runs normally in c:\programme\gemeinsame dateien\aol\acs\! Check if you know this process and arrange a viruscheck where required. Part of AOL
   C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe  
Very safe
This entry was classified from our visitors as good.
   C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe  
Very safe
This entry was classified from our visitors as good.
   C:\PROGRA~1\Grisoft\AVG7\avgemc.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\Ati2evxx.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\Explorer.EXE  
Very safe
This entry was classified from our visitors as good.
   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe  
Safe
 
   C:\WINDOWS\system32\WLTRAY.exe  
Very safe This is a unknown process.
This entry was classified from our visitors as good.
   C:\WINDOWS\stsystra.exe  
Safe
This entry was classified from our visitors as good.
   C:\Program Files\ATI Technologies\ATI.ACE\cli.exe  
Very safe
ATI Control Center
   C:\Program Files\Dell\QuickSet\quickset.exe  
Safe
 
   C:\WINDOWS\system32\dla\tfswctrl.exe  
Neutral
HP DLA Packet Writing Software
   C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe  
Very safe
Install Shield Software Update
   C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe  
Very safe
Google Desktop Search
   C:\Program Files\Dell\MediaDirect\PCMService.exe  
 
PowerCinema
   C:\PROGRA~1\Grisoft\AVG7\avgcc.exe  
Very safe
This entry was classified from our visitors as good.
   C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe  
Very safe
This entry was classified from our visitors as good.
   C:\Program Files\Microsoft IntelliType Pro\type32.exe  
Very safe
Possibly nasty! According to our database this process runs normally in c:\programme\microsoft hardware\keyboard\! Check if you know this process and arrange a viruscheck where required.  
   C:\Program Files\Microsoft IntelliPoint\point32.exe  
Safe
 
   C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe  
Very safe
Possibly nasty! According to our database this process runs normally in c:\programme\hewlett-packard\toolbox\statusclient\! Check if you know this process and arrange a viruscheck where required. Toolbox for a Hewlett-Packard Printer
   C:\Program Files\NetWaiting\netWaiting.exe  
 
NetWaiting
   C:\Program Files\Dell Support\DSAgnt.exe  
Very safe
Dell Support Application
   C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe  
Very safe
Goodle Dekstop Search
   C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe  
Safe
Associated with GoogleToolbarNotifier from Google Inc.
   C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe  
Very safe
This entry was classified from our visitors as good.
   C:\WINDOWS\system32\ctfmon.exe  
Very safe
This entry was classified from our visitors as good.
   C:\Program Files\Messenger\msmsgs.exe  
Safe
This entry was classified from our visitors as good.
   C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE  
 Fuzzy Algorithmcheck (4.18 / 5.00), Safe
   C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe  
 
Possibly nasty! According to our database this process runs normally in c:\programme\java\jre1.5.0_05\bin\! Check if you know this process and arrange a viruscheck where required. Java
   C:\Program Files\Digital Line Detect\DLG.exe  
Safe
Digital Line Detect - BVRP Phone Tools software suite
   C:\Program Files\Internet Explorer\iexplore.exe  
Safe
This entry was classified from our visitors as good.
   C:\Program Files\ATI Technologies\ATI.ACE\cli.exe  
Very safe
ATI Control Center
   C:\PROGRA~1\MI1933~1\Office10\OUTLOOK.EXE  
 
Possibly nasty! According to our database this process runs normally in c:\programme\microsoft office\office11\! Check if you know this process and arrange a viruscheck where required. E-Mail Client für Windows.
   C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe  
Very safe
This entry was classified from our visitors as good.
   C:\Program Files\Microsoft Office\Office10\WINWORD.EXE  
Safe
Microsoft Word
   E:\Hijack This\HijackThis.exe  
 Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups! Tool, mit dem sie dieses Logfile erzeugt haben. Das Programm sollte so angelegt sein ! C:\Programme\HijackThis\HijackThis.exe
   R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070509 
 This page has been identified as safe.
   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 
Safe This page has been identified as safe.
   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 
Safe This page has been identified as safe.
   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 
Safe This page has been identified as safe.
   R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 
Safe This page has been identified as safe.
   R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070509 
 This page has been identified as safe.
   R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll  
 This entry has been identified as safe.  
   O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll  
 Ycomp*_*_*_*.dll - Yahoo Companion!, Yahoo Companion!  
   O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll  
Very safe AcroIEhelper.ocx, AcroIEhelper.dll - Adobe Acrobat reader, http://www.adobe.com/products/acrobat/re adstep2.html  
   O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll  
Safe This entry was classified from our visitors as good.
   O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll  
 Fuzzy Algorithmcheck (2.33 / 5.00), Nasty
   O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll  
 SBC Yahoo! Browser related
   O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll  
Neutral tfswshx.dll - Hewlett-Packard/Veritas DLA software
   O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll  
Safe This entry was classified from our visitors as good.
   O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll  
Safe This entry was classified from our visitors as good.
   O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll  
 GoogleAE.dll - Google Search related, found on Dell computers. Reportedly responsible for displaying this, http://www.google.com/hws/dell/afe? placeholder web page; also see here, http://www.gamedev.net/community/forums/ topic.asp?topic_id=368054 a
   O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll  
Safe This entry was classified from our visitors as good.
   O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll  
Neutral Ycomp*_*_*_*.dll - Yahoo Companion!, http://companion.yahoo.com/ 
   O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe  
Very safe  
   O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe  
Safe This entry was classified from our visitors as good.
   O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe  
Safe This entry was classified from our visitors as good.
   O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay  
Very safe ATI Catalyst ControlCenter
   O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe  
Very safe Not dangerous, but unnecessary. Dell taskbar icon allowing you to quickly change settings  
   O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe  
Safe Part of Sonic Solutions DVD/CD Suite / HP's packet writing software
   O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup  
 Not dangerous, but unnecessary. InstallShield Update Service related; Automatically searches for and performs any updates to the software. Not required.  
   O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start  
Very safe Not dangerous, but unnecessary. InstallShield Update Service Scheduler; automatically searches for and performs any updates to the software so youre always working with the most current version. Not required.
   O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup  
Very safe Not dangerous, but unnecessary. Google Desktop Search -
   O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"  
 In a Dell\Media Experience sub-directory  
   O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP  
Very safe This entry was classified from our visitors as good.
   O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime  
Neutral Not dangerous, but unnecessary. QuickTime
   O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"  
Very safe Firewall program from Zonelabs. Pro version inlcudes other online security options
   O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE  
Safe O4 - HKLM..Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
   O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"  
Safe Not dangerous, but unnecessary. For MS programmable keyboards. If you disable Intellitype in Startup, any "Hot Keys" that are changed by the user to perform functions other than default settings, defer back to their default settings. Not required unless you have changed them  
   O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"  
Safe Microsoft IntelliPoint
   O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto  
 Part of Hewlett-Packard Toolbox
   O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe  
Very safe Part of Hewlett-Packard Toolbox
   O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe  
Safe Dell V.92 modem control software
   O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup  
Neutral Dell Support
   O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe  
Very safe Associated with GoogleToolbarNotifier from Google Inc.
   O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe  
Safe This entry was classified from our visitors as good.
   O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background  
Safe This entry was classified from our visitors as good.
   O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet  
 Part of Yahoo Instant Messenger
   O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe  
 Adjusts monitor colours across all programs
   O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe  
Neutral Not dangerous, but unnecessary. Speeds up the time it takes to load the Adobe Reader application. Your choice
   O4 - Global Startup: Digital Line Detect.lnk = ?  
Neutral
The entry is unnecessary and can be fixed.  
   O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE  
Safe Not dangerous, but unnecessary. This entry was classified from our visitors as good.
   O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000  
 The entry E&xport to Microsoft Excel has been identified as safe.
   O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll  
Safe The entry has been identified as safe.
   O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll  
Very safe The entry Sun Java Console has been identified as safe.
   O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll  
Very safe The entry Yahoo! Services has been identified as safe.
   O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll  
Safe The entry Real.com has been identified as safe.
   O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)  
Safe
Unnecessary (deactivated) entry that can be fixed. This entry was classified from our visitors as good.
   O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)  
Very safe
Unnecessary (deactivated) entry that can be fixed. This entry was classified from our visitors as good.
   O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe  
Very safe The entry Messenger has been identified as safe.
   O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe  
Safe The entry Windows Messenger has been identified as safe.
   O11 - Options group: [INTERNATIONAL] International*  
Neutral  
   O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 
Safe This entry was classified from our visitors as good.
   O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll  
 This entry has been identified as safe.
   O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL  
Safe This entry was classified from our visitors as good.
   O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll  
Safe This entry was classified from our visitors as good.
   O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe  
Safe This service (Adobelmsvc.exe) was identified as a good one.  
   O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe  
 This service (AOLacsd.exe) was identified as a good one.  
   O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe  
Safe This service (Ati2evxx.exe) was identified as a good one. This entry was classified from our visitors as good.
   O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe  
Very safe This service (avgamsvr.exe) was identified as a good one. This entry was classified from our visitors as good.
   O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe  
Safe This service (avgupsvc.exe) was identified as a good one. This entry was classified from our visitors as good.
   O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe  
Very safe This service (avgemc.exe) was identified as a good one.  
   O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe  
Safe This service (GoogleUpdaterService.exe) was identified as a good one.  
   O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe  
Safe This service (HPZipm12.exe) was identified as a good one. This entry was classified from our visitors as good.
   O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe  
Very safe This service (vsmon.exe) was identified as a good one. This entry was classified from our visitors as good.
   O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE  
Very safe This service (WLTRYSVC.EXE) was identified as a good one.  
Short analysis
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Johnb6767 you had mentioned missing dll file. I am not aware of any missing dll files off hand. I just recently purchased a new Dell laptop with 1 m of RAM. It has an ATI Mobility Radeon X1400 video driver - Pretty much basic stuff.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I just downloaded and installed this software. Is there an application or log file under one of the tabs that would allow me to go back in after a shut down to find out what files was not closing?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial