you know when u press ctrl+alt+delete on windows XP and it bring up the menu with applications, processes, etc. well i always close all programs running for me and other usernames, but i never touched the ones under SYSTEM. im concerned now tho because some of them look like they may be hacking or spyware programs.

Um, dunno, but those look normal to me. Spoolsv is just your print server/driver, ccevtmgr.exe is a symantec event manager, and the r_server is a remote admin. Now the last one could be a hack if your not using remote admin, but a legit prog if you are, or are on a VPN or your network admin set something like that up. If none of those are true, startup your services.msc and disable r_server.exe, check your msconfig and startup directory, and check your registry.


d/l'ed the spyware protector in ur sig earlier, ill check out the adware one

Then after reboot:
Download 'Hijack This!'. http://www.tomcoyote.org/hjt/
Unzip to a permanent folder, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, load it in Notepad, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.
then post the log here


hmm the web site might be down or wrong link because the link isnt working

Yeah ,the site is under a DDOS attach ,the temporary link in my sig now works

