mikeandike22 18 Nearly a Posting Virtuoso

Ok since you dont have system restore and i am a semi-newb to hijackthis (only know common spyware entries which you dont have). then i would wait for a mod or someone with more HJT experience tell you what to do I would hate to mess up your computer and not be able to restore back.

mikeandike22 18 Nearly a Posting Virtuoso

Well i have never had a problem with winmx and spyware so that should be alright just i would try and get antivirus software of some kind. In one of my first posts i told you what i thought might be viruses you should check those out at some virus search page.

mikeandike22 18 Nearly a Posting Virtuoso

here goto this site (if you can on your computer or another one with the internet)
http://www.spychecker.com/program/hijackthis.html
Download hijack this place on your c: drive then open up the program and hit scan. Then once the scan is complete save the log and place it here.

mikeandike22 18 Nearly a Posting Virtuoso

Oh thanks for the advice kc0arf but i really dont think that i am going to put it on that machine i have a better computer that i am running now the only reason i dont want to put linux on it is because it is the family computer and my little sister b!tc#es at me every time I do something to it and istalling another os on the pc (even with dual boot) is just the sort of thing that would get her pissed at me.

mikeandike22 18 Nearly a Posting Virtuoso

well if you took my advice then u should of created a restore point or backup of files so open system restore and restore back to the place where you performed the scan. Did you also check into having illegal p2p programs on your computer like kazaa, imesh, grokster, andd things like tha because usually those a re back with malware.

mikeandike22 18 Nearly a Posting Virtuoso

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = www.jeffco.edu
O9 - Extra button: MoneySide (HKLM)

mikeandike22 18 Nearly a Posting Virtuoso

about the keyboard thing i dont see the point do you mean that you want to hookup another keyboard or add peices on for an existing keyboard. The only real problem that I see is you might have to develop your own hardware for the audio(you would have to put more audio input spaces into your computer), then fabricate a new keyboard. From my knowledge of computers this sounds like something impossible.

mikeandike22 18 Nearly a Posting Virtuoso

binary if you didnt notice in the post all he would have lost was windows files he didnt need anymore not personal data and if he does a reinstall he would still need to reinstall some programs that need to be in the registry to run.

mikeandike22 18 Nearly a Posting Virtuoso

all i see is this
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

mikeandike22 18 Nearly a Posting Virtuoso

please add your own add ons and comments.

mikeandike22 18 Nearly a Posting Virtuoso

ok first off before you post a hijack this log you should probably do a basic spyware/virus scan with ad-aware, spybot S&D, and you anti virus software software.

Also make sure that when fixing problems to back up the files either via system restore or hijackthis will do it for you.

Now when you scan with hijack this you arent really going to understand what it is saying so to help you out here are somethings to watch for.

1.Things that are potentially viruses:

Sometimes you can tell if something is a virus by the name i would watch out for things that are like random series of letters of numbers i.e gf324sd.exe or 123fre786.exe these are probably viruses.

2. Here are some basic spyware things that you should watch out for:
webrebates
ebatesmoneymaker
mysearch bar
myfunstart
bargain buddy
cydoor
cool websearch
gator
xxxtoolbar
well those are just some of the main ones the occur frequently.

3.How to make sure spyware and viruses dont return or are properly deleted:
Well first off you should make sure that you have proper firewalls in place most makers of anti-virus software also make firewalls. The windows firewall should be up (if running sp2 it well inform you when either anti-virus or firewall software is disabled).
A good way to make sure that spyware does not return is to get something like spyware blaster which …

mikeandike22 18 Nearly a Posting Virtuoso

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php

O4 - HKLM\..\RunOnce: [ieie.exe] C:\WINDOWS\system32\ieie.exe

O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.skoobidoo.com

mikeandike22 18 Nearly a Posting Virtuoso

yeah it doesnt matter the cd drive is borken and so old that it would not be able to run the cd-r i burnt of the SuSE live eval cd. All it can run is basic linux which runs off of two floppy disks.

mikeandike22 18 Nearly a Posting Virtuoso

does gag support windows xp because all the screenshots (i didnt read much of the site) show that they can load older windows OSes but none specifically say windows xp.

mikeandike22 18 Nearly a Posting Virtuoso

yeah slackware was another choose but i had started to download slax live cd and the size(120 megs or so) is really small so i thought that would be a good choose i also thought of using this really old linux that i found called basic linux that looks sort of like the pre windows days.

mikeandike22 18 Nearly a Posting Virtuoso

all of these look like viruses
C:\WINDOWS\System32\gcfzzkheujp.exe
C:\WINDOWS\System32\8d2mo5ybwxr4xj.exe
C:\WINDOWS\System32\gcfzzkheujp.exe
C:\WINDOWS\System32\gcfzzkheujp.exe
C:\WINDOWS\System32\gcfzzkheujp.exe
C:\WINDOWS\System32\gcfzzkheujp.exe
set a system restore point and then open up the task manager end those processes(make sure that they dont restart) then delete them.

fix these item (unless you know what the are)
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART *(this means that you probably have illegal p2p software like kazaa intsalled on your pc i would look out for that)*
O4 - HKLM\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe *(never heard of it but sounds suspicous)*
O4 - HKLM\..\Run: [pnpsvc_lock] C:\WINDOWS\System32\25587401.exe
O4 - HKLM\..\Run: [TmybfCTiM] C:\documents and settings\corey\local settings\temp\TmybfCTiM.exe
O4 - HKLM\..\Run: [Network Security Guard] C:\WINDOWS\System32\gcfzzkheujp.exe
O4 - HKCU\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {B94B4225-E02E-4D3F-BADB-026F1E2F3AD7} (HttpDownloader Control) - http://www.instantplugin.com/SexDownloader.cab

make sure you make a restore point or backup before trying to fix these just in case it doesnt work.

mikeandike22 18 Nearly a Posting Virtuoso

if you are running of a router than you should have the auto detect boxes checked in the lan settings.

mikeandike22 18 Nearly a Posting Virtuoso

It sounds like a registry problem to me. I would get hijack this (http://www.spychecker.com/program/hijackthis.html) shut off all browser windows then scan click save log and post it here. I would also get something like registry mechanic. or if you want the easy way out then system restore to a day or two before this problem happened then run all those spyware programs.

mikeandike22 18 Nearly a Posting Virtuoso

yes get hijackthis shut down any browser windows then scan. Click save log and post the log here.
here is a good place to download hijack this
http://www.spychecker.com/program/hijackthis.html

mikeandike22 18 Nearly a Posting Virtuoso

than make sure that in your internet explorer connection settings the place where it says lan settings has to be set to auto detect. I though you had dial up.

mikeandike22 18 Nearly a Posting Virtuoso

it really doesnt matter about disk space though. the linux distros i am talking about are just run off the cd. I am sure if you calculations about my ram are right than it will not be able to run it. I will just have to test it out and see.

mikeandike22 18 Nearly a Posting Virtuoso

i have a machine built for windows 95 it has about 500mb or so hard drive space I have a better computer but it is used by my entire family and i've already screwed it up enough and dont need someone yelling at me. So i was wondering if this really old machine with a pentium 2 could run a live cd on it. Right now there is no OS on it and the hardware is probably so ancient that it was developed before i could read. But if i could get the specifications for the hardware then maybe you could tell me wether or not i could run a linux live cd along the lines of SuSe or Slax.

mikeandike22 18 Nearly a Posting Virtuoso

I installed fedora core 1 but at first i had problems (I hadnt installed the bootloader thinking that i had a third party one on my system which i forgot that i had uninstalled) so i ran the xp cd and tried to get windows working but it still couldnt get past this screen that said "GRUB" to run the setup so after about 7 hours i finally figured out the right config for my boot loader and ran it wheni went to check windows it said i needed to run the cd so i had to do a total reinstall of windows but i had t install over the boot loader so now i cant get to linux rather than reinstall linux i was hoping someone could tell me a good third party boot loader or just how to reinstall GRUB.

mikeandike22 18 Nearly a Posting Virtuoso

ok sunflower first why is there 3 IE's running at the same time and next time you shouldn't post your hijack this log in someone else's post especially when your problem does not relate to his.

mikeandike22 18 Nearly a Posting Virtuoso

can you brows the internet at all because if you can than just get mozilla firefox some people dont like it but i think it is definetly the better browser.

mikeandike22 18 Nearly a Posting Virtuoso

C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\Web_Rebates\WebRebates0.exe

O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

all of these look like spyware to me I know for sure that webrebates is but I dont Know about winad. So make a registry backup and then fix these selected problems.

mikeandike22 18 Nearly a Posting Virtuoso

did you try reininstallin or upgrading(if possible) IE first and did you do an ad-aware or spybot S&D scan before running hijack this.

mikeandike22 18 Nearly a Posting Virtuoso

ok your using nero so instead of copying the files onto your computer then burning them why not just open up nero express and select copy entire disc and then put the audio disc in your cd drive and the blank in the cd-rw drive.

mikeandike22 18 Nearly a Posting Virtuoso

did you do an ad-aware and spybot S&D scan before posting your HJT because that might detect it. Oh it would also help if there was a name on the toolbar like mysearch bar or something like that then that would help.

mikeandike22 18 Nearly a Posting Virtuoso

first off all you should check auto detect settings and the only reason i wanted you to check these settings is because you might have had proxy settings that you didnt need but if the proxy connection box is not checked then i dont think it has to do with proxy.

mikeandike22 18 Nearly a Posting Virtuoso

then how should he fix these problems. I myself dont have sp2 and dont need it i get the same security it gives you for IE from the mozilla firefox I have on sp1 its just some people are hardcore IE fans and dislike the feel of mozilla.

mikeandike22 18 Nearly a Posting Virtuoso

open up the task manager by pressing ctrl+alt+delete and click proccesses and end the process mfcwx.exe and then delete it.

mikeandike22 18 Nearly a Posting Virtuoso

http://www.spychecker.com/program/hijackthis.html
goto that link hit download save it then open up the file hit scan then save log and save as .txt file and open it and copy what the document says to this post.

mikeandike22 18 Nearly a Posting Virtuoso

download sp2 and update IE. the browser i like to use is mozilla firefox but switching to that is simply something that you decide. Or you could reinstall IE restore options to windows default or you are just going to have to right click links and say open in new window. I personally prefer tabbed browsing in firefox which allows you to surf multiple pages with less clutter on your desktop.

P.s I almost forgot do an ad-aware scan and a spybot scan then post your hijack this log here maybe someone can figure out how to fix it with that info.

mikeandike22 18 Nearly a Posting Virtuoso

you could set the filetype associations back to default using another program. This link below might help.
http://www.microsoft.com/technet/archive/win98/maintain/assoc.mspx
It talks about understanding file type asscociations in windows 98

mikeandike22 18 Nearly a Posting Virtuoso

do you have the software for the modem. Because usually when you get a computer like i have a dell they send you resource cds and one of them is for the 56k modem built into your computer. You should just go online to whatever company makes your computer and find the driver for windows xp.

mikeandike22 18 Nearly a Posting Virtuoso

ok here are some things that look a little suspicous to me but you might no what they are.

C:\WINNT\system32\keyhook.exe
C:\WINNT\system32\mfcwx.exe
C:\Documents and Settings\Dennis\Application Data\iehl.exe

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\system32\keyhook.exe
O4 - HKLM\..\Run: [mfcwx.exe] C:\WINNT\system32\mfcwx.exe
O4 - HKLM\..\Run: [SysA] C:\winnt\system32\winfoi32.exe

make sure to make a backup of your registry if you want to test these files.

im pretty sure that crunchie who knows everything about hijack this will check out your log soon just wait a little.

mikeandike22 18 Nearly a Posting Virtuoso

ok to boot from the disk you should enter your bios by pressing F2 setup(button may vary you should find it in the top right of your boot screen) then scroll to boot configuration open that up and make the order go cd-rom, floppy, hard drive just make your cd rom drive first the floppy and HD could be in different order. Then restart and when booting your computer press F12(again the button might be different) Now you should have a screen with some options one option should be boot from cd select that and hit enter.

mikeandike22 18 Nearly a Posting Virtuoso

do a virus scan and then post a hijackthis log here.

mikeandike22 18 Nearly a Posting Virtuoso

here is a script that helps figure out morgates I got it from http://javascript.internet.com/

<!-- TWO STEPS TO INSTALL AMORTIZATION CALCULATOR:

1. Copy the coding into the HEAD of your HTML document
2. Add the last code into the BODY of your HTML document -->

<!-- STEP ONE: Paste this code into the HEAD of your HTML document -->

<HEAD>

<!-- This script and many more are available free online at -->
<!-- The JavaScript Source!! http://javascript.internet.com -->
<!-- Original: Paul Baggethun -->
<script src="amortizationCalc11.js" type="text/javascript"></script>
</HEAD>

<!-- STEP TWO: Copy this code into the BODY of your HTML document -->

<BODY>

<!-- This script and many more are available free online at -->
<!-- The JavaScript Source!! http://javascript.internet.com -->
<!-- Original: Paul Baggethun -->
<p>
<table cellpadding=2 style="border:2px outset;background-color:silver;font-size:smaller;">
<tr> <td> Loan Amount
<td> <input id=amount name=amount type=text value=6000 size=10>
<tr> <td> Interest Rate (APR)
<td> <input id=apr name=apr type=text value=10.0 size=10>
<tr> <td> Term (months)
<td> <input id=term name=term type=text value=24 size=10>
<tr> <td align=right colspan=2>
<button onclick="getAmortization(document.getElementById('amount').value,document.getElementById('term').value,document.getElementById('apr').value)" width=100 height=50">Calculate</button>
</table>
</p>
<p>
<textarea id="amortizationtable" rows="16" cols="70" wrap="off" style="visibility:hidden;background-color:silver"></textarea>
</p>

<p><center>
<font face="arial, helvetica" size"-2">Free JavaScripts provided<br>
by <a href="http://javascriptsource.com">The JavaScript Source</a></font>
</center><p>

<!-- Script Size: 1.72 KB -->

mikeandike22 18 Nearly a Posting Virtuoso

do a ad-aware and spybot scan then download hijack this and post your log here.
And if you want you should just switch to mozilla firefox i know some people dont like it but if you dont want to even type the www then you will like firefox because all you have to type is daniweb then it will come to daniweb.com

mikeandike22 18 Nearly a Posting Virtuoso

i installed fedora core 1 recently but during the setup something went wrong and i messed up the boot config so that all it said was GRUB to try and fix this problem i ran the xp restore cd and that didnt work. I later configed the boot loader right and forgot i had ran the setup cd so when i tried to load windows i was prompted to continue setup so then i had to do a clean install of xp and the ir was a problem where now it wont read my ethernet drivers. So i was wondering if their was a way that i could setup the modem on fedora core then switch it over to a router and be able to access the internet in xp through the router.

mikeandike22 18 Nearly a Posting Virtuoso

oh well the setup would not install onto the primary hard drive so they way i partitioned it was 1. select auto partition (check modify partitions) 2. select /boot partition and click edit chech the box that says set to primary partition. 3.when setting up boot loader check the box at the bottom that says configure adavanced boot options 4. chech the circle that says setup MBR on /hda. 5. continue installation 6. reboot and now you can select what you want to load.

mikeandike22 18 Nearly a Posting Virtuoso

hey mastadex did you see this part of the post
"-Cleaning your system:
-Clean the inside of your pc very carefully to make sure that no dust is clogging fans or anything like that.
-uninstall old or useless programs that you dont want or need anymore so that you create space on your computer for better stuff or whatever
-Delete your old registry files: after you uninstall software a registry key is still left behind so you want to get rid of those so that they dont conflict with new registry files. Goto start<run<regedt32 then expand the folders HKEY_CURRENT_USER and HKEY_LOCAL_MACHINE and expand the subfolder software then scroll down the list and delete any registry keys for programs that you have uninstalled (be carefull while doing this and if you downloaded a trial then bought the serial make sure you that you arent going to get that app again or that you have the serial somewhere)."
next time read it before you tell me what i missed

mikeandike22 18 Nearly a Posting Virtuoso

Logfile of HijackThis v1.98.2
Scan saved at 12:11:21 PM, on 8/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\Systmesy.exe
C:\WINDOWS\System32\Microsoftx.exe
C:\WINDOWS\System32\winprocessor.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\winupdater.exe
C:\WINDOWS\System32\ctfmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\ctfmon.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=5.1.5&bm=ho_search
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=5.1.5&bm=ho_home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: …

mikeandike22 18 Nearly a Posting Virtuoso

go into your internet options goto connections and select your default connection and click settings then tell us what you settings look like

mikeandike22 18 Nearly a Posting Virtuoso

I have a dell dimension 8300 desktop and i recently had to reinstall everything and now i cannot install the network adapter for the intel pro/100 VE adapter. The driver doesnt register with my computer. I have to setup an ethernet connection to my dsl modem so i can setup my linksys router. The ethernet light blinks on my modem and ready and power are on but the modem setup doesnt recognize the ethernet connection. Right now i am stuck using crappy usb.

How can i tell what motherboard i am using so that i can update the entire driver for that as well.

You can see my hijack this log here
http://www.daniweb.com/techtalkforums/thread9915.html

mikeandike22 18 Nearly a Posting Virtuoso

here is my new log tell me if i missed anything

Logfile of HijackThis v1.98.2
Scan saved at 9:57:53 PM, on 8/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\Systmesy.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\syscfg32.exe
C:\WINDOWS\System32\Microsoftx.exe
C:\WINDOWS\System32\winupdater.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\ctfmon.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=5.1.5&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.asp?region=all&bw=dsl&cd=5.1.5&bm=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [winprocessor Update] winprocessor.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\uwllem.exe
O4 - HKLM\..\Run: [Systmesy] Systmesy.exe
O4 - HKLM\..\Run: [Configuration Loader] syscfg32.exe
O4 …

mikeandike22 18 Nearly a Posting Virtuoso

yeah crunchie you were right i installed my virus scan software and found 64 trojans and spyware

mikeandike22 18 Nearly a Posting Virtuoso

dont need your help anymore