kevin wood 29 Posting Whiz

i worked this out a few days ago forgot to come back and post my answer. to get the gotoAndPlay to work how i wanted it to i had to tell the playhead which level i wanted it to gotoAndPlay on, the code which worked for me is as follows

on (release) {
	_level0.gotoAndPlay("_about");
}
kevin wood 29 Posting Whiz

thanks for the reply i will have a go at getting that to work. thanks again.

kevin wood 29 Posting Whiz

when thinking of what colours you should use you should look into colour blindness as someone already pointed out. from the top of my head i can think of two different types of colour blindness which are protanopia which deals with reds and greens and deutanopia which i think is blues and purples. colour blindness effects how the user will see different shades of colours.

i know from experience that colour blind people can get some shades of gray and blues confused and some say they cannot see the colour purple. so what looks good to you might not be good for people who are colour blind.

kevin wood 29 Posting Whiz

i have set my timeline inside the movie clip up so that i have my frame labels for the up, over and out states. the problem i am having is that when the mouse moves over the movie clip it is not playing the animation.

i have set the script up on the main timeline so that the animation should play but it is not. the code i have used on the main timeline looks like this

this.prof_mc.onRollOver = function() {
	prof_mc.gotoAndPlay("over");
};
this.prof_mc.onRollOut = function() {
	prof_mc.gotoAndPlay("out");
};

i have put a on release function on the movie clip on the main stage and this is not working. when the movie clip is pressed once it is playing the over state from inside the movie clip and when it is pressed again it plays the out state of the movie clip which should not be happening.

the on release on the movie clips has been scripted like this

on (release){
	gotoAndPlay("_about");
}

i have set up the timeline with frame labels for the individual pages with "_about" being one of the pages i have set up.

if someone could tell me where i have gone wrong that would be great as i have not a clue why it is behaving in this way.

kevin wood 29 Posting Whiz

is it possible tpo have a movie clip use the gotoAndPlay function without converting it to a button.

kevin wood 29 Posting Whiz

the movie that i want to play is on a different part of the screen. i want to role the mouse over one object and another object will start to play.

kevin wood 29 Posting Whiz

how can i get a rollover to target another movie.

i have set up some text to use as a link inside a flash website i am building but i have a small box next to it which i want to animated when the mouse rollover the text.

i have set the small box to be a movie and inside this movie clip i have set the up over and out states for the animation.

i am not sure how to get the movie to play when the text is rollover.

if someone can point me in the direction of a tutorial that would be great.

kevin wood 29 Posting Whiz

yes it is possible and here is how it is done.

firstly in frame one of the timeline a variable needs to be set. i set this as

var frame : String;

once this has been done you next need to add the

stop();

in the frame where you want the play head to pause. As mine then had the animation after the pause for the page exit, you will need to add this code to frame at the end of the page.

stop();
if(_level0.frame != undefined){
_level0.gotoAndPlay(_level0.frame); // or gotoAndStop(_level0.frame_to_goto)... If you want it to stop on that frame...
}else{
trace("An error as occured!");
}

this section of the code is looking for a variable to be sent to it from the button being clicked on. The code to get the variable to be sent will obviously go on to the button.

the code which goes on the button is this

on(release){
// set the variable...
_level0.frame = "_page1"; // assuming that's the frame's label...
//play the timeline from the next frame to frame 25...
play();
}

this will then pause where you want it to pause and when a button is pressed it will play the animation for the page exit then take the user to the page the have requested depending on which button is pressed.

just to clear things up a bit for any novice flashers i had a layer for the actions where all the code script went …

peter_budo commented: Good job Kevin +10
kevin wood 29 Posting Whiz

is it possible to get flash to play x amount of frames before completing the gotoAndPlay from a button click.

kevin wood 29 Posting Whiz

is there a need to run a anti virus scanner on a mac running os 9.1

if there is is there any good free anti virus scanners out there available.

kevin wood 29 Posting Whiz

anyone no of any good free anti virus programs for the mac os 9.1?

kevin wood 29 Posting Whiz

i am all clean now?

if so thanks for all your help.

kevin wood 29 Posting Whiz

i just logged on to the mac and it crashed again once it had restarted i logged on again and it was ok.

when i first log on to the computer all the text that goes with the short cuts on the desktop have a shadow behind them and then it gradually starts to disappear? dont no why it is doing that as that is something new.

also the trojan downloader that was in acrobat reader has that gone now.

do you know of any good free anti virus programs for the mac with os 9.1

kevin wood 29 Posting Whiz

the adobe acrobat reader in the professional version so i need to keep that version on the comp. here are my logs i had to leave the comp on friday before they had chance to finish on scans.

Malwarebytes' Anti-Malware 1.24
Database version: 1026
Windows 5.1.2600 Service Pack 2

15:49:36 08/08/2008
mbam-log-8-8-2008 (15-49-36).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 248331
Time elapsed: 3 hour(s), 7 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:27:02, on 11/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

kevin wood 29 Posting Whiz

thanks for the reply i have tried to remove all of norton and symantec i am now searching to see if anything is left. i have finished work for the day now so i will run what you have asked and post back in the morning and let you now how it gets on.

i will stop the unnesaccery start ups in the morning.

thanks for all your help on this. my comp might eventually be infection free.

o and another thing bridge does not work any more since the virus's found where removed. that will have to be reinstalled.

kevin wood 29 Posting Whiz

I have tried to recreate the error but i can connect to the mac know with no porblems. this is all the information i could get.

Source : System error

Catagory : 102

Event ID : 1003

Type : Error

Error code 1000008e, parameter1 c0000005, parameter2 806ee753, parameter3 b6ec3acc, parameter4 00000000.

this was from the bottom of the error log window this is the data in words

0000: 74737953 45206d65 726f7272 72452020
0010: 20726f72 65646f63 30303120 38303030
0020: 50202065 6d617261 72657465 30632073
0030: 30303030 202c3530 65363038 33353765
0040: 3662202c 61336365 202c6363 30303030
0050: 30303030

i will get rid of the SDfix backups now.

kevin wood 29 Posting Whiz

when ever i try to connect to the mac across the network my pc restarts and then tells me it has recovered from a serious error.

kevin wood 29 Posting Whiz

here are my logs

Malwarebytes' Anti-Malware 1.24
Database version: 1026
Windows 5.1.2600 Service Pack 2

15:29:20 06/08/2008
mbam-log-8-6-2008 (15-29-20).txt

Scan type: Full Scan (C:\|E:\|)
Objects scanned: 250594
Time elapsed: 3 hour(s), 35 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Adobe\Acrobat 6.0\Acrobat\PDF417Encoder.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{CB2D7211-9D54-424D-9E9C-8E062E202775}\RP230\A0073489.vxd (Adware.Winad) -> Quarantined and deleted successfully.
C:\WINDOWS\BMbf924418.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\1doc2pdf.dll (Trojan.Agent) -> Quarantined and deleted successfully.

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3329 (20080805)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=10436f4d3802054697ec13c60b68f2f0
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-08-05 05:35:44
# …

kevin wood 29 Posting Whiz

that is where i was going to post the logs from the scans i have completed. i just wanted to know if a network could have a virus not just the computers attached to the network.

kevin wood 29 Posting Whiz

is it possible to have a virus on a network.

every time i try to connect to a mac computer over the network from my pc my computer restarts?

anyone know what could be causing this.

i have followed all the instructions from the sticky posts above and i am just waiting for Malwarebytes Anti Malware to finish running now before i post my logs up. (usually takes about 3 hours to run).

i have ran the eset online scanner, dss scanner, microsoft malicious software removal tool, atf cleaner and the hijack this misc tools section. all these logs will be uploaded soon

kevin wood 29 Posting Whiz

my comp has just started to randomly restart on me. it started over the weekend whn my manager was on the comp and tried to access another computer on the network (the comp was a mac running os 9) and it restarted. it has now just done it to when i was in the middle of using flash. could this be a virus of some sort? here is a print out of my hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:33:01, on 04/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\iKnowPS\iKnowPS.exe
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\dumprep.exe
C:\spywarebegone\SpywareBeGone.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
C:\PROGRA~1\MUSICM~1\Common\COMPON~1\MMCOMP~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dwwin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

kevin wood 29 Posting Whiz

they were not quite what i was looking for but thanks for the reply. i need to do what this example does but this is not written in english so i cannot begin to work through what is going on with each of the elements.

http://www.flashkit.com/movies/Scripting/Scrolling/Scroll_H-Massimo_-11241/index.php

if you know of a tutorial in english that can show me how to do this that would be great.

kevin wood 29 Posting Whiz

from what i was reading what it does is, say if you had a column called cust_num and wanted to display this to someone who has not set the table up and did not know what the column names where for or what they meant you would use the AS function to give the column names a more understandable name like customer numbers instead of cust_num.

kevin wood 29 Posting Whiz

i want to make a flash image viewer that is always scrolling horizontally across the screen. when the user move the mouse over it stops playing and when the image is clicked the image increases in size.

i have found numerous examples of image viewers but not what i want. can someone please point me in the direction of a good tutorial. making the images increase in size i know how to do it is the setting up of the scrolling section i need help with.

kevin wood 29 Posting Whiz

found out what it means now it is pseudo names for the columns. What it does is gives the names of the columns being used more suitable names to make it easier for people to know what data the column is holding when displaying the information

kevin wood 29 Posting Whiz

i have just had to go into the backend of an old site to fix the mysql db as some had deleted the wrong db. i have got most of it working again now but did not know what this line of code is doing.

$sql = "SELECT id,thumb,image,designer,title,(total/freq) AS score FROM shirts ORDER BY score DESC";

i know it is telling it to select the information out of the table and from which table but i have not used the AS condition before and i cannot find an explanation of this anywhere.

if someone could point me in the direction of a good explanation of how this condition effects the sql statement that would be great

kevin wood 29 Posting Whiz

thanks for all your help last time and thanks for the reply.

kevin wood 29 Posting Whiz

my comp was very badly infected a couple of weeks ago i am now just checking to see if i am still all in the clear and my comp is infection free. here is a copy of my hijack This log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:53, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\iKnowPS\iKnowPS.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\spywarebegone\SpywareBeGone.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 …

kevin wood 29 Posting Whiz

thanks for the reply you are also a great help

kevin wood 29 Posting Whiz

thanks for the reply. sorry i took so long to get back i am in the middle of creating a user guide for the email system. so if i run that code and where it says local host could i change that to the host name and it would run as intended.

kevin wood 29 Posting Whiz

is it possible to create a new db on the server with a new user name and password without having to login to the phpmyadmin section on the control panel on the server?

i have had a look around but all the information i have found is already using a user name and passwrod to make the connection. I want to be able to create everything from the beginning. could you point me in the right direction of a good tutorial on this.

kevin wood 29 Posting Whiz

i am just trying to replicate the error now i will get post my results back in a minute.

kevin wood 29 Posting Whiz

when i didint have the mysql_errno in and just the mysql_error it was saying that the error was on line 15 which was the fourth one down in the table create syntax. i got the tables set up in the end but i had to log on to the control panel to set it up.

kevin wood 29 Posting Whiz

i am trying to set up this db and i am getting a parse error which it says it is on line 24 i cannot see the error. help need

$sql="CREATE TABLE IF NOT EXISTS `merc_users` (
			
			`****` int not null,
			`******` varchar (250) not null,
			`*****` varchar(250) not null,
			`******` varchar(250) not null,
			`*****` varchar(250) not null,
			`******` varchar (250) not null,
			`*******` varchar(250) not null,
			`****` varchar(250) not null,
			`****` varchar(250) not null,
			`******` varchar (250) not null,
			`********` varchar(250) not null,
			`******` int not null
		)";	
		mysql_query($sql) or die (mysql_error() mysql_errno()); (line 24)
kevin wood 29 Posting Whiz

have had to move some file across from one server to another and i am now getting access denied for user. it also says it could not connect to the server.

i have changed the site path so it is now the address where the files have benn moved across to.

kevin wood 29 Posting Whiz

the problem i was having with loading the page was i had saved the page as a .htm and flash would only load the page if it was saved with a .html.

it now works with the code

getUrl("http//www.the-page-i-want.com/index1.html
kevin wood 29 Posting Whiz

is it possible to get this function in flash to load a page without using a on release function. I want to make the flash file i have created to load a html page once the end of the timeline is reached.

if i use it wil out the on release function i just keep getting the error undifined url. the code i have used is

getURL("http://www.the-page-i-want.com/", "_self"
kevin wood 29 Posting Whiz

thanks for the reply.

kevin wood 29 Posting Whiz

i have an image of a teady bear and i wanted to know if i could set up some random animation on this image.

What i want the image to do is move its are or blink an eye, only slight movements but for then to occur randomly. i know i could just set up a timeline so the image animates how i want along a set amount of time, but i would like it to randomly move in different ways so there is no set pattern to the movement,

if anyone could point me in the direction of a good tutorial that would be great or if someone can shoot me out the sky and tell me it cannot be done would also be good.

kevin wood 29 Posting Whiz

thanks for all your help.

kevin wood 29 Posting Whiz

The PC is working fine now i will run some checks over the weekend and get back to you on monday. thanks for all your help up to now. the latest hijackthis log has been uploaded for you. the tw*t URLSearchHook is still there i wil look at how to remove this myself over the weekend also.

kevin wood 29 Posting Whiz

microsoft anti-apyware was out of date so i just uninstalled it.

kevin wood 29 Posting Whiz

i already had ATF cleaner installed. Ran that and HijackThis the urkhook still there. here is the log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:40:40, on 27/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\sistray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat …

kevin wood 29 Posting Whiz

the comp loads fine firefox opens a little bit quicker too. here is the log the URLHook is back

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:15:16, on 27/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\iKnowPS\iKnowPS.exe
C:\spywarebegone\SpywareBeGone.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} …

kevin wood 29 Posting Whiz

sorry that was just me trying to split it down to fit

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03:40, on 27/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\iKnowPS\iKnowPS.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\WINDOWS\System32\svchost.exe
C:\spywarebegone\SpywareBeGone.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wuauclt.exe

kevin wood 29 Posting Whiz

HJT log

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0ae5b2c8-22ca-420c-b799-a1a506d436be} - C:\WINDOWS\System32\iifdcYst.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Miramar Systems, Inc.] C:\Program Files\Miramar\PC MACLAN\atmsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [iKnowPS] C:\Program Files\iKnowPS\iKnowPS.exe
O4 - HKCU\..\Run: [Spyware Begone] "C:\spywarebegone\SpywareBeGone.exe" -FastScan

kevin wood 29 Posting Whiz

the other threads are not displaying properly on my comp i am getting a white space where the replies and post are meant to be. here is the combo fix log without the snap shot section

ComboFix 08-06-20.4 - Admin 2008-06-27 10:44:55.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.431 [GMT 1:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMbf924418.xml
C:\WINDOWS\pskt.ini
.
(((((((((((((((((((((((((   Files Created from 2008-05-27 to 2008-06-27  )))))))))))))))))))))))))))))))
.
2008-06-27 10:16 . 2008-06-13 14:10 272,128 -----c---   C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-27 10:09 . 2008-06-27 10:18 <DIR>    d--------   C:\WINDOWS\LastGood
2008-06-27 09:39 . 2004-08-04 08:56 221,184 --a------   C:\WINDOWS\system32\wmpns.dll
2008-06-27 09:37 . 2008-06-27 09:37 <DIR>    d--------   C:\WINDOWS\provisioning
2008-06-27 09:37 . 2008-06-27 09:37 <DIR>    d--------   C:\WINDOWS\peernet
2008-06-26 16:47 . 2004-08-04 06:41 404,990 ---------   C:\WINDOWS\system32\drivers\slntamr.sys
2008-06-26 16:46 . 2004-08-04 08:56 1,737,856   ---------   C:\WINDOWS\system32\mtxparhd.dll
2008-06-26 16:45 . 2004-08-04 08:56 380,416 ---------   C:\WINDOWS\system32\irprops.cpl
2008-06-26 16:44 . 2004-08-04 06:41 1,041,536   ---------   C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-06-26 16:43 . 2004-08-04 08:56 1,888,992   ---------   C:\WINDOWS\system32\ati3duag.dll
2008-06-26 16:42 . 2004-08-04 08:56 4,255   ---------   C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-06-26 16:42 . 2004-08-04 08:56 3,967   ---------   C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-06-26 16:42 . 2004-08-04 08:56 3,775   ---------   C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-06-26 16:42 . 2004-08-04 08:56 3,711   ---------   C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-06-26 16:42 . 2004-08-04 08:56 3,647   ---------   C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-06-26 16:42 . 2004-08-04 08:56 3,615   ---------   C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-06-26 16:42 . 2004-08-04 08:56 3,135   ---------   C:\WINDOWS\system32\drivers\adv08nt5.dll
2008-06-26 16:27 . 2005-10-20 23:20 1,082,368   --a------   C:\WINDOWS\system32\esent.dll
2008-06-26 15:35 . 2008-06-27 10:37 <DIR>    d--h-----   C:\WINDOWS\$hf_mig$
2008-06-26 15:35 . 2005-06-28 10:21 22,752  --a------   C:\WINDOWS\system32\spupdsvc.exe
2008-06-26 14:41 . 2008-06-26 14:41 …
kevin wood 29 Posting Whiz

the log will not show up proplerly it is disappearing on upload of post

kevin wood 29 Posting Whiz

log continued

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0ae5b2c8-22ca-420c-b799-a1a506d436be} - C:\WINDOWS\System32\iifdcYst.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Miramar Systems, Inc.] C:\Program Files\Miramar\PC MACLAN\atmsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [iKnowPS] C:\Program Files\iKnowPS\iKnowPS.exe
O4 - HKCU\..\Run: [Spyware Begone] "C:\spywarebegone\SpywareBeGone.exe" -FastScan

kevin wood 29 Posting Whiz

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:03:40, on 27/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\keyhook.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\iKnowPS\iKnowPS.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Miramar\PC MACLAN\ATMsg.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Miramar\PC MACLAN\ATSERVER.EXE
C:\Program Files\Miramar\PC MACLAN\ATSPOOL.EXE
C:\WINDOWS\System32\svchost.exe
C:\spywarebegone\SpywareBeGone.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Admin\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wuauclt.exe