Thanks, JP, I'm happy for the help. Per your question, the system is working fine. The only concern is I have something on that is connecting outside post-start up, but which is no longer being detected.
I have just uploaded Attach.txt. Below is the DDS requested (
I just noticed that I did it without disabling any script blocking protection - you'll have to tell me how to do that):
DDS (Ver_09-01-07.01) - NTFSx86
Run by [removed] at 12:37:53.06 on 16/01/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.464 [GMT -5:00]
AV: avast! antivirus 4.8.1296 [VPS 090116-0] *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\BinarySense\HDDlife 3\HDDlifePro.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\BinarySense\HDDlife 3\hldasvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wwSecure.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MagicTune Premium\MagicTune.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bill\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [Window Washer] "c:\program files\webroot\washer\wwDisp.exe"
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [SkyTel] "c:\windows\SkyTel.EXE"
mRun: [RTHDCPL] "c:\windows\RTHDCPL.EXE"
mRun: [Alcmtr] "c:\windows\ALCMTR.EXE"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Norton Ghost 12.0] "c:\program files\norton ghost\agent\VProTray.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\bill\startm~1\programs\startup\hddlife.lnk - c:\program files\binarysense\hddlife 3\HDDlifePro.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ncprot~1.lnk - c:\program files\sec\natural color pro\NCProTray.exe
uPolicies-explorer: NoThemesTab = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - c:\program files\binarysense\hddlife 3\hlAPP.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\bill\applic~1\mozilla\firefox\profiles\oacebevy.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - http:www.google.ca
FF - plugin: c:\program files\google\google updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2007-7-11 38448]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-2 111184]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-7-10 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-7-10 352920]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-2 20560]
R4 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-7-10 155160]
R4 HDDlife HDD Access service;HDDlife HDD Access service;c:\program files\binarysense\hddlife 3\hldasvc.exe [2007-5-25 78175]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2009-1-1 32512]
=============== Created Last 30 ================
2009-01-09 10:03 –d—– c:\program files\common files\Wise Installation Wizard
2009-01-03 00:27 –d—– c:\documents and settings\bill\.housecall6.6
2009-01-02 10:52 –d—– c:\program files\MSXML 4.0
2009-01-01 18:34 –d—– c:\program files\Trend Micro
2009-01-01 18:15 360,448 a——- c:\windows\system32\myodbc3.dll
2009-01-01 18:12 32,512 a——- c:\windows\system32\drivers\npf.sys
2009-01-01 18:11 –d—– C:\AdventNet
2009-01-01 16:54 16,572 a——- C:\replace.cmd
2009-01-01 16:54 16,474 a——- C:\smitfrau.reg
2009-01-01 16:54 3,451 a——- C:\delfiles.cmd
2009-01-01 14:29 –d—– c:\docume~1\alluse~1\applic~1\Uniblue
2009-01-01 14:29 –d—– c:\docume~1\bill\applic~1\Uniblue
2009-01-01 11:39 –d—– c:\docume~1\alluse~1\applic~1\ZoomBrowser
2008-12-26 23:31 244 a—h— C:\sqmnoopt00.sqm
2008-12-26 23:31 232 a—h— C:\sqmdata00.sqm
2008-12-25 11:14 –d—– c:\program files\SEC
2008-12-25 11:14 13,312 a——- c:\windows\system32\drivers\MTictwl.sys
2008-12-25 11:14 –d—– c:\program files\MagicTune Premium
==================== Find3M ====================
2008-12-11 05:57 333,952 a——- c:\windows\system32\drivers\srv.sys
2008-11-10 05:43 410,984 a——- c:\windows\system32\deploytk.dll
2008-10-23 07:36 286,720 a——- c:\windows\system32\gdi32.dll
2008-09-30 22:09 51,544 a——- c:\docume~1\bill\applic~1\GDIPFONTCACHEV1.DAT
2007-08-05 23:32 56 —shr– c:\windows\system32\3E65B116B4.sys
2008-05-13 22:42 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008051320080514\index.dat
============= FINISH: 12:38:21.70 ===============
Bill