I've also posted the logs from running DDS, as was indicated in the initial instructions.
My Root Repeal Log
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/12/31 21:40
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x95613000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:\windows\temp\mcmsc_m2ooaam6jijy7pv
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\sqlite_uxb73x3whdjqa7e
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcafee_rknd9qo6td4fvgm
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\windows\temp\mcmsc_cfh83dbdgh1azxv
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: c:\documents and settings\phil\local settings\temp\etilqs_ttoyuompyu0lxmalcu5k
Status: Allocation size mismatch (API: 4096, Raw: 0)
Path: \\?\C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\*
Status: Could not enumerate files with the Windows API (0x00000003)!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\A0003182.ini
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\A0003183.ini
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\A0003184.old
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\change.log
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\RestorePointSize
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\rp.log
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot
Status: Invisible to the Windows API!
Path: \\?\C:\Documents and Settings\Phil\Local Settings\temp\RarSFX3\*
Status: Could not enumerate files with the Windows API (0x00000003)!
Path: C:\Documents and Settings\Phil\Local Settings\temp\RarSFX3\Offline
Status: Invisible to the Windows API!
Path: \\?\C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\*
Status: Could not enumerate files with the Windows API (0x00000003)!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-3499916212-2798751602-3588590466-1007
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\ComDb.Dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\domain.txt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_MACHINE_SAM
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_MACHINE_SECURITY
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_MACHINE_SOFTWARE
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_MACHINE_SYSTEM
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_.DEFAULT
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-3499916212-2798751602-3588590466-1004
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-3499916212-2798751602-3588590466-1006
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-3499916212-2798751602-3588590466-500
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-3499916212-2798751602-3588590466-1004
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-3499916212-2798751602-3588590466-1006
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-3499916212-2798751602-3588590466-1007
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-3499916212-2798751602-3588590466-500
Status: Invisible to the Windows API!
Path: \\?\C:\Documents and Settings\Phil\Local Settings\temp\RarSFX3\Offline\*
Status: Could not enumerate files with the Windows API (0x00000003)!
Path: \\?\C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\*
Status: Could not enumerate files with the Windows API (0x00000003)!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\$WinMgmt.CFG
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\67MPMHSF\mtiglobal[2].js
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\67MPMHSF\superfish[2].js
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XU4TLFOD\jquery.corner[2].js
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\XU4TLFOD\thickbox[2].js
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YBKE7C2I\jquery.hoverintent.minified[2].js
Status: Visible to the Windows API, but not on disk.
Path: C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YWK6N1RP\jquery.curvycorners.source[1].js
Status: Invisible to the Windows API!
Path: \\?\C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\*
Status: Could not enumerate files with the Windows API (0x00000003)!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\INDEX.BTR
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\INDEX.MAP
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\MAPPING.VER
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\MAPPING1.MAP
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\MAPPING2.MAP
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\OBJECTS.DATA
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Phil\Local Settings\temp\WPDNSE\snapshot\Repository\FS\OBJECTS.MAP
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Philip\Local Settings\Application Data\Microsoft\Messenger\jrdragon40@hotmail.com\SharingMetadata\moogle_powa@hotmail.com\DFSR\Staging\CS{641E71F7-0E5E-20E1-928E-723FEB40917E}\18\4222-{~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.
==EOF==
The DDS Log
DDS (Ver_09-12-01.01) - NTFSx86
Run by Phil at 16:18:21.78 on 01/01/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.505 [GMT -7:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\DOCUME~1\Phil\LOCALS~1\Temp\Temporary Directory 2 for RootRepeal.zip\RootRepeal.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\Phil\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.defaulthomepage.info/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://search.live.com/sphome.aspx
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: {C17590D2-ECB4-4b15-8820-F58798DCC118} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [PhotoShow Deluxe Media Manager] c:\progra~1\ahead\ahead\data\xtras\mssysmgr.exe
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ClearAllHistory] c:\documents and settings\hal\my documents\my videos\cah.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\photosmart\hp share-to-web\hpgs2wnd.exe
mRun: [RemoteControl] "c:\program files\cyberlink dvd solution\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero 7\nero backitup\NBKeyScan.exe"
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideo[inspector]] c:\program files\logitech\video\InstallHelper.exe /inspect
mRun: [LogitechCameraService(E)] c:\windows\system32\ElkCtrl.exe /automation
mRun: [LogitechCameraAssistant] c:\program files\logitech\video\CameraAssistant.exe
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [CXMon] "c:\program files\hewlett-packard\photosmart\photo imaging\Hpi_Monitor.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 5.0\distillr\AcroTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: &Webshots Photo Search - c:\program files\webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim95\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - c:\program files\plotsoft\pdfill\DownloadPDF.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
DPF: {22D4879A-92DB-470D-8A83-E158797D8176} - file://f:\components\Liquid.ocx
DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://spaces.msn.com//PhotoUpload/MsnPUpld.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\kbdsock.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\phil\applic~1\mozilla\firefox\profiles\6i82zj2e.default\
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CID4E7FF8BB-0A5A-4AA3-B764-B39BA9A13E38", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CIDB24F189F-FB14-4EFD-8B9D-217EC6C84EA1", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CID86ED3659-02F6-465D-8F19-A9334614CCC3", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CID5D7F48C0-CB49-4ea6-97D4-04F4EACC2F3B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CID4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CIDA43C6FC7-09F6-4E04-B8E3-683F3BDFEF7C", "AllAccess");
c:\program files\mozilla firefox\defaults\pref\activexFF10.js - pref("capability.policy.default.ClassID.CID4C8D6404-A9F6-4236-8488-6C5732CB3BFA", "AllAccess");
============= SERVICES / DRIVERS ===============
R0 MrFilter;EasyWrite Driver;c:\windows\system32\drivers\MRFilter.sys [2005-5-30 11776]
R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [2005-1-31 4064]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-11-4 214664]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-24 54752]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2006-11-30 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2006-11-30 35272]
R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-11-30 34248]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-11-30 40552]
S2 IcRecUsb;IC Recorder Driver;c:\windows\system32\drivers\IcRecUsb.sys [2006-9-19 17432]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [2005-1-31 16512]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\phil\locals~1\temp\onlinescanner\anti-virus\fsgk.sys --> c:\docume~1\phil\locals~1\temp\onlinescanner\anti-virus\fsgk.sys [?]
=============== Created Last 30 ================
2009-12-31 17:05:37 15 ----a-w- c:\documents and settings\phil\settings.dat
2009-12-30 23:20:12 0 d-----w- c:\program files\ESET
2009-12-30 04:00:48 0 d-----w- c:\documents and settings\phil\DoctorWeb
2009-12-29 00:30:35 0 d-----w- C:\VundoFix Backups
2009-12-29 00:10:43 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-29 00:10:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-29 00:10:41 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-27 13:25:22 0 ----a-w- c:\windows\system32\18467.exe
2009-12-27 12:55:34 1 ----a-w- C:\s
2009-12-27 12:55:03 0 d-sh--w- c:\docume~1\phil\applic~1\SystemProc
2009-12-17 03:04:31 11961 ----a-w- c:\windows\system32\Config.MPF
2009-12-17 02:59:42 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-17 02:59:01 0 d-----w- c:\program files\common files\McAfee
2009-12-17 02:58:59 0 d-----w- c:\program files\McAfee.com
==================== Find3M ====================
2010-01-01 04:25:18 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-12-07 09:22:56 99562 ----a-w- c:\windows\War3Unin.dat
2009-11-30 02:21:18 66408 ----a-w- c:\docume~1\phil\applic~1\GDIPFONTCACHEV1.DAT
2009-11-18 18:03:36 48176 ----a-w- c:\windows\fonts\VNTIME.TTF
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47:28 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47:28 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47:28 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47:28 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47:28 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-12 21:42:18 37376 ----a-w- c:\windows\system32\drivers\hssdrv.sys
2009-11-12 21:42:16 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2009-11-04 23:54:12 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-11-04 23:54:12 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-11-04 23:54:12 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-11-04 23:54:12 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-29 05:38:23 667136 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-09 06:46:13 80476 ----a-w- c:\windows\HPHins08.dat
2007-11-25 16:57:00 604 ---ha-w- c:\program files\STLL Notifier
2004-03-11 20:27:22 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2002-07-27 00:02:06 153088 ----a-w- c:\program files\UNWISE.EXE
2003-03-31 12:00:00 94784 --sh--w- c:\windows\twain.dll
2008-04-14 00:12:07 50688 --sh--w- c:\windows\twain_32.dll
2005-04-08 03:19:36 56 --sh--r- c:\windows\system32\634B638EB3.sys
2008-04-14 00:11:56 1028096 --sha-w- c:\windows\system32\mfc42.dll
2008-04-14 00:12:01 57344 --sha-w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12:01 413696 --sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 00:12:02 551936 --sh--w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12:02 84992 --sha-w- c:\windows\system32\olepro32.dll
2008-04-14 00:12:32 11776 --sh--w- c:\windows\system32\regsvr32.exe
============= FINISH: 16:23:18.12 ===============
I'll await further instructions.
Attached File(s)
-
Attach.txt (10.7K)
Number of downloads: 9
This post has been edited by smartjock99: 02 January 2010 - 12:34 AM

Help
This topic is locked


Back to top





button.
to download the ESET Smart Installer. Save it to your desktop.
button.

, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
button.










