Happy to help 
-- I need to see the DDS.txt
Run it again and copy and paste that into your reply.
I don't need another attach.txt. Just the DDS.txt.
I will check back as time permits over the weekend.
PP
ah, sorry, here we go, the DDS.txt
thanks...
DDS (Ver_09-10-26.01) - NTFSx86
Run by FSantoso4859 at 8:40:31.51 on Sat 10/31/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_05
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2006.1190 [GMT 8:00]
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
============== Running Processes ===============
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Navision\Client\INSTAL~1.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\msiexec.exe
svchost.exe "C:\WINDOWS\system32\ahuiu.exe"
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\tp4mon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\FSantoso4859\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll
BHO: Megaupload Toolbar: {4e7bd74f-2b8d-469e-ccb0-b130eedbe97c} - c:\progra~1\megaup~1\MEGAUP~1.DLL
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: IeCatch2 Class: {a5366673-e8ca-11d3-9cd9-0090271d075b} - c:\progra~1\flashget\jccatch.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll
TB: Megaupload Toolbar: {4e7bd74f-2b8d-469e-ccb0-b130eedbe97c} - c:\progra~1\megaup~1\MEGAUP~1.DLL
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon
uRun: [P2kAutostart]
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet
mRun: [TrackPointSrv] tp4mon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [PSQLLauncher] "c:\program files\thinkvantage fingerprint software\launcher.exe" /startup
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [<NO NAME>]
mRun: [TpShocks] TpShocks.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\fsanto~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{ccbaa1f7-e5e1-48b2-9ed9-a79c6a37ce78}\Icon3E5562ED7.ico
mPolicies-system: EnableLUA = 0 (0x0)
IE: Download All by FlashGet - c:\program files\flashget\jc_all.htm
IE: Download using FlashGet - c:\program files\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: microsoft.com\mbs
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: psfus - c:\windows\system32\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli psqlpwd
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\fsanto~1\applic~1\mozilla\firefox\profiles\papnscwi.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://hk.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - prefs.js: keyword.enabled - false
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npicaN.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2007-10-16 103472]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2007-10-16 19504]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2008-3-18 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2008-3-18 38528]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2008-3-18 4442]
R2 CiscoVpnInstallService;Cisco Systems, Inc. Installer service;c:\navision\client\INSTAL~1.EXE [2007-4-3 217215]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2009-6-3 80936]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2007-3-14 11152]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [2009-10-21 28672]
S2 dmadminHKHKG-SXF4859N1-SQL;Logical Disk Manager Administrative Service dmadminHKHKG-SXF4859N1-SQL;c:\windows\system32\1033u.exe srv --> c:\windows\system32\1033u.exe srv [?]
S2 dmserverHKHKG-SXF4859N1-SQL;Logical Disk Manager dmserverHKHKG-SXF4859N1-SQL;c:\windows\system32\ahuiu.exe srv --> c:\windows\system32\ahuiu.exe srv [?]
S2 RDSessMgrlanmanworkstation;Remote Desktop Help Session Manager RDSessMgrlanmanworkstation;c:\windows\system32\1037sb.exe srv --> c:\windows\system32\1037sb.exe srv [?]
S2 RDSessMgrW3SVC;Remote Desktop Help Session Manager RDSessMgrW3SVC;c:\windows\system32\1037su.exe srv --> c:\windows\system32\1037su.exe srv [?]
S2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2008-8-21 98304]
S2 SpoolerHKHKG-SXF4859N1-CLASSIC;Print Spooler SpoolerHKHKG-SXF4859N1-CLASSIC;c:\windows\system32\ac3acmq.exe srv --> c:\windows\system32\ac3acmq.exe srv [?]
S3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\drivers\cam1690.sys [2007-8-29 153344]
S3 HeathDev;Application Server for Microsoft Dynamics NAV HeathDev;c:\navision\application server\nassql.exe [2009-8-28 1930360]
S3 HeathDev_2;Application Server for Microsoft Dynamics NAV HeathDev_2;c:\navision\application server 2\nassql.exe [2009-8-28 1930360]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-3-11 42112]
S3 MsDtsServer;SQL Server Integration Services;c:\program files\microsoft sql server\90\dts\binn\MsDtsSrvr.exe [2007-3-3 202096]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 ZSMC302;PLEOMAX PWC-3800;c:\windows\system32\drivers\usbvm302.sys --> c:\windows\system32\drivers\usbvm302.sys [?]
S4 HKHKG-SXF4859N1-CLASSIC;Microsoft Dynamics NAV Application Server HKHKG-SXF4859N1-CLASSIC;c:\program files\microsoft dynamics nav\application server\nas.exe [2008-2-14 1860728]
S4 HKHKG-SXF4859N1-SQL;Microsoft Dynamics NAV Application Server HKHKG-SXF4859N1-SQL;c:\program files\microsoft dynamics nav\application server\nassql.exe [2008-2-14 1930360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2009-1-13 14976]
=============== Created Last 30 ================
2009-10-27 11:11:08 32256 ----a-w- C:\Item Create 01.xls
2009-10-27 11:11:08 100864 ----a-w- C:\Item Amend Test Case.xls
2009-10-26 15:31:30 121344 ----a-w- C:\Outstanding Task List.xls
2009-10-23 12:57:38 0 d-----w- c:\program files\WinSCP
2009-10-21 14:33:39 43520 ----a-w- c:\windows\system32\libusb0.dll
2009-10-21 14:33:39 28672 ----a-w- c:\windows\system32\drivers\libusb0.sys
2009-10-21 14:33:39 0 d-----w- c:\program files\LibUSB-Win32
2009-10-21 14:29:00 933888 ----a-w- c:\windows\system32\SENXPCTL.OCX
2009-10-21 14:29:00 212240 ----a-w- c:\windows\system32\RICHTX32.OCX
2009-10-21 14:28:59 65536 ----a-w- c:\windows\system32\device.OCX
2009-10-21 14:28:59 32768 ----a-w- c:\windows\system32\Bar.OCX
2009-10-21 14:28:59 224016 ----a-w- c:\windows\system32\tabctl32.OCX
2009-10-21 14:28:59 140096 ----a-w- c:\windows\system32\COMDLG32.OCX
2009-10-21 14:28:59 0 d-----w- c:\program files\QuickFreedom
2009-10-21 14:26:12 0 d-----w- c:\docume~1\alluse~1\applic~1\iPodtoComputer
2009-10-21 14:25:49 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2009-10-21 14:25:48 6144 ----a-w- c:\windows\system32\ff_acm.acm
2009-10-21 14:25:44 499712 ----a-w- c:\windows\system32\MSVCP71.DLL
2009-10-21 14:25:44 1060864 ----a-w- c:\windows\system32\MFC71.DLL
2009-10-21 14:25:41 0 d-----w- c:\program files\Cucusoft
2009-10-21 14:23:35 0 d-----w- c:\docume~1\fsanto~1\applic~1\GetRightToGo
2009-10-21 13:53:13 0 d-----w- c:\windows\system32\XPSViewer
2009-10-21 13:51:57 117760 ------w- c:\windows\system32\prntvpt.dll
2009-10-21 13:51:56 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-21 13:51:56 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-21 13:51:56 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-21 13:51:56 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-10-21 13:51:56 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-21 13:51:56 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-10-21 13:51:56 0 d-----w- C:\36300c4706e967932a170e731a941f
2009-10-21 13:51:14 0 d-----w- c:\windows\SxsCaPendDel
2009-10-17 14:00:02 0 d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
2009-10-16 08:53:49 104 --s-a-w- c:\windows\system32\440199740.dat
2009-10-15 01:57:45 9254180 ----a-w- C:\Item Master Templates_20091008_Item - Some Fields + 1500 error records.xlsx
2009-10-12 03:23:35 0 d-----w- c:\program files\Millennium Trader 4
2009-10-09 02:36:29 0 d-----w- c:\docume~1\fsanto~1\applic~1\Malwarebytes
2009-10-09 02:36:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-09 02:36:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-09 02:36:21 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-09 02:36:20 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-05 15:39:57 0 d-----w- c:\program files\common files\Deterministic Networks
2009-10-02 12:24:05 0 d-----w- c:\program files\Microsoft Office Outlook Connector
2009-10-02 12:23:06 0 d-----w- c:\program files\Microsoft
==================== Find3M ====================
2009-09-13 14:44:22 64796 ---ha-w- c:\windows\system32\mlfcache.dat
2009-08-28 11:42:52 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-06 11:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 11:23:46 215920 ----a-w- c:\windows\system32\muweb.dll
2006-02-28 12:00:00 61952 --sh--r- c:\windows\system32\1037su.exe
2006-02-28 12:00:00 61952 --sh--r- c:\windows\system32\ac3acmq.exe
2006-02-28 12:00:00 61952 --sh--r- c:\windows\system32\ahuiu.exe
============= FINISH: 8:41:34.43 ===============