sounds like we're making progress at least. (hopefully)
Strange about port21fs.exe
I know with Comodo firewall you can view every active process, and terminate and quarantine. While they are quarantined they cannot execute. Comodo also has a HIPS feature (host intrusion prevention system) which prevents new executables from activating without the user's permission. You may have been able to avoid infection with Comodo, I recommend it personally as Ive been using it for about 6 months, and it is totally free and has passed all leak tests at
www.matousec.com
I've never tried any MacAfee products so don't really have any opinions on them.
If HijackThis was able to fix the .dll then that's good.
Regarding the port21fs.exe, I don't know, thats weird that you didn't delete it or fix it with HTJ, but it's no longer showing up. I wonder if it could possibly be a trojan or something that is switching from active to dormant?
I must do the crashing of the me for a while now, I'll check this thread when I am reborn.