Hi again
I followed all the steps but i wasn't quite sure what you meant in step 8.
But the desktop screen is there still. I have managed to block that before somehow by searching the files and folders, then blocking it in screen properties on the desk top, but it always comes back.
I think the pop up that appears on the tool bar is gone though.
Here are the active scan and hijack logs,
Logfile of HijackThis v1.99.1
Scan saved at 2:07:30 PM, on 23/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Vet\isafe.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Vet\VetTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Vet\VetMsg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Simon\My Documents\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com.au/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.optusnet.com.au/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer from OptusNet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 0;<local>
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3100] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3100" /O6 "USB001" /M "Stylus CX3100"
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
O4 - HKCU\..\Run: [EPSON Stylus CX3100] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "C:\WINDOWS\system32\E_S191.tmp"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au/
O16 - DPF: JT's Blocks -
http://download.game...ts/y/blt1_x.cabO16 - DPF: Video Poker -
http://download.game...ts/y/vpt0_x.cabO16 - DPF: Yahoo! Backgammon -
http://download.game...nts/y/at0_x.cabO16 - DPF: Yahoo! Go Fish -
http://download.game...nts/y/zt3_x.cabO16 - DPF: Yahoo! Literati -
http://download.game...nts/y/tt3_x.cabO16 - DPF: Yahoo! MahJong -
http://download.game...nts/y/ot0_x.cabO16 - DPF: Yahoo! Poker -
http://download.game...nts/y/pt3_x.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://jcs.chat.dcn....v45/yacscom.cabO16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} -
http://akamai.downlo...thv32_EN_XP.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) -
http://zone.msn.com/...me/ZAxRcMgr.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabO16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) -
http://zone.msn.com/.../default/gf.cabO16 - DPF: {D7B59209-0ED9-4986-BD4A-527BE836C6B2} -
http://akamai.downlo...ICE_1046_XP.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://zone.msn.com/...aploader_v5.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
http://us.dl1.yimg.c...ebio5_1_6_0.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{1D4B7958-8143-475D-A453-E6448CFF36F0}: NameServer = 203.2.75.132 198.142.0.51
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe
Incident Status Location
Adware:adware/cws.searchmeup Not desinfected C:\WINDOWS\SYSTEM32\dsmanager.dll
Dialer:dialer.b Not desinfected C:\WINDOWS\SYSTEM32\EGCOMSERVICE2.dll
Adware:adware/sahagent Not desinfected C:\WINDOWS\SYSTEM32\SHAgentNew.dll
Adware:adware/topspyware Not desinfected C:\WINDOWS\SYSTEM32\spoolsrv32.exe
Adware:adware/addestroyer Not desinfected C:\WINDOWS\SYSTEM32\SWRT01.dll
Adware:adware/keenvalue Not desinfected C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho
Adware:adware/quicksearch Not desinfected C:\PROGRAM FILES\QuickSearch
Adware:adware/sidesearch Not desinfected C:\Documents and Settings\Simon\Application Data\Lycos
Adware:adware/virtualbouncer Not desinfected Windows Registry
Virus:Trj/Downloader.gen Disinfected C:\Documents and Settings\Simon\My Documents\hijackthis\backups\backup-20051223-133536-788.dll
Spyware:Spyware/New.net Not desinfected C:\Program Files\filesubmit\doublestriketh.zip\NNEZTA388.exe
Adware:Adware/QuickSearch Not desinfected C:\Program Files\filesubmit\doublestriketh.zip\TBEZA127Q.exe
Dialer:Dialer.JI Not desinfected C:\WINDOWS\ExeDialer.exe
Adware:Adware/VirtualBouncer Not desinfected C:\WINDOWS\system32\BO2802040128.exe
Adware:Adware/CWS.Searchmeup Not desinfected C:\WINDOWS\system32\dsmanager.dll
Dialer:Dialer.B Not desinfected C:\WINDOWS\system32\EGCOMSERVICE2.dll
Dialer:Dialer.B Not desinfected C:\WINDOWS\system32\EGCOMSERVICE_1044.dll
Dialer:Dialer.VL Not desinfected C:\WINDOWS\system32\EGCOMSERVICE_1046.dll
Adware:Adware/SAHAgent Not desinfected C:\WINDOWS\system32\SHAgentNew.dll
Adware:Adware/CWS.Searchmeup Not desinfected C:\WINDOWS\system32\spoolsrv32.exe
Adware:Adware/CWS.Searchmeup Not desinfected C:\WINDOWS\system32\srpcsrv32.dll
Adware:Adware/VirtualBouncer Not desinfected C:\WINDOWS\system32\SWRT01.dll
Adware:Adware/CWS.Searchmeup Not desinfected C:\WINDOWS\system32\txfdb32.dll
Adware:Adware/SAHAgent Not desinfected C:\WINDOWS\system32\xmltok.dll
Thanks again for your prompt reply.
Del