Did all that, still having the same problems. Desktop wallpaper is still replaced with that link.
Logfile of HijackThis v1.99.0
Scan saved at 1:11:27 AM, on 2/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\hicom.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\938664.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alex\Desktop\HiJack This\HijackThis.exe
F3 - REG:win.ini: run=C:\WINDOWS\inetm\services.exe
O1 - Hosts: 64.91.255.87
www.dcsresearch.comO2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetm\services.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetm\services.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: 938664.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (GTDownloaderCtrl Class) -
http://inst.c-wss.com/78/html/gtdownlr.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/018f049977d5f7...ip/RdxIE601.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co...b?1106783608342O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
http://www.bitdefender.com/scan/Msie/bitdefender.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cabO21 - SSODL: eplrr - {655D066F-0B8A-40FA-BFDF-9B452FAD6DB9} - C:\WINDOWS\System32\eplrr3.dll
O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Manageer Network Connections - Unknown - C:\WINDOWS\System32\telcmd.exe (file missing)
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sub Connections - Unknown - C:\WINDOWS\System32\shmyga.exe
O23 - Service: Working Network Connections - Unknown - C:\WINDOWS\System32\hicom.exe
ScanDump
Scan Control Dumped @ 17:33:10 08-02-05
RegVal Trace: TrojanDownloader.Win32.Keyw: HKEY_CURRENT_USER
File: Software\Microsoft\Windows\CurrentVersion\Run [xp_system=C:\WINDOWS\inetm\services.exe]
RegVal Trace: TrojanDownloader.Win32.Keyw: HKEY_LOCAL_MACHINE
File: Software\Microsoft\Windows\CurrentVersion\Run [xp_system=C:\WINDOWS\inetm\services.exe]
Positive identification: TrojanProxy.Win32.Agent.cx1
File: c:\windows\system32\telcmd.exe
Positive identification (DLL): Adware.BiSpy.t (dll)
File: c:\documents and settings\alex\desktop\hijack this\backups\backup-20050103-170630-486.dll
Positive identification (DLL): Adware.Adstart.c2 (dll)
File: c:\documents and settings\alex\desktop\hijack this\backups\backup-20050103-170630-660.dll
Positive identification (embedded in file): Trojan.Win32.Delf.cf (Unpacked)
File: c:\documents and settings\alex\desktop\hijack this\backups\backup-20050103-170630-767.dll
Positive identification (DLL): Trojan.Win32.Delf.cf8 (dll)
File: c:\documents and settings\alex\desktop\hijack this\backups\backup-20050103-170630-767.dll
Positive identification: Trojan.Win32.Delf.cf8
File: c:\documents and settings\alex\local settings\temp\27vc.sys
Positive identification (embedded in file): Trojan.Win32.Delf.cf (Unpacked)
File: c:\documents and settings\alex\local settings\temp\temp.fr7914
Positive identification (DLL): Trojan.Win32.Delf.cf8 (dll)
File: c:\documents and settings\alex\local settings\temp\temp.fr7914
Positive identification (embedded in file): Trojan.Win32.Delf.cf (Unpacked)
File: c:\documents and settings\alex\local settings\temp\temp.fr855b
Positive identification (DLL): Trojan.Win32.Delf.cf8 (dll)
File: c:\documents and settings\alex\local settings\temp\temp.fr855b
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp10.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp13.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp17.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp19.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp1c.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp4.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmp7.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmpa.tmp
Positive identification: TrojanProxy.Win32.Small.ah2
File: c:\documents and settings\alex\local settings\temp\tmpd.tmp
Positive identification (embedded in file): Adware.DelphinMediaViewer.c
File: c:\documents and settings\alex\local settings\temp\vmstmp\vmstmp.exe
Positive identification (DLL): Adware.MiniBug (dll)
File: c:\program files\aws\weatherbug\minibugtransporter.dll
Positive identification: Trojan.Win32.Delf.cf8
File: c:\windows\27vc.sys
Positive identification: Worm.Delf.i
File: c:\windows\ef.exe
Positive identification (embedded in file): TrojanDownloader.Win32.Delf.dg
File: c:\windows\pd7.exe
Positive identification: TrojanClicker.Win32.Small.cx
File: c:\windows\r.exe
Positive identification: TrojanClicker.Win32.Small.cx
File: c:\windows\s.exe
Positive identification: Adware.BetterInternet
File: c:\windows\bundles\thin-8-1-x-x.exe
Positive identification: TrojanClicker.Win32.Small.cx
File: c:\windows\inetm\pvtkil.exe
Positive identification <Adv>: Suspicious: Microsoft-tagged exe built with Borland compiler
File: c:\windows\inetm\services.exe
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\aaiejcyp.exe
Positive identification: Adware.Adstart.c2
File: c:\windows\system32\blwvrd.exe
Positive identification: Adware.Adstart.b2
File: c:\windows\system32\blwvrf.exe
Positive identification (DLL): TrojanProxy.Win32.Small.ah (dll)
File: c:\windows\system32\eplrr3.dll
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\glklqaaa.exe
Positive identification: Adware.Adstart.c2
File: c:\windows\system32\hqlpdd.exe
Positive identification: Adware.Adstart.b2
File: c:\windows\system32\hqlpdf.exe
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\jglbaaaa.exe
Positive identification (embedded in file): Trojan.Win32.Delf.cf6
File: c:\windows\system32\k5o9o0.dll
Positive identification (DLL): Trojan.Win32.Delf.cf5 (dll)
File: c:\windows\system32\k5o9o0.dll
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\mcdtaaaa.exe
Positive identification: Trojan.Win32.Delf.cf5
File: c:\windows\system32\moneyspm.exe
Positive identification <Adv>: Suspicious: Microsoft-tagged exe built with Borland compiler
File: c:\windows\system32\notepad.exe
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\shxuiiac.exe
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\sydoyaaa.exe
Positive identification: TrojanProxy.Win32.Agent.cx1
File: c:\windows\system32\telcmd.exe
Positive identification: Trojan.Win32.StartPage.qp1
File: c:\windows\system32\vqwomaaa.exe
Positive identification: TrojanClicker.Win32.Agent.bd
File: c:\windows\system32\wtl32a.exe