Hi
I am pulling whatever hair I have left out, please help!
I picked up scripting messages on desktop and was getting unwanted re-directs to sites in IE.
Installed and ran Malwarebytes- cleaned up 12 viruses.
Got prob again, installed and ran Avast, and ran various different scans also in Safe Mode, it picked up viruses on different scans, first lot classes in Sun Java cache,last lot were jar_cache/3132.tmp and A0057113.exe.
Have also run windows cmd sfx, and uninstalled IE!
I also get error missing Dll box pop up, if its related ‘DLGCtime.dll, missing entry Run DLLEntry’ in sys32 spool drivers, and still the IE script box which has links to various and chaNGING DODGY WEBSITES!
jOEYM
Installed and ran Malwarebytes- cleaned up 12 viruses.
can you post the scan log
try clearing your browser cache/temp files
TFC - Temp File Cleaner by OldTimer
http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/
TFC requires a reboot immediately after running. Be sure to save any unsaved work before run
Then avast boot scan http://spgscott.wordpress.com/tutorials/avast-boot-time-scan/
Hi
sorry for delay, and stupid question no.1: where are the logs saved to? I’m on xp
open Malwarebytes, and look at the tab`s on top of the program…nr #5 from left with the name “LOG” 
no.1
Malwarebytes’ Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6459
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
28/04/2011 01:17:29
mbam-log-2011-04-28 (01-17-29).txt
Scan type: Full scan (C:|D:|F:|)
Objects scanned: 331498
Time elapsed: 1 hour(s), 40 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{19127AD2-394B-70F5-C650-B97867BAA1F7} (Backdoor.Bot) → Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{19127AD2-394B-70F5-C650-B97867BAA1F7} (Backdoor.Bot) → Quarantined and deleted successfully.
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Backdoor.Bot) → Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Backdoor.Bot) → Quarantined and deleted successfully.
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{494E6CEC-7483-A4EE-0938-895519A84BC7} (Backdoor.Bot) → Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{494E6CEC-7483-A4EE-0938-895519A84BC7} (Backdoor.Bot) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\net (Trojan.Agent) → Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run{A31421F1-598E-668D-E99F-9349AD022D52} (Trojan.ZbotR.Gen) → Value: {A31421F1-598E-668D-E99F-9349AD022D52} → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) → Value: UID → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\net (Trojan.Agent) → Value: net → Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit (Hijack.UserInit) → Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (userinit.exe) → Quarantined and deleted successfully.
Folders Infected:
c:\winntse.bin (Trojan.SpyEyes) → Delete on reboot.
c:\WINDOWS\system32\lowsec (Stolen.data) → Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\Joe\local settings\Temp\jar_cache52198.tmp (Trojan.FakeAlert) → Quarantined and deleted successfully.
c:\documents and settings\Joe\local settings\Temp\jar_cache9633.tmp (Spyware.Passwords.XGen) → Quarantined and deleted successfully.
c:\system volume information_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp363\a0055898.exe (Spyware.Passwords.XGen) → Quarantined and deleted successfully.
c:\winntse.bin\winntse.bin.exe (Spyware.Passwords.XGen) → Quarantined and deleted successfully.
c:\winntse.bin\config.bin (Trojan.SpyEyes) → Quarantined and deleted successfully.
c:\WINDOWS\system32\lowsec\local.ds (Stolen.data) → Quarantined and deleted successfully.
c:\WINDOWS\system32\lowsec\user.ds (Stolen.data) → Quarantined and deleted successfully.
if you update Malwarebytes an run a quick scan, is the log clean ?
Is your problem gone ?
p.s. I suggest you to change all your accounts passwords that you have had saved in your browsers/mail clients or FTP programs 
Updated and running now, but the last couple of scans using MWB have been clean, and avast has picked up stuff, I guess the update may capture something…
nope, nothing…