Ben Myers and friends that have helped:

Well. Finally got sometimes to get a copy of Spy Sweeper last Thursday
and loaded on the Computer. It detected it on the Idesk Adware and the
associated files and the registry entries. The Spysweeper log is at the
end of this post. The four files that got indentified by Spy Sweeper
are:
CSVNR.EXE
idemlog.exe
zpmodemnt.sys
pppcgm.exe

There are 12 entries in the Registry under the
CurrenColtrolSet\Services. Check the Spy Sweeper Log for detail.

BTW, the original problem waswhen teh system comes up, it has 6 square
boxes on the desktop:
Gaming
Dating
Sex
Insurance
Phamarcy
Spyware.

When the mouse is move over the box, links to the related subject will
popup. There were six bitmap files with the above name and an
Idesk.conf files with the php links. Deleted the files doesn't help
because they would be regnerated.

Thanks.
Dewaine


Below is the SpySweeper Log:
>>>>>

********
4:47 PM: | Start of Session, Sunday, December 18, 2005 |
4:47 PM: Spy Sweeper started
4:47 PM: Sweep initiated using definitions version 586
4:47 PM: Starting Memory Sweep
4:49 PM: Memory Sweep Complete, Elapsed Time: 00:02:04
4:49 PM: Starting Registry Sweep
4:49 PM: Found Trojan Horse: trojan-downloader-ruin
4:49 PM: HKLM\software\microsoft\windows\currentversion\url s\ (10
subtraces) (ID = 605127)
4:49 PM: Found Adware: idesk
4:49 PM: HKLM\system\currentcontrolset\services\zpmodemsysn tdrvnt\
(12 subtraces) (ID = 1047250)
4:49 PM: Found Trojan Horse: trojan-downloader-sccash
4:49 PM:
HKU\S-1-5-21-507921405-1677128483-1957994488-1003\software\microsoft\windows\currentversion\run \
|| desktop (ID = 144747)
4:49 PM: Found Adware: searchtoolbar
4:49 PM:
HKU\S-1-5-21-507921405-1677128483-1957994488-1003\software\microsoft\internet
explorer\toolbar\shellbrowser\ || {08bec6aa-49fc-4379-3587-4b21e286c19e}
(ID = 1020297)
4:49 PM: Registry Sweep Complete, Elapsed Time:00:00:14
4:49 PM: Starting Cookie Sweep
4:49 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
4:49 PM: Starting File Sweep
4:49 PM: csvnr.exe (ID = 203528)
4:52 PM: zpmodemnt.sys (ID = 205674)
4:52 PM: idemlog.exe (ID = 205677)
4:52 PM:
HKU\S-1-5-21-507921405-1677128483-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Run
|| desktop (ID = 0)
4:52 PM: pppcgm.exe (ID = 125496)
4:52 PM: Found Adware: cws-aboutblank
4:52 PM: blank.htm (ID = 54894)
4:53 PM: File Sweep Complete, Elapsed Time: 00:03:34
4:53 PM: Full Sweep has completed. Elapsed time 00:05:56
4:53 PM: Traces Found: 32
4:54 PM: Removal process initiated
4:54 PM: Quarantining All Traces: cws-aboutblank
4:54 PM: Quarantining All Traces: trojan-downloader-ruin
4:54 PM: trojan-downloader-ruin is in use. It will be removed on
reboot.
4:54 PM: csvnr.exe is in use. It will be removed on reboot.
4:54 PM: Quarantining All Traces: trojan-downloader-sccash
4:54 PM: Quarantining All Traces: idesk
4:54 PM: Quarantining All Traces: searchtoolbar
4:54 PM: Preparing to restart your computer. Please wait...
4:54 PM: Removal process completed. Elapsed time 00:00:17
********
4:46 PM: | Start of Session, Sunday, December 18, 2005 |
4:46 PM: Spy Sweeper started
4:46 PM: Messenger service has been disabled.
4:47 PM: | End of Session, Sunday, December 18, 2005 |

<<<<<