I searched the computer from the start menu and the downloads don't show up anywhere.

Logfile of HijackThis v1.99.1 Scan saved at 21:09: VIRUS ALERT!, on 7/15/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe

You will probably have to reboot. C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP267\A0036772.exe (Trojan.Fakealert) -> Quarantined and deleted successfully. I sure hope you guys can tell what's wrong.

uStart Page = hxxp://www.google.co.uk/ uInternet Connection Wizard,ShellNext = iexplore BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

Online services are available: Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally Win32/Msblast Not Infected.

Try the Iobit malware fighter: http://www.iobit.com/malware-fighter.html
Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\WINDOWS\system32\drivers\CDAC11BA.EXEC:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exeC:\WINDOWS\system32\DVDRAMSV.exeC:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exeC:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exeC:\PROGRA~1\McAfee\MSC\mcmscsvc.exec:\program files\common files\mcafee\mna\mcnasvc.exeC:\WINDOWS\Explorer.EXEC:\PROGRA~1\McAfee\VIRUSS~1\mcods.exeC:\PROGRA~1\McAfee\MSC\mcpromgr.exec:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exec:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exeC:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exeC:\Program Files\McAfee\MPF\MPFSrv.exeC:\WINDOWS\system32\PSIService.exeC:\Program Files\Intel\Wireless\Bin\RegSrvc.exeC:\Program Files\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\system32\svchost.exec:\Toshiba\IVP\swupdate\swupdtmr.exec:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exeC:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exeC:\WINDOWS\wanmpsvc.exeC:\Program Files\Toshiba\Tvs\TvsTray.exeC:\Program Files\Toshiba\Toshiba Applet\thotkey.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\WINDOWS\AGRSMMSG.exeC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exeC:\Program Files\TOSHIBA\ConfigFree\NDSTray.exeC:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

O20 - AppInit_DLLs: c:\programdata\flashbeat\flashbeat32.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - 
I found a program last night called Exterminateit which seemed to do the trick. Here it is: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:08:33 AM, on 7/20/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal 
I opened task manager and found that services.exe was running up my CPU.

HKLM\Software\Microsoft\Windows\CurrentVersion\Run DataCardMonitor = c:\program files\T-Mobile\T-Mobile Internet Manager\DataCardMonitor.exe

C:\Windows\Sys1.exeC:\WINDOWS\evgratsm.dll - Note that some of these file(s)/folder(s) may or may not be present.

Yep, that solved the problem!

Completion time: 2011-04-08 11:40:53 ComboFix-quarantined-files.txt 2011-04-08 10:40 . 
Do not install more than one antivirus program because they will conflict with each other. I did not try HitmanPro yesterday, but I've downloaded it this morning and after I re-run MalwareBytes I'm going to follow up with HitmanPro for the "2nd opinion" they advertise it 
Perform at least TWO virus scans via the below: (Set them to clean)BitDefenderHousecallPanda5.

It sets flags in the registry to prevent the running of a specific list of bad spyware related ActiveX controls.

A bit more info:- This machine was full of virus's and spyware. 
I'm running Vista Home Premium.

C:\Documents and Settings\Hazel\Local Settings\Application Data\Zimbra\Zimbra Desktop\store\0\2\msg\3\12301-42307.msg [DETECTION] Is the TR/Spy.ZBot.dye Trojan [NOTE] The file was moved to the quarantine directory under the name '51508fc8.qua'. 
If present, and cannot be deleted because they're 'in use', try deleting them in Safe Mode by doing the following: Restart your computer After hearing your computer beep once during startup,
I THINK I solved the problem myself! I'm going to mark it solved!

hosts file corrupted ! hk.digitaltrends.com127.0.0.1 microsoft.com.org127.0.0.1 www.www.microsoft.com.org
My son downloaded FireFox and we tried downloading using that browser, but the same thing happens. Avira likely caught and removed files located in system restore cache, or backups that were created during the course of cleaning the machine. Install & update SpywareBlaster with the latest definitions.

This is in addition to the quick scan suggested upon installation. 
uStart Page = hxxp://www.google.co.uk/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Hazel\Application Data\Mozilla\Firefox\Profiles\6758roz6.default\ FF - prefs.js: browser.startup.homepage - hxxp://mail.ccalphagroup.co.uk/#1 .

C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP268\A0038882.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.