this is the new hijack this log and the panda activescan results
Incident Status Location
Virus:Trj/Downloader.ABE Disinfected Operating system
Adware:Adware/nCase No disinfected Windows Registry
Adware:Adware/PortalScan No disinfected C:\WINDOWS\SYSTEM\swin32.dll
Spyware:Spyware/Searchcentrix No disinfected Windows Registry
Adware:Adware/Apropos No disinfected C:\Program Files\cxtpls
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dealhlpr.dll
Adware:Adware/AdLogix No disinfected C:\WINDOWS\SYSTEM\retpdat32.xml
Spyware:Spyware/SurfSideKick No disinfected Windows Registry
Virus:Trj/Downloader.AEE Disinfected Operating system
Adware:Adware/PowerStrip No disinfected C:\WINDOWS\pgtaff?.bin
Spyware:Spyware/LinkReplacer No disinfected C:\WINDOWS\SYSTEM\LMF32.DLL
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\clueacct.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\crtdial.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\wuaelind.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\xen0dal.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\SYSTEM\SWin32.dll
Adware:Adware/AdLogix No disinfected C:\WINDOWS\SYSTEM\adstartup.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\SYSTEM\modgxyz.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\SYSTEM\adupdater.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\pro3dv2.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\qdvml.exe
Virus:Trj/Downloader.AQI Disinfected C:\WINDOWS\SYSTEM\oipdefui.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\rnrebdvd.exe
Virus:Trj/Downloader.AAU Disinfected C:\WINDOWS\SYSTEM\rsaxpand.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\ksui400.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\mbstilse.exe
Virus:Trj/Downloader.AMT Disinfected C:\WINDOWS\SYSTEM\atlrm24f.exe
Adware:Adware/PortalScan No disinfected C:\WINDOWS\SYSTEM\winupdtl.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\SYSTEM\InstaFinder_inst.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\SYSTEM\instFindtvmk38megaV2.dll
Adware:Adware/PortalScan No disinfected C:\WINDOWS\SYSTEM\winupdt.exe
Adware:Adware/MyDailyHoroscopeNo disinfected C:\WINDOWS\SYSTEM\setup_silent_17307.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\cmuerold.exe
Virus:Trj/Downloader.AQI Disinfected C:\WINDOWS\SYSTEM\vfpshl.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\SYSTEM\wpwrch.exe
Adware:Adware/CWS.008k No disinfected C:\WINDOWS\SYSTEM\awf0dal.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\TEMP\AutoUpdate1\auto_update_install.exe
Adware:Adware/Envolo No disinfected C:\WINDOWS\TEMP\AutoUpdate1\setup.inf
Spyware:Spyware/SurfSideKick No disinfected C:\WINDOWS\TEMP\SskUpdater.exe
Spyware:Spyware/Searchcentrix No disinfected C:\WINDOWS\Downloaded Program Files\instafin.dll
Adware:Adware/PortalScan No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\BYVNX2CI\install_1000[1].exe
Adware:Adware/Envolo No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\EFKJBGTO\AutoUpdaterInstaller[1].exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\EFKJBGTO\bannerbottom1[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\EFKJBGTO\bannerbottom2[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\SHAN09E3\bannertop2[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\SHAN09E3\navigation[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\SHAN09E3\affiliates[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\SHAN09E3\bannerbottom1[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\4DYZOHQB\bannertop1[1].htm
Adware:Adware/WUpd No disinfected C:\WINDOWS\Temporary Internet Files\Content.IE5\4DYZOHQB\bannerbottom2[1].htm
Adware:Adware/PortalScan No disinfected C:\WINDOWS\pgtaff.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dealhlpr.dll
Virus:Bck/Agent.K Disinfected C:\WINDOWS\xezi.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhsvr.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhbrwsr.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhp.dll
Virus:Trojan Horse Disinfected C:\WINDOWS\Helper100.dll
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhupdt.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhp2.dll
Adware:Adware/Minibug No disinfected C:\Program Files\AIM\Sysfiles\WxBug.EXE
Virus:Trj/Downloader.AEE Disinfected C:\RECYCLED\Dc2356\backups\backup-20050407-212600-374.inf
Logfile of HijackThis v1.99.1
Scan saved at 3:16:59 PM, on 4/14/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\WINDOWS\AU10TRAY.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\NETGEAR WG311V2 ADAPTER\WLANCFG5.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HJT\HIJACKTHIS.EXE
R3 - Default URLSearchHook is missing
O2 - BHO: LinkTracker Class - {6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} - C:\WINDOWS\SYSTEM\LMF32.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [VortexTray] C:\WINDOWS\au10setp.exe 3
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\Run: [AutoLoaderotqr1ISTPIWO] "C:\WINDOWS\SYSTEM\ICSCJI32.EXE" /HideUninstall /PC="CP.BYZ"
O4 - HKLM\..\Run: [AutoLoaderotqd1ISTPIWO] "C:\WINDOWS\SYSTEM\PDBLL.EXE"
O4 - HKLM\..\Run: [oE9X36P] PDBLL.EXE
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
O4 - HKCU\..\Run: [Zpq7RWj7U] TSPIS400.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cab