ok did everything you mentioned and heres a fresh hijackthis log, as well Panda's full report (all in that order).
the ewido report will be in next post since was too big to fit in this post (so ahead of time sry for double posting but have no choice).
HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 12:56:15 AM, on 6/30/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\msiexec.exe
C:\HJT\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Class - {C9AB42A0-2FA0-2537-CA6F-E3F20239C430} - C:\WINDOWS\lshjt1.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) -
http://www.worldwinner.com/games/v45/pool/pool.cabO16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - <a href="
http://aolcc.Email Removed/computercheckup/qdiagcc.cab" target="_blank">
http://aolcc.Email Removed/computercheckup/qdiagcc.cab</a>
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - <a href="
http://download.av.Email Removed/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab" target="_blank">
http://download.av.Email Removed/molbin/shared/m...83/mcinsctl.cab</a>
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1126150560982O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinner.com/games/shared/wwlaunch.cabO16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) -
http://www.snapfish.com/SnapfishUpload.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dllO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - <a href="
http://download.av.Email Removed/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab" target="_blank">
http://download.av.Email Removed/molbin/shared/m...,20/mcgdmgr.cab</a>
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Panda's:
Incident Status Location
Adware:adware/cws Not disinfected C:\Documents and Settings\All Users\Favorites\Download Free Spyware Remover.url
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Gummy.class-65afd8eb-6b59267d.class
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-66d002b9-31d77ea9.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2760418d-20d41516.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count3.jar-7907a8df-5ca32d8d.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-3fdcad19-6c0da6cf.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-3fdcad19-6c0da6cf.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5d76e5c1-535a4938.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5d76e5c1-535a4938.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-665487cf-5ea150da.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-665487cf-5ea150da.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70ea9e12-2a1b6374.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70ea9e12-2a1b6374.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv518.jar-1d54bffb-696e7733.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv518.jar-1d54bffb-696e7733.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv518.jar-26326209-1bf6485a.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv518.jar-26326209-1bf6485a.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv620.jar-1c9f8209-1832e4b9.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv679.jar-5c862677-67b07643.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv679.jar-5c862677-67b07643.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv788.jar-7578ea2e-717730aa.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv788.jar-7578ea2e-717730aa.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16352cad-5f5edd72.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-47610a46-251eed1f.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-47610a46-497e78b4.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-47610a46-76b8b8ce.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\PAUL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-7debe0dd-653bf554.zip[Dummy.class]
Adware:adware/delfinmedia Not disinfected C:\keys.ini
Adware:Adware/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry.exe
Adware:Adware/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry1.dll
Adware:Adware/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry3.dll
Spyware:Cookie/Atwola Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B.tmp
Virus:Backdoor Program Disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C.tmp
Spyware:Cookie/RealMedia Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27.tmp
Spyware:Cookie/Versiontracker Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6.tmp
Potentially unwanted tool:Application/MyWay Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB4.tmp\mysearch.cab
Adware:adware/keenvalue Not disinfected C:\WINDOWS\browserxtras\pn\remove.exe
Adware:adware/bravesentry Not disinfected C:\WINDOWS\desktop.html
Dialer:dialer generic Not disinfected C:\WINDOWS\Downloaded Program Files\sex.exe
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\casino-ico.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\casino.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\dating-ico.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\dating.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\drugs-ico.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\drugs.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\fav-ico.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\fav.bmp
Adware:Adware/Exact.BargainBuddy Not disinfected C:\WINDOWS\EliteToolBar\xml\images\virus.bmp
Adware:Adware/BTGrab Not disinfected C:\WINDOWS\inf\btgrab.inf
Adware:adware/ieplugin Not disinfected C:\WINDOWS\kwv2.dat
Virus:Trj/Agent.CIH Disinfected C:\WINDOWS\pss\ms.exeStartup
Potentially unwanted tool:Application/Kill&Clean Not disinfected C:\WINDOWS\system32\kilacln.exe[KillAndClean.exe]
Spyware:Spyware/MarketScore Not disinfected C:\WINDOWS\system32\rk.bin
Spyware:Spyware/MarketScore Not disinfected C:\WINDOWS\system32\rk.exe
Virus:Trj/Downloader.AZI Disinfected C:\WINDOWS\system32\SSK_B5_MVSSK9.exe.ren.ren
Spyware:Spyware/LinkReplacer Not disinfected C:\WINDOWS\system32\uninst.exe
Adware:Adware/DigInk Not disinfected C:\WINDOWS\Tagasuarus2.exe
Adware:Adware/DigInk Not disinfected C:\WINDOWS\unin101.exe
Adware:Adware/DigInk Not disinfected C:\WINDOWS\uni_ehhh.exe
Adware:Adware/MediaTickets Not disinfected C:\WINDOWS\YOINSI.exe