I have followed your instructions by using ATF=Cleaner.exe and have scanned My Computer with Panda ActiveScan. The following are the logs for each.
The following is the Hijackthis log.
Logfile of HijackThis v1.99.1
Scan saved at 11:07:19 PM, on 08/06/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST ANTI-SPAM\QSP-2.1.215.5\QOELOADER.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ FIREWALL\CA.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\COREL\WORDPERFECT OFFICE 2000\PROGRAMS\ALARM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/yco...search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/flash/index.cfm?division=69
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/flash/index.cfm?division=69
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [QOELOADER] "C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST ANTI-SPAM\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~3\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\PROGRAM FILES\MARKETBROWSER\LMT\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\PROGRAM FILES\MARKETBROWSER\LMT\MarketBrowser_Launch.xpy
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?322
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) -
http://ftp.hp.com/pub/automatic/player/isetupML.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
https://www-secure.symantec.com/tech...ActiveData.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/SSC/Sha.../bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/S...9x/AvSniff.cab
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) -
http://prod1.centra.com/SiteRoots/ma...Downloader.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) -
http://ib.armstrong.com/ib/databases/actimage30717.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
https://ww2.lifescan.com/otdms/isetup.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) -
http://fdl.msn.com/public/investor/v13/invinstl.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) -
http://www.schaeffersresearch.com/download/CfxIEAx.cab
O16 - DPF: {24BACF02-5676-11D3-B8DE-00105A17A9E6} (ChartFX Internet Financial Client 4.0) -
http://www.schaeffersresearch.com/Do...4Financial.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) -
http://www.smilecam.com/home/ezwebca...ebMonProj1.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) -
http://206.222.17.186/images/PopupSh.ocx
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) -
http://download.zonelabs.com/bin/free/cm/ICSCM_ca.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/is...20/mcfscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
The following is the Panda ActiveScan Log.
Incident Status Location
Adware:adware/comet Not disinfected c:\windows\downloaded program files\cc.inf
Adware:adware/transponder Not disinfected c:\windows\thin-114-1-x-x.exe
Adware:adware/cws Not disinfected C:\WINDOWS\Favorites\Insurance
Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[1].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[3].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\WINDOWS\Cookies\charles r[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\WINDOWS\Cookies\anyuser@www.myaffiliateprogram[2].txt
Spyware:Cookie/WebPower Not disinfected C:\WINDOWS\Cookies\anyuser@webpower[1].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\charles r. clark@go[1].txt
Spyware:Cookie/Affiliate fuel Not disinfected C:\WINDOWS\Cookies\anyuser@www.affiliatefuel[1].txt
Spyware:Cookie/Mircx Not disinfected C:\WINDOWS\Cookies\anyuser@pop.mircx[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\WINDOWS\Cookies\charles r. clark@ccbill[2].txt
Spyware:Cookie/web-stat Not disinfected C:\WINDOWS\Cookies\anyuser@www.web-stat[1].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Cookies\anyuser@atwola[2].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[2].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[4].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\charles r. clark@go[3].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Cookies\charles r. clark@atwola[2].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\charles r. clark@go[4].txt
Spyware:Cookie/Azjmp Not disinfected C:\WINDOWS\Cookies\charles r. clark@azjmp[1].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[5].txt
Spyware:Cookie/360i Not disinfected C:\WINDOWS\Cookies\anyuser@ct.360i[1].txt
Spyware:Cookie/Yadro Not disinfected C:\WINDOWS\Cookies\anyuser@yadro[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\WINDOWS\Cookies\charles r[30].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\charles r. clark@go[2].txt
Spyware:Cookie/Kount Not disinfected C:\WINDOWS\Cookies\charles r. clark@kount[1].txt
Spyware:Cookie/360i Not disinfected C:\WINDOWS\Cookies\charles r. clark@ct.360i[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\WINDOWS\Cookies\anyuser@www.myaffiliateprogram[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\WINDOWS\Cookies\anyuser@www.burstbeacon[2].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[6].txt
Spyware:Cookie/did-it Not disinfected C:\WINDOWS\Cookies\anyuser@did-it[1].txt
Spyware:Cookie/GoClick Not disinfected C:\WINDOWS\Cookies\anyuser@c.goclick[2].txt
Spyware:Cookie/Target Not disinfected C:\WINDOWS\Cookies\anyuser@target[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\WINDOWS\Cookies\anyuser@searchportal.information[1].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Cookies\anyuser@ath.belnk[1].txt
Spyware:Cookie/64.62.232 Not disinfected C:\WINDOWS\Cookies\anyuser@64.62.232[3].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Cookies\charles r[41].txt
Spyware:Cookie/Azjmp Not disinfected C:\WINDOWS\Cookies\anyuser@azjmp[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\WINDOWS\Cookies\charles r. clark@searchportal.information[1].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Cookies\charles r. clark@ath.belnk[1].txt
Spyware:Cookie/Xmts Not disinfected C:\WINDOWS\Cookies\anyuser@xmts[2].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\anyuser@go[8].txt
Spyware:Cookie/NewMedia Not disinfected C:\WINDOWS\Cookies\anyuser@anm.co[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\WINDOWS\Cookies\anyuser@www.myaffiliateprogram[4].txt
Spyware:Cookie/2o7 Not disinfected C:\WINDOWS\Cookies\anyuser@microsofteup.112.2o7[1].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Cookies\charles r. clark@atwola[1].txt
Spyware:Cookie/Banner Not disinfected C:\WINDOWS\Cookies\anyuser@banner[1].txt
Spyware:Cookie/Screensavers Not disinfected C:\WINDOWS\Cookies\anyuser@i.screensavers[2].txt
Spyware:Cookie/did-it Not disinfected C:\WINDOWS\Cookies\anyuser@did-it[2].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Cookies\anyuser@atwola[1].txt
Spyware:Cookie/360i Not disinfected C:\WINDOWS\Cookies\anyuser@ct.360i[3].txt
Spyware:Cookie/Xiti Not disinfected C:\WINDOWS\Cookies\anyuser@xiti[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\WINDOWS\Cookies\anyuser@www.burstbeacon[3].txt
Spyware:Cookie/Paypopup Not disinfected C:\WINDOWS\Cookies\anyuser@paypopup[1].txt