Ok, here are the panda logs...
Incident Status Location
Adware:Adware/SaveNow No disinfected Windows Registry
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Ab scissor.url
Adware:Adware/Adsmart No disinfected C:\WINDOWS\sys????.exe
Virus:Trj/Downloader.CFJ Disinfected Operating system
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Ab scissor.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Broadband comparison.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Credit counseling.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Credit report.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Crm software.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Debt credit card.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Escorts.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Fha.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Health insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Help desk software.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Insurance home.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Loan for debt consolidation.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Loan for people with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Marketing email.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Mortgage insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Mortgage life insurance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Nevada corporations.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Online Betting Site.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Online gambling casino.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Online instant loan.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Order phentermine.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Payroll advance.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Personal loans online.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Personal loans with bad credit.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Prescription Drugs Rx Online.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Refinancing my mortgage.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Tahoe vacation rental.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Unsecured bad credit loans.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\Videos.url
Spyware:Spyware/Petro-Line No disinfected C:\Documents and Settings\Tramel Raggs\Favorites\Sites about\What is hydrocodone.url
Adware:Adware/SearchAid No disinfected C:\WINDOWS\addpz.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apilq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\apixc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\appwx32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlhf.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlix32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\atlma.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\crlq32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3zg.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ierl.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\iewb.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ieyc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ipek32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\javarn32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mfcgu.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msdr.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\msnj.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\mszc32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\netmg32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntps32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ntue.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\n_euzywg.dat
Adware:Adware/SearchAid No disinfected C:\WINDOWS\n_qorlor.dat
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkih32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkno32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\syskf32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\apphg32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\atlwm32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\crqi32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\iedw.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ipaz.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\javavg32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\mfcyq.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msbt.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\msnj32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netml32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\ntlh.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdkmj.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\sdknf.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\wincd.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\winyz.exe
...and the hijack this logs...
Logfile of HijackThis v1.99.1
Scan saved at 4:09:57 PM, on 6/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tramel Raggs\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gamefaqs.com/
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/ ... 0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v ... 8704411515
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Now, Panda found that stuff, but it hasn't come up anywhere else. I still have a few spyware programs in the Add/Remove section (and I don't trust the installers they want you to download to get rid of them), but they aren't the ones listed. They are:
Offer Optimizer
Shopping Wizard.
So far, I haven't seen any ill effects from them, though and my system is running top notch. I have also since deleted ieyc32.exe and addpz.exe in the windows directory. I don't know how I missed them before.