i dont really know where to post this log , so im just gonna post it here and if its wrong then sorry.
here's the log i got from HijackThis
Logfile of HijackThis v1.99.1
Scan saved at 15:10:56, on 20-Nov-06
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Yes, this is the correct place to post your HjT logs.
I see 1 worm and 1 downloader showing in your HjT log, but here may be more that we can't see. Before we remove those you need to do something first. You need to get Service Pack 1 for XP. Although SP2 is now out, do not install it until we know you're clean. Both Service Pack have major security updates and patches. Download and install SP1a from here.
After you install SP1a and restart, run a scan only with HijackThis, place a check beside these, then click "Fix checked".
O4 - HKLM\..\Run: [Bron-Spizaetus] "C:\WINDOWS\INF\norBtok.exe"
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\user\Local Settings\Application Data\smss.exe"
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O20 - Winlogon Notify: WLogon - C:\WINDOWS\SYSTEM32\srvc.dll
Update AVG Anti-spyware then close it, you will run the scan in safe mode.
Note: Print or copy these instructions to Notepad and save them. You will be in safe mode an can't access the internet.
Restart your computer in safe mode. (press F8 before the Windows load screen, select Safe Mode from the menu then press Enter
Show hidden files and folders.
Start > Control Panel > Folder Options > View tab > check "Show hidden files and folders".
Click Apply, then OK.
Locate and delete these files. Some may not be there, I'm listing all the files this worm can copy its self as, just incase they are present.
C:\WINDOWS\INF\norBtok.exe C:\WINDOWS\SYSTEM32\srvc.dll C:\Documents and Settings\user\Local Settings\Application Data\csrss.exe* C:\Documents and Settings\user\Local Settings\Application Data\inetinfo.exe* C:\Documents and Settings\user\Local Settings\Application Data\lsass.exe* C:\Documents and Settings\user\Local Settings\Application Data\services.exe* C:\Documents and Settings\user\Local Settings\Application Data\smss.exe*
* - These have the same name as legit files in the System32 folder. Do not confuse those with these.
Empty the Recycle Bin.
Then, run a "Complete scan" with AVGAS.
Be sure to click "Save Report" after you delete any files found.
Restart in normal mode and post back with the AVGAS report and a new HijackThis log.