Thanks for the quick reply
I followed the instructions, CCleaner cleaned all files first time. Im still getting popups that tell me I am infected and linking to the following site:
ANTISPYWARE Reviews - PROTECT YOUR PC FROM VIRUSES AND SPYWARE
Here are the logs:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:19:10 05/05/2008
+ Scan result:
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@amazonms.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@aoluk.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@archant.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@mobilefun.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@myfamily.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@pandasoftware.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@media.adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adviva[1].txt -> TrackingCookie.Adviva : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bluemountain[2].txt -> TrackingCookie.Bluemountain : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.bluemountain[1].txt -> TrackingCookie.Bluemountain : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www1.bluemountain[2].txt -> TrackingCookie.Bluemountain : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@cz8.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@hit.gemius[2].txt -> TrackingCookie.Gemius : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ehg-baa.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ehg-icelandair.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ehg-rodale.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ehg-sothebys.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ehg-tfl.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@counter2.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@searchportal.information[2].txt -> TrackingCookie.Information : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@equs.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@server.lon.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@paycounter[2].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.safer-networking[1].txt -> TrackingCookie.Safer-networking : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@counter12.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@counter8.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ dr_criton_tomazos@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!
Generated 05/05/2008 at 10:42 AM
Application Version : 4.0.1154
Core Rules Database Version : 3452
Trace Rules Database Version: 1444
Scan type : Complete Scan
Total Scan Time : 00:21:23
Memory items scanned : 228
Memory threats detected : 0
Registry items scanned : 5764
Registry threats detected : 0
File items scanned : 20830
File threats detected : 74
Adware.Tracking Cookie
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ dr_criton_tomazos@www.stopzilla[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@track.adform[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.googleadservices[4].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.googleadservices[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.googleadservices[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adv.surinter[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad.yieldmanager[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@hits.revenuestreet[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@tracker.roitesting[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@countrycode.sitestat[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@countrycode.sitestat[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.maleforcemobile[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad1.emediate[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad2.pl.mediainter[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad2.pl.mediainter[3].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@server.iad.liveperson[3].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.8teenboy[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@8teenboy[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.gmbtrack[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@stopzilla[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@focalex[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.stopzilla[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@saletrack.co[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad2.eurobb[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.aol.co[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@xiti[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adinterax[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@stats.free-rein[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@keywordmax[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.gaydvdsexvideos[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@prospect.adbureau[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@eas.apm.emediate[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adultcheck[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@imrworldwide[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adlegend[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@sixapart.adbureau[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@d0003.77tracking[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@account.live[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bannersng.yell[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@server.lon.liveperson[3].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@sex-tube20008[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.findmypast[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@specificclick[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@porn-youtube-08[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@sex-tube20008[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@porn-youtube-08[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@straightfuckfest[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.interracialgaysexvideos[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad.uk.tangozebra[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ad.uk.tangozebra[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@tracking.summitmedia.co[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@apmebf[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@richmedia.yahoo[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bizrate[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@stats.rainbowrevenue[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.addesktop[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@dhdmedia[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@adserver.matchcraft[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@m1.webstats.motigo[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@indexstats[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@tracking.essence-media[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@bizrate.co[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.anm.co[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www3.addfreestats[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@www.stats.tso.co[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.ecards.co[2].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@media.adrevolver[1].txt
C:\Users\Dr Criton Tomazos\AppData\Roaming\Microsoft\Windows\Cookies\ Low\dr_criton_tomazos@ads.bleepingcomputer[1].txt
Rogue.PC-Cleaner
C:\Users\Dr Criton Tomazos\Desktop\virii\Trojan-Downloader.Win32.Agent.bl.exe
C:\Users\Dr Criton Tomazos\Desktop\virii\Trojan-Downloader.Win32.Agent.p.exe
C:\Users\Dr Criton Tomazos\Desktop\virii\Trojan-Downloader.Win32.Agent.r.exe
C:\Users\Dr Criton Tomazos\Desktop\virii\Trojan-Downloader.Win32.Agent.t.exe
C:\Users\Dr Criton Tomazos\Desktop\virii\Trojan-Downloader.Win32.Agent.v.exe
C:\Users\Dr Criton Tomazos\Desktop\virii
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:55:54, on 05/05/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\ProgramData\xcnkxwsz\ybcxajyp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\Dr Criton Tomazos\Desktop\Hijack this\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Enfield Weather Forecast | Weather in Enfield - Yahoo! Weather UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://support.thetechguys.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [xcnkxwsz] C:\ProgramData\xcnkxwsz\ybcxajyp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/actives.../as2stubie.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
--
End of file - 5856 bytes