Kristy,
I did what you said
Here is the spysweeper log
********
10:34 PM: |··· Start of Session, Saturday, July 16, 2005 ···|
10:34 PM: Spy Sweeper started
10:34 PM: Sweep initiated using definitions version 505
10:34 PM: Starting Memory Sweep
10:36 PM: Memory Sweep Complete, Elapsed Time: 00:02:23
10:36 PM: Starting Registry Sweep
10:37 PM: Found Trojan Horse: antivirus gold
10:37 PM: HKCR\appid\cerberus.exe\ (1 subtraces) (ID = 4364402)
10:37 PM: HKCR\appid\{70f17c8c-1744-41b6-9d07-575db448dcc5}\ (1 subtraces) (ID = 4364403)
10:37 PM: HKCR\cerberus.enginelistener.1\ (3 subtraces) (ID = 4364404)
10:37 PM: HKCR\cerberus.enginelistener\ (5 subtraces) (ID = 4364405)
10:37 PM: HKCR\cerberus.scanner.1\ (3 subtraces) (ID = 4364406)
10:37 PM: HKCR\cerberus.scanner\ (5 subtraces) (ID = 4364407)
10:37 PM: HKCR\cerberus.threatcollection.1\ (3 subtraces) (ID = 4364408)
10:37 PM: HKCR\cerberus.threatcollection\ (5 subtraces) (ID = 4364409)
10:37 PM: HKCR\clsid\{020b1227-417d-4682-9ac3-61f43cb5b6b1}\ (9 subtraces) (ID = 4364410)
10:37 PM: HKCR\clsid\{3d00a39c-655b-428b-aeb2-2fba03dcc49c}\ (8 subtraces) (ID = 4364411)
10:37 PM: HKCR\clsid\{5f6bbd8a-18cf-4d55-8b4c-c9b4c9328dfe}\ (8 subtraces) (ID = 4364412)
10:37 PM: HKCR\clsid\{8c56b6ce-c53f-44c4-9bdc-a9bc1711d05a}\ (8 subtraces) (ID = 4364413)
10:37 PM: HKCR\clsid\{8ee6bf73-b370-4d13-9126-eb0071178f2e}\ (8 subtraces) (ID = 4364414)
10:37 PM: HKCR\clsid\{9bb7e700-4e48-476d-b75c-6f47606be988}\ (8 subtraces) (ID = 4364415)
10:37 PM: HKCR\clsid\{20a3d913-30ef-4e69-b3f7-93b3f1fb9d5c}\ (9 subtraces) (ID = 4364416)
10:37 PM: HKCR\clsid\{97f56e12-c706-4aeb-9ffb-133c05ee5d38}\ (9 subtraces) (ID = 4364417)
10:37 PM: HKCR\clsid\{408f660a-9465-44a3-b557-8709dfd992bc}\ (8 subtraces) (ID = 4364418)
10:37 PM: HKCR\clsid\{125494b2-acad-414c-98b9-452f3ef7703a}\ (9 subtraces) (ID = 4364419)
10:37 PM: HKCR\clsid\{cbcaca58-1aee-4600-8cf0-e8b30bff1535}\ (9 subtraces) (ID = 4364420)
10:37 PM: HKCR\clsid\{d6d64cdf-0363-4261-b723-29a3af365e1d}\ (8 subtraces) (ID = 4364421)
10:37 PM: HKCR\engine.backup.1\ (3 subtraces) (ID = 4364422)
10:37 PM: HKCR\engine.backup\ (5 subtraces) (ID = 4364423)
10:37 PM: HKCR\engine.ignorelist.1\ (3 subtraces) (ID = 4364424)
10:37 PM: HKCR\engine.ignorelist\ (5 subtraces) (ID = 4364425)
10:37 PM: HKCR\engine.log.1\ (3 subtraces) (ID = 4364426)
10:37 PM: HKCR\engine.log\ (5 subtraces) (ID = 4364427)
10:37 PM: HKCR\engine.logrecord.1\ (3 subtraces) (ID = 4364428)
10:37 PM: HKCR\engine.logrecord\ (5 subtraces) (ID = 4364429)
10:37 PM: HKCR\engine.paths.1\ (3 subtraces) (ID = 4364430)
10:37 PM: HKCR\engine.paths\ (5 subtraces) (ID = 4364431)
10:37 PM: HKCR\engine.quarantine.1\ (3 subtraces) (ID = 4364432)
10:37 PM: HKCR\engine.quarantine\ (5 subtraces) (ID = 4364433)
10:37 PM: HKCR\engine.runas.1\ (3 subtraces) (ID = 4364434)
10:37 PM: HKCR\engine.runas\ (5 subtraces) (ID = 4364435)
10:37 PM: HKCR\engine.searchitem.1\ (3 subtraces) (ID = 4364436)
10:37 PM: HKCR\engine.searchitem\ (5 subtraces) (ID = 4364437)
10:37 PM: HKCR\engine.threat.1\ (3 subtraces) (ID = 4364438)
10:37 PM: HKCR\engine.threat\ (5 subtraces) (ID = 4364439)
10:37 PM: HKLM\software\classes\appid\cerberus.exe\ (1 subtraces) (ID = 4364441)
10:37 PM: HKLM\software\classes\appid\{70f17c8c-1744-41b6-9d07-575db448dcc5}\ (1 subtraces) (ID = 4364442)
10:37 PM: HKLM\software\classes\cerberus.enginelistener.1\ (3 subtraces) (ID = 4364443)
10:37 PM: HKLM\software\classes\cerberus.enginelistener\ (5 subtraces) (ID = 4364444)
10:37 PM: HKLM\software\classes\cerberus.scanner.1\ (3 subtraces) (ID = 4364445)
10:37 PM: HKLM\software\classes\cerberus.scanner\ (5 subtraces) (ID = 4364446)
10:37 PM: HKLM\software\classes\cerberus.threatcollection.1\ (3 subtraces) (ID = 4364447)
10:37 PM: HKLM\software\classes\cerberus.threatcollection\ (5 subtraces) (ID = 4364448)
10:37 PM: HKLM\software\classes\clsid\{020b1227-417d-4682-9ac3-61f43cb5b6b1}\ (9 subtraces) (ID = 4364450)
10:37 PM: HKLM\software\classes\clsid\{3d00a39c-655b-428b-aeb2-2fba03dcc49c}\ (8 subtraces) (ID = 4364451)
10:37 PM: HKLM\software\classes\clsid\{5f6bbd8a-18cf-4d55-8b4c-c9b4c9328dfe}\ (8 subtraces) (ID = 4364452)
10:37 PM: HKLM\software\classes\clsid\{8c56b6ce-c53f-44c4-9bdc-a9bc1711d05a}\ (8 subtraces) (ID = 4364453)
10:37 PM: HKLM\software\classes\clsid\{8ee6bf73-b370-4d13-9126-eb0071178f2e}\ (8 subtraces) (ID = 4364454)
10:37 PM: HKLM\software\classes\clsid\{9bb7e700-4e48-476d-b75c-6f47606be988}\ (8 subtraces) (ID = 4364455)
10:37 PM: HKLM\software\classes\clsid\{20a3d913-30ef-4e69-b3f7-93b3f1fb9d5c}\ (9 subtraces) (ID = 4364456)
10:37 PM: HKLM\software\classes\clsid\{97f56e12-c706-4aeb-9ffb-133c05ee5d38}\ (9 subtraces) (ID = 4364457)
10:37 PM: HKLM\software\classes\clsid\{408f660a-9465-44a3-b557-8709dfd992bc}\ (8 subtraces) (ID = 4364458)
10:37 PM: HKLM\software\classes\clsid\{125494b2-acad-414c-98b9-452f3ef7703a}\ (9 subtraces) (ID = 4364459)
10:37 PM: HKLM\software\classes\clsid\{cbcaca58-1aee-4600-8cf0-e8b30bff1535}\ (9 subtraces) (ID = 4364460)
10:37 PM: HKLM\software\classes\clsid\{d6d64cdf-0363-4261-b723-29a3af365e1d}\ (8 subtraces) (ID = 4364461)
10:37 PM: HKLM\software\classes\engine.backup.1\ (3 subtraces) (ID = 4364462)
10:37 PM: HKLM\software\classes\engine.backup\ (5 subtraces) (ID = 4364463)
10:37 PM: HKLM\software\classes\engine.ignorelist.1\ (3 subtraces) (ID = 4364464)
10:37 PM: HKLM\software\classes\engine.ignorelist\ (5 subtraces) (ID = 4364465)
10:37 PM: HKLM\software\classes\engine.log.1\ (3 subtraces) (ID = 4364466)
10:37 PM: HKLM\software\classes\engine.log\ (5 subtraces) (ID = 4364467)
10:37 PM: HKLM\software\classes\engine.logrecord.1\ (3 subtraces) (ID = 4364468)
10:37 PM: HKLM\software\classes\engine.logrecord\ (5 subtraces) (ID = 4364469)
10:37 PM: HKLM\software\classes\engine.paths.1\ (3 subtraces) (ID = 4364470)
10:37 PM: HKLM\software\classes\engine.paths\ (5 subtraces) (ID = 4364471)
10:37 PM: HKLM\software\classes\engine.quarantine.1\ (3 subtraces) (ID = 4364472)
10:37 PM: HKLM\software\classes\engine.quarantine\ (5 subtraces) (ID = 4364473)
10:37 PM: HKLM\software\classes\engine.runas.1\ (3 subtraces) (ID = 4364474)
10:37 PM: HKLM\software\classes\engine.runas\ (5 subtraces) (ID = 4364475)
10:37 PM: HKLM\software\classes\engine.searchitem.1\ (3 subtraces) (ID = 4364476)
10:37 PM: HKLM\software\classes\engine.searchitem\ (5 subtraces) (ID = 4364477)
10:37 PM: HKLM\software\classes\engine.threat.1\ (3 subtraces) (ID = 4364478)
10:37 PM: HKLM\software\classes\engine.threat\ (5 subtraces) (ID = 4364479)
10:37 PM: Found Adware: cws_analyzeie
10:37 PM: HKCR\clsid\{60d75c7f-d119-4a89-b3b3-d8aa07ef3300}\ (ID = 4377830)
10:37 PM: HKLM\software\classes\clsid\{60d75c7f-d119-4a89-b3b3-d8aa07ef3300}\ (ID = 4377852)
10:37 PM: Found Adware: instafinder
10:37 PM: HKU\WRSS_Profile_S-1-5-21-2366997589-1562546304-2584548655-501\software\instafink\ (26 subtraces) (ID = 4389737)
10:37 PM: Found Adware: psguard desktop hijacker
10:37 PM: HKLM\software\microsoft\windows\currentversion\uninstall\internet update\ (3 subtraces) (ID = 4398274)
10:37 PM: HKLM\software\psguard.com\ (1 subtraces) (ID = 4398275)
10:37 PM: Registry Sweep Complete, Elapsed Time:00:00:14
10:37 PM: Starting Cookie Sweep
10:37 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:37 PM: Starting File Sweep
10:38 PM: screen.html (ID = 4090481)
10:39 PM: File Sweep Complete, Elapsed Time: 00:01:53
10:39 PM: Full Sweep has completed. Elapsed time 00:04:36
10:39 PM: Traces Found: 510
10:46 PM: Removal process initiated
10:46 PM: Quarantining All Traces: antivirus gold
10:46 PM: Quarantining All Traces: cws_analyzeie
10:46 PM: Quarantining All Traces: instafinder
10:46 PM: Quarantining All Traces: psguard desktop hijacker
10:46 PM: Removal process completed. Elapsed time 00:00:12
********
10:34 PM: |··· Start of Session, Saturday, July 16, 2005 ···|
10:34 PM: Spy Sweeper started
10:34 PM: Warning: Hosts File Shield unable to read from hosts file. Access violation at address 7C910370 in module 'ntdll.dll'. Read of address 000000D0
10:34 PM: |··· End of Session, Saturday, July 16, 2005 ···|
I deleted the whole file of
C:\!Submit
C:\Program Files\The Cleaner\MooLive.exe(If you don't know what this is, delete it as well)My Task Mgr is still the same
I still have to press ALT F4