Here is the log from A-Squared (nothing deleted)
a-squared Anti-Malware - Version 3.5
Last update: 1/06/2008 6:59:02 PM
Scan settings:
Objects: Memory, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: On
Heuristics: On
ADS Scan: On
Scan start: 1/06/2008 7:00:07 PM
Value: HKEY_CLASSES_ROOT\arlnk -->
URL Protocol detected: Trace.Registry.Ares
Key: HKEY_CLASSES_ROOT\clsid\{9afb8248-617f-460d-9366-d71cdeda3179} detected: Trace.Registry.FunWebProducts
Key: HKEY_CLASSES_ROOT\clsid\{147a976f-eee1-4377-8ea7-4716e4cdd239} detected: Trace.Registry.MyWebSearchToobar
Key: HKEY_CLASSES_ROOT\clsid\{147a976f-eee1-4377-8ea7-4716e4cdd239} detected: Trace.Registry.MyWebSearchToolbar
c:\windows\hh.ico detected: Trace.File.Xtractor Plus 3.6
Value: HKEY_CLASSES_ROOT\CLSID\{0AF8185C-26D7-4607-A005-7D586B750C38}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_CLASSES_ROOT\CLSID\{5BF31631-3D94-4267-B6F4-0CE18B008928}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_CLASSES_ROOT\CLSID\{D322CFB6-5195-4EDA-87CA-6D624CCF2751}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_CLASSES_ROOT\CLSID\{EFC25C6F-1A04-43FD-AB25-0F3ED89E050A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0AF8185C-26D7-4607-A005-7D586B750C38}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BF31631-3D94-4267-B6F4-0CE18B008928}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D322CFB6-5195-4EDA-87CA-6D624CCF2751}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EFC25C6F-1A04-43FD-AB25-0F3ED89E050A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.Blubster
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Freeze.com\Installer --> id detected: Trace.Registry.Living Beaches #2 Animated Wallpaper
Value: HKEY_CLASSES_ROOT\CLSID\{03A1A408-CB07-4C90-B380-78C83828707D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{0622801A-0B11-4A90-A036-56CC93D4AA5E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{08CEC807-8452-4CE0-B682-6ED8FAC75FDB}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{09A3D436-4063-46DA-9DD6-0A4FE9D3F887}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{12798743-BA16-448C-B122-8A3EA40ECEB0}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{13151C33-1150-4D7A-8E43-87CA44E85D7E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{1A1FF417-C908-41F0-9AED-ED312EB68500}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{2062525A-D503-4ECE-A3C2-D1883DCBBFA6}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{247F1754-ABE2-4985-9A7A-94E106EDD15D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{29C32CDC-26AA-42C5-A6FD-2192F59B24BB}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{2AD3DEA9-C68D-4976-A627-5CA4ADF99EC4}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{38975430-A042-48C7-B6B9-42875B895589}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{4340BF93-8CB0-4DD9-89ED-5B2980E3F98C}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{4B51C1BC-C1EF-4DC6-B50E-61C50DDBFED0}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{4CE53602-D079-410F-BE21-0F86C472709D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{5BAD6705-C8AB-49FD-B76B-031C66171FFA}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{61634438-3BA1-419B-8CFB-A94ADF2B7B6A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{6A5FB6A5-4B93-430F-A747-CA4F01A2BDB7}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{6DA92D60-5B0C-425E-97C8-658865A96E7D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{7237A978-67A9-455C-8E99-3E0A5B1AECEF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{7AB80000-6E98-4A2B-814E-8F259331AAFF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{8372E131-F6DF-41CE-AC89-FC5F2AB7FE0F}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{93993BC0-C75C-429A-819D-B04E7ED885DA}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{93E1BF2D-FAB5-4243-BD25-0EFDB8964935}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{A2AC1E1F-8F6B-4CA3-80EF-9AAEF18AA0EF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{AEFB259B-2CA8-47C5-AAB4-6557DFCC97D3}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{B269327C-3440-487A-8CDC-1A7741C467E9}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{BAF45FE2-CA67-49EE-BC0E-916B9F861E1E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{D0900FFC-332A-4405-A09E-C6147772D0A2}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{D0B07D23-4A06-4152-87EB-FD201233B137}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{D6D7387C-7369-49DD-B791-CD12A2243895}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{D8286F34-EEDA-4898-9EC7-D2D9E70DDBBF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{DAC39EE6-F721-4B4B-834D-244506139197}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{E615A9D8-2FAD-4732-803C-FFB21CA1EAEF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{E72E7BFF-7D81-4211-8598-77C701A827B8}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{FDC077D4-7094-4CC9-A3B6-9C28C362FF1E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_CLASSES_ROOT\CLSID\{FF9982B4-EB7D-49CF-A76A-08F38119FAB4}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_USERS\S-1-5-21-1214440339-413027322-839522115-1003\Software\Winferno\RegPowerClean --> AutoBackup detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_USERS\S-1-5-21-1214440339-413027322-839522115-1003\Software\Winferno\RegPowerClean --> SBOption detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_USERS\S-1-5-21-1214440339-413027322-839522115-1003\Software\Winferno\RegPowerClean --> StartBehavior detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03A1A408-CB07-4C90-B380-78C83828707D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0622801A-0B11-4A90-A036-56CC93D4AA5E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08CEC807-8452-4CE0-B682-6ED8FAC75FDB}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{09A3D436-4063-46DA-9DD6-0A4FE9D3F887}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12798743-BA16-448C-B122-8A3EA40ECEB0}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{13151C33-1150-4D7A-8E43-87CA44E85D7E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A1FF417-C908-41F0-9AED-ED312EB68500}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2062525A-D503-4ECE-A3C2-D1883DCBBFA6}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{247F1754-ABE2-4985-9A7A-94E106EDD15D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29C32CDC-26AA-42C5-A6FD-2192F59B24BB}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2AD3DEA9-C68D-4976-A627-5CA4ADF99EC4}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{38975430-A042-48C7-B6B9-42875B895589}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4340BF93-8CB0-4DD9-89ED-5B2980E3F98C}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B51C1BC-C1EF-4DC6-B50E-61C50DDBFED0}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4CE53602-D079-410F-BE21-0F86C472709D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BAD6705-C8AB-49FD-B76B-031C66171FFA}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61634438-3BA1-419B-8CFB-A94ADF2B7B6A}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A5FB6A5-4B93-430F-A747-CA4F01A2BDB7}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6DA92D60-5B0C-425E-97C8-658865A96E7D}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7237A978-67A9-455C-8E99-3E0A5B1AECEF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7AB80000-6E98-4A2B-814E-8F259331AAFF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8372E131-F6DF-41CE-AC89-FC5F2AB7FE0F}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93993BC0-C75C-429A-819D-B04E7ED885DA}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93E1BF2D-FAB5-4243-BD25-0EFDB8964935}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2AC1E1F-8F6B-4CA3-80EF-9AAEF18AA0EF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEFB259B-2CA8-47C5-AAB4-6557DFCC97D3}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B269327C-3440-487A-8CDC-1A7741C467E9}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BAF45FE2-CA67-49EE-BC0E-916B9F861E1E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0900FFC-332A-4405-A09E-C6147772D0A2}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D0B07D23-4A06-4152-87EB-FD201233B137}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6D7387C-7369-49DD-B791-CD12A2243895}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D8286F34-EEDA-4898-9EC7-D2D9E70DDBBF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAC39EE6-F721-4B4B-834D-244506139197}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E615A9D8-2FAD-4732-803C-FFB21CA1EAEF}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E72E7BFF-7D81-4211-8598-77C701A827B8}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDC077D4-7094-4CC9-A3B6-9C28C362FF1E}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF9982B4-EB7D-49CF-A76A-08F38119FAB4}\InprocServer32 --> ThreadingModel detected: Trace.Registry.RegistryPowerCleaner
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Freeze.com\Installer --> id detected: Trace.Registry.EZ Game Cheats
Value: HKEY_CLASSES_ROOT\arlnk --> URL Protocol detected: Trace.Registry.Ares Galaxy
P2P Plus
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\arlnk --> URL Protocol detected: Trace.Registry.Ares Galaxy P2P Plus
c:\windows\fish.scr detected: Trace.File.Fish ScreenSaver
C:\Documents and Settings\Owner\Cookies\owner@adtech[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@com[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@media.adrevolver[1].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@media.adrevolver[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@media6degrees[2].txt detected: Trace.TrackingCookie
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt detected: Trace.TrackingCookie
C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL detected: Riskware.AdTool.Win32.MyWebSearch.az
C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL detected: Riskware.AdTool.Win32.MyWebSearch.az
C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL detected: Riskware.AdTool.Win32.MyWebSearch.az
Scanned
Files: 191130
Traces: 412111
Cookies: 43
Processes: 70
Found
Files: 3
Traces: 95
Cookies: 8
Processes: 0
Registry keys: 0
Scan end: 1/06/2008 8:36:51 PM
Scan time: 1:36:44