Thanks for your patience!
As you can see from the log below, I ran the scan, and quite a bit turned up...
After the removal process, the .dat file in the system32 folder was still there, so I deleted it and rebooted.
As for the computer behavior, up until the scan, it's been acting "the same"... I haven't had a chance to test anything except Live Update, which still isn't working...
Thanks for all of your help!
Zach
********
10:44 PM: | Start of Session, Friday, February 03, 2006 |
10:44 PM: Spy Sweeper started
10:44 PM: Sweep initiated using definitions version 611
10:44 PM: Starting Memory Sweep
10:45 PM: Memory Sweep Complete, Elapsed Time: 00:00:53
10:45 PM: Starting Registry Sweep
10:45 PM: Found Adware: multidial
10:45 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\unidist.ocx (ID = 135372)
10:45 PM: Found Adware: rapidblaster
10:45 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/activeinstaller.dll\ (2 subtraces) (ID = 139221)
10:45 PM: Found Adware: tibs dialer
10:45 PM: HKCR\interface\{8a94c367-815a-4d4f-a6b6-d4eb877a126c}\ (8 subtraces) (ID = 143691)
10:45 PM: HKLM\software\classes\interface\{8a94c367-815a-4d4f-a6b6-d4eb877a126c}\ (8 subtraces) (ID = 143717)
10:45 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/tl7000.dll\ (2 subtraces) (ID = 143740)
10:45 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\tl7000.dll (ID = 143748)
10:45 PM: Found Adware: websearch toolbar
10:45 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/qdow_as2.dll\ (2 subtraces) (ID = 146482)
10:45 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\qdow_as2.dll (ID = 146497)
10:45 PM: HKLM\system\currentcontrolset\enum\root\legacy_wintoolssvc\ (7 subtraces) (ID = 146518)
10:45 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/system32/mfc42.dll\ || {e8edb60c-951e-4130-93dc-faf1ad25f8e7} (ID = 956093)
10:45 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/system32/msvcrt.dll\ || {e8edb60c-951e-4130-93dc-faf1ad25f8e7} (ID = 956095)
10:45 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/system32/olepro32.dll\ || {e8edb60c-951e-4130-93dc-faf1ad25f8e7} (ID = 956097)
10:45 PM: Found Adware: lopdotcom
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\microsoft\internet explorer\new windows\allow\ || lop.com (ID = 130287)
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\microsoft\internet explorer\new windows\allow\ ||
www.lop.com (ID = 130289)
10:45 PM: Found Adware: search200.com hijacker
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\microsoft\internet explorer\new windows\allow\ || search200.com (ID = 134078)
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\microsoft\internet explorer\new windows\allow\ ||
www.search200.com (ID = 134079)
10:45 PM: Found Adware: 180search assistant/zango
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\saap\ (18 subtraces) (ID = 135784)
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\saie\ (15 subtraces) (ID = 135788)
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\toolbar\ (26 subtraces) (ID = 146513)
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1008\software\toolbar\ (26 subtraces) (ID = 646239)
10:45 PM: HKU\S-1-5-21-891307005-2014835873-67682326-1007\software\microsoft\internet explorer\new windows\allow\ || lop.com (ID = 130287)
10:45 PM: HKU\S-1-5-21-891307005-2014835873-67682326-1007\software\microsoft\internet explorer\new windows\allow\ ||
www.lop.com (ID = 130289)
10:45 PM: HKU\S-1-5-21-891307005-2014835873-67682326-1007\software\microsoft\internet explorer\new windows\allow\ || search200.com (ID = 134078)
10:45 PM: HKU\S-1-5-21-891307005-2014835873-67682326-1007\software\microsoft\internet explorer\new windows\allow\ ||
www.search200.com (ID = 134079)
10:45 PM: HKU\S-1-5-21-891307005-2014835873-67682326-1007\software\sbitplugin\ (6 subtraces) (ID = 552128)
10:45 PM: HKU\WRSS_Profile_S-1-5-21-891307005-2014835873-67682326-1006\software\saap\ (14 subtraces) (ID = 135784)
10:45 PM: Registry Sweep Complete, Elapsed Time:00:00:21
10:45 PM: Starting Cookie Sweep
10:45 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:45 PM: Starting File Sweep
10:46 PM: c:\windows\system32\fleok (ID = -2147480556)
10:46 PM: c:\program files\sbitplugin (3 subtraces) (ID = -2147480159)
10:47 PM: 116193.ico (ID = 78824)
10:54 PM: saap.log (ID = 70593)
10:57 PM: Found Adware: webrebates
10:57 PM: imgconv.dll (ID = 83909)
11:00 PM: saapau.dat (ID = 70594)
11:03 PM: saap_kyf.dat (ID = 70596)
11:05 PM: Found Adware: netpal
11:05 PM: big fish games.url (ID = 70885)
11:05 PM: flyordie games.url (ID = 70890)
11:06 PM: File Sweep Complete, Elapsed Time: 00:20:22
11:06 PM: Full Sweep has completed. Elapsed time 00:21:56
11:06 PM: Traces Found: 172
11:15 PM: Removal process initiated
11:15 PM: Quarantining All Traces: multidial
11:15 PM: Quarantining All Traces: rapidblaster
11:15 PM: Quarantining All Traces: tibs dialer
11:15 PM: Quarantining All Traces: websearch toolbar
11:16 PM: Quarantining All Traces: lopdotcom
11:17 PM: Quarantining All Traces: search200.com hijacker
11:17 PM: Quarantining All Traces: 180search assistant/zango
11:21 PM: Quarantining All Traces: webrebates
11:21 PM: Quarantining All Traces: netpal
11:21 PM: Removal process completed. Elapsed time 00:05:43