clicktilluwin is gone...
But there's still C:\Program Files\adp\bin\adp.exe which is installed, runs and contacts
http://adp.ikena.com/update.asp?part...&type=software. It downloads the Bargain Buddy installation program, which fires off it's own permanent process of course, to track web site patterns and who knows what.
There's no hope.
This is no different than the dlder.exe/explorer.exe trojan. adp.exe is the downloader for
http://adp.ikena.com:80/file/bbi7378.exe, the Bargain Buddy installation program. c:\program files\bargain buddy\bin\bargains.exe is the trojan that stays in memory.
Zildy