Efwis,
Ran Findlt9xMe.bat. The log is below. I'll stand-by for your reply.
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
------- System Files in System Directory -------
Volume in drive C is WIN98SE
Volume Serial Number is 2029-12F4
Directory of C:\WINDOWS\SYSTEM
VW4EN16 DLL 227,104 03-16-05 7:06a VW4EN16.DLL
OSETHK32 DLL 227,104 03-16-05 7:06a OSETHK32.DLL
IDM32 DLL 227,104 03-16-05 7:06a IDM32.DLL
OUECNV32 DLL 227,104 03-16-05 7:06a OUECNV32.DLL
MUMP3WAV DLL 227,104 03-16-05 7:06a mump3wav.dll
UHP10 DLL 227,104 03-16-05 7:06a uhp10.dll
VBHELPER DLL 227,104 03-16-05 7:06a VBHELPER.DLL
WOICORE DLL 227,104 03-16-05 7:06a WOICORE.DLL
CPTDLL DLL 227,104 03-16-05 7:06a CPTDLL.DLL
PSBDLG DLL 227,104 03-16-05 7:06a PSBDLG.DLL
FISRCH DLL 227,104 03-16-05 7:06a FISRCH.DLL
ID50_QC DLL 227,104 03-16-05 7:06a Id50_qc.dll
MXCPXL32 DLL 227,104 03-16-05 7:06a MXCPXL32.DLL
MZACM DLL 227,104 03-16-05 7:06a MZACM.DLL
MQC42ENU DLL 227,104 03-16-05 7:06a MQC42ENU.DLL
RVAUI DLL 227,104 03-16-05 7:06a RVAUI.DLL
MWAFD DLL 227,104 03-16-05 7:06a MWAFD.DLL
MZCRLREV DLL 227,104 03-16-05 7:06a mzcrlrev.dll
VGR DLL 227,104 03-16-05 7:06a VGR.DLL
NIS DLL 227,104 03-16-05 7:06a NIS.DLL
SKSCRAP DLL 227,104 03-16-05 7:06a SKSCRAP.DLL
SCLSTR DLL 227,104 03-16-05 7:06a SCLSTR.DLL
TED32 DLL 227,104 03-16-05 7:06a TED32.DLL
SREM0409 DLL 227,104 03-16-05 7:06a SREM0409.DLL
NOS DLL 227,104 03-16-05 7:06a NOS.DLL
MHSTDFMT DLL 227,104 03-16-05 7:06a MHSTDFMT.DLL
SHSTHUNK DLL 227,104 03-16-05 7:06a SHSTHUNK.DLL
MFYUV DLL 227,104 03-16-05 7:06a mfyuv.dll
BGMFUSB DLL 227,104 03-16-05 7:06a BgmfUSB.dll
MDAFD DLL 227,104 03-16-05 7:06a MDAFD.DLL
JOMP500 DLL 227,104 03-16-05 7:06a JOMP500.DLL
BANDFILE DLL 227,104 03-16-05 7:06a BANDFILE.DLL
AASTREAM DLL 227,104 03-16-05 7:06a AASTREAM.DLL
DXIMAN32 DLL 227,104 03-16-05 7:06a DXIMAN32.DLL
JFVALE DLL 227,104 03-16-05 7:06a JFVALE.DLL
IDDKCS32 DLL 227,104 03-16-05 7:06a IDDKCS32.DLL
POUSTAB DLL 227,104 03-16-05 7:06a POUSTAB.DLL
SXLWOA DLL 227,104 03-16-05 7:06a SXLWOA.DLL
CQRESRC DLL 227,104 03-16-05 7:06a CQRESRC.DLL
MRBRKR12 DLL 227,104 03-16-05 7:06a MRBRKR12.DLL
OJE2NLS DLL 227,104 03-16-05 7:06a OJE2NLS.DLL
VXODCTL DLL 227,104 03-16-05 7:06a VXODCTL.DLL
DXNDI DLL 227,104 03-16-05 7:06a DXNDI.DLL
IK509CLS DLL 227,104 03-16-05 7:06a IK509CLS.DLL
BXWEBINS DLL 227,104 03-16-05 7:06a BxWebIns.dll
AVDENC32 DLL 227,104 03-16-05 7:06a AVDENC32.DLL
ONECNV32 DLL 227,104 03-16-05 7:06a ONECNV32.DLL
TZBINF32 DLL 227,104 03-16-05 7:06a TZBINF32.DLL
WFLSOF32 DLL 227,104 03-16-05 7:06a Wflsof32.dll
MZAFD DLL 227,104 03-16-05 7:06a MZAFD.DLL
DYDXOF DLL 227,104 03-16-05 7:06a DYDXOF.DLL
ACFERROR DLL 227,104 03-16-05 7:06a acferror.dll
IDCTL DLL 227,104 03-16-05 7:06a idctl.dll
MCPCIC DLL 227,104 03-16-05 7:06a MCPCIC.DLL
SVLWOA DLL 227,104 03-16-05 7:06a SVLWOA.DLL
RUAUI DLL 227,104 03-15-05 3:33p RUAUI.DLL
LEME_ENC DLL 227,104 03-15-05 3:33p lEme_enc.dll
MMGSYS DLL 227,104 03-15-05 3:33p MMGSYS.DLL
MMMIXMGR DLL 227,104 03-15-05 3:33p MMMIXMGR.DLL
MKIMRT16 DLL 227,104 03-08-05 5:32p MKIMRT16.DLL
MFOSS DLL 227,104 03-08-05 5:32p MFOSS.DLL
QSSNAME DLL 227,104 03-08-05 5:32p QSSNAME.DLL
PIGFILT DLL 227,104 03-08-05 5:32p pigfilt.dll
REAUI DLL 227,104 03-08-05 5:32p REAUI.DLL
MZVCIRT DLL 227,104 03-08-05 5:32p mzvcirt.dll
NERSNL DLL 227,104 03-08-05 5:32p NERSNL.DLL
IPSENG DLL 227,104 03-08-05 2:31p IPSENG.DLL
AXRIP DLL 227,104 03-08-05 2:31p axrip.dll
RWSAPI16 DLL 222,568 02-01-05 2:54p RWSAPI16.DLL
CNHTMGR DLL 222,568 02-01-05 2:54p CNHTMGR.DLL
WCNNET16 DLL 222,568 02-01-05 2:54p WCNNET16.DLL
ILMUI DLL 222,568 02-01-05 2:54p ILMUI.DLL
NSMODE DLL 222,568 02-01-05 2:54p NSMODE.DLL
KDRNEL32 DLL 222,568 02-01-05 2:54p KDRNEL32.DLL
SOELL DLL 222,568 02-01-05 2:54p SOELL.DLL
OOBCINT DLL 222,568 02-01-05 2:54p OOBCINT.DLL
PKUSTAB DLL 222,568 02-01-05 2:54p PKUSTAB.DLL
FHNTEXT DLL 222,568 02-01-05 2:54p FHNTEXT.DLL
OZECNV32 DLL 222,568 02-01-05 2:54p OZECNV32.DLL
DEMIGR DLL 222,568 02-01-05 2:54p demigr.dll
VFAR2232 DLL 222,568 02-01-05 2:54p VFAR2232.DLL
WBLP32T DLL 222,568 02-01-05 2:54p WBLP32T.DLL
IJDKCS32 DLL 222,568 02-01-05 2:54p IJDKCS32.DLL
IDSENG DLL 222,568 02-01-05 2:54p IDSENG.DLL
SGNSAPI DLL 222,568 02-01-05 2:54p sgnsapi.dll
BHNDFILE DLL 222,568 02-01-05 2:54p BHNDFILE.DLL
IU509CLS DLL 222,568 02-01-05 2:54p IU509CLS.DLL
RWVPSP DLL 222,568 02-01-05 2:54p RWVPSP.DLL
TCPI DLL 222,568 02-01-05 2:54p TCPI.DLL
VKRSION DLL 222,568 02-01-05 2:54p VKRSION.DLL
FFPWPP DLL 222,568 02-01-05 2:54p FFPWPP.DLL
XHLPARSE DLL 222,568 02-01-05 2:54p xhlparse.dll
NSQTWK DLL 222,568 02-01-05 2:54p NSQTWK.DLL
MJSTDFMT DLL 222,568 02-01-05 2:54p MJSTDFMT.DLL
MFJINT35 DLL 222,568 02-01-05 2:54p mfjint35.dll
CSMMDLG DLL 222,568 02-01-05 2:54p CSMMDLG.DLL
PUTORERC DLL 222,568 02-01-05 2:54p PUTORERC.DLL
SMBAPI DLL 222,568 02-01-05 2:54p smbapi.dll
ESSMTP DLL 222,568 02-01-05 2:54p essmtp.dll
IZWDIAL DLL 222,568 02-01-05 2:54p izwdial.dll
MFLTUS40 DLL 222,568 02-01-05 2:54p MFLTUS40.DLL
GUU32 DLL 222,568 02-01-05 2:54p GUU32.DLL
NBRSES DLL 222,568 02-01-05 2:54p NBRSES.DLL
MVPP32 DLL 222,568 02-01-05 2:54p MVPP32.DLL
DOVOICED DLL 222,568 02-01-05 2:54p dovoiced.dll
MQCPXL32 DLL 222,568 02-01-05 2:54p MQCPXL32.DLL
DLMCLIEN DLL 222,568 02-01-05 2:54p dlmclien.dll
TKPELIB DLL 222,568 02-01-05 2:54p TKPELIB.DLL
RDCLTS3 DLL 222,568 02-01-05 2:54p RDCLTS3.DLL
JET DLL 222,568 02-01-05 2:54p JET.DLL
MEC40 DLL 222,568 02-01-05 2:54p MEC40.DLL
MWC40 DLL 222,568 02-01-05 2:54p MWC40.DLL
JPSD400 DLL 222,568 02-01-05 2:54p jpsd400.dll
JXDW500 DLL 222,568 02-01-05 2:54p JXDW500.DLL
WX5INF16 DLL 222,568 02-01-05 2:54p WX5INF16.DLL
NMRSIT DLL 222,568 02-01-05 2:54p NMRSIT.DLL
DKWAVED DLL 222,568 02-01-05 2:54p dkwaved.dll
RLCLTSCM DLL 222,568 02-01-05 2:54p RLCLTSCM.DLL
TREMBED DLL 222,568 02-01-05 2:54p tRembed.dll
COHTMGRX DLL 222,568 02-01-05 2:54p COHTMGRX.DLL
COAXFR DLL 222,568 02-01-05 2:54p COAXFR.DLL
DVVENUM DLL 222,568 02-01-05 2:54p DVVENUM.DLL
MALTUS40 DLL 222,568 02-01-05 2:54p MALTUS40.DLL
BZOWSEUI DLL 222,568 02-01-05 2:54p BZOWSEUI.DLL
ANMCMPRS DLL 222,568 02-01-05 2:54p ANMCMPRS.DLL
CLIMGX DLL 222,568 02-01-05 2:54p CLIMGX.DLL
ULP10 DLL 222,568 02-01-05 2:54p ulp10.dll
VYW4 EXE 254,038 12-06-04 5:34p Vyw4.exe
SND2C EXE 254,038 12-06-04 5:34p Snd2C.exe
129 file(s) 29,082,660 bytes
0 dir(s) 9,563.75 MB free
------- Hidden Files in System Directory -------
Volume in drive C is WIN98SE
Volume Serial Number is 2029-12F4
Directory of C:\WINDOWS\SYSTEM
NSVSVC <DIR> 03-26-05 9:17p nsvsvc
FOLDER HTT 13,122 03-26-05 11:58a folder.htt
DESKTOP INI 266 03-26-05 11:58a desktop.ini
PROSETP GID 24,200 03-26-05 9:15a PROSETP.GID
PICSVR <DIR> 03-25-05 8:51p picsvr
VMSS <DIR> 03-06-05 6:30p vmss
VYW4 EXE 254,038 12-06-04 5:34p Vyw4.exe
SND2C EXE 254,038 12-06-04 5:34p Snd2C.exe
VX0 NLS 8,192 11-01-04 7:47p VX0.NLS
6 file(s) 553,856 bytes
3 dir(s) 9,563.73 MB free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{305938A1-9132-56EB-379D-BFFE055C0FC5}"=""
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
vw4en16.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
osethk32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
rwsapi16.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
cnhtmgr.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
wcnnet16.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
ilmui.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
nsmode.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
kdrnel32.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
folder.htt Sat Mar 26 2005 11:58:40a ...H. 13,122 12.81 K
idm32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
soell.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
desktop.ini Sat Mar 26 2005 11:58:40a ...H. 266 0.26 K
ouecnv32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
oobcint.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
pkustab.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mump3wav.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
uhp10.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
fhntext.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
ozecnv32.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
demigr.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
vfar2232.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
prosetp.gid Sat Mar 26 2005 9:15:36a A..H. 24,200 23.63 K
vbhelper.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
woicore.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
wblp32t.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
ijdkcs32.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
idseng.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
sgnsapi.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
bhndfile.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
iu509cls.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
rwvpsp.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
tcpi.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
vkrsion.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
ffpwpp.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
xhlparse.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
nsqtwk.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mjstdfmt.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mfjint35.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
csmmdlg.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
putorerc.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
smbapi.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
essmtp.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
izwdial.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mfltus40.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
guu32.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
nbrses.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mvpp32.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
dovoiced.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mqcpxl32.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
dlmclien.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
cptdll.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
psbdlg.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
fisrch.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
tkpelib.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
rdclts3.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
jet.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mec40.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
mwc40.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
jpsd400.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
id50_qc.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
jxdw500.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
wx5inf16.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
nmrsit.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
dkwaved.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
rlcltscm.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
trembed.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
cohtmgrx.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
coaxfr.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
dvvenum.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
maltus40.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
bzowseui.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
anmcmprs.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
climgx.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
ipseng.dll Tue Mar 8 2005 2:31:12p ..S.R 227,104 221.78 K
mkimrt16.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
mfoss.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
qssname.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
pigfilt.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
reaui.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
axrip.dll Tue Mar 8 2005 2:31:12p ..S.R 227,104 221.78 K
ulp10.dll Tue Feb 1 2005 2:54:52p ..S.R 222,568 217.35 K
ruaui.dll Tue Mar 15 2005 3:33:46p ..S.R 227,104 221.78 K
mzvcirt.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
leme_enc.dll Tue Mar 15 2005 3:33:46p ..S.R 227,104 221.78 K
mmgsys.dll Tue Mar 15 2005 3:33:46p ..S.R 227,104 221.78 K
mmmixmgr.dll Tue Mar 15 2005 3:33:46p ..S.R 227,104 221.78 K
mxcpxl32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mzacm.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
nersnl.dll Tue Mar 8 2005 5:32:36p ..S.R 227,104 221.78 K
mqc42enu.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
rvaui.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mwafd.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mzcrlrev.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
vgr.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
nis.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
skscrap.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
sclstr.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
ted32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
srem0409.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
nos.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mhstdfmt.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
shsthunk.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mfyuv.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
bgmfusb.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mdafd.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
jomp500.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
bandfile.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
aastream.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
dximan32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
jfvale.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
iddkcs32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
poustab.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
sxlwoa.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
cqresrc.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mrbrkr12.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
oje2nls.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
vxodctl.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
dxndi.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
ik509cls.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
bxwebins.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
avdenc32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
onecnv32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
tzbinf32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
wflsof32.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mzafd.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
dydxof.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
acferror.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
idctl.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
mcpcic.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
svlwoa.dll Wed Mar 16 2005 7:06:30a ..S.R 227,104 221.78 K
130 items found: 130 files, 0 directories.
Total of file sizes: 28,612,172 bytes 27.29 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\VPTNFILE.518: TROJ_QOOLOGIC.G
C:\WINDOWS\VPTNFILE.518: TROJ_QOOLOGIC.C
C:\WINDOWS\VPTNFILE.518: TROJ_QOOLOGIC.B
C:\WINDOWS\VPTNFILE.518: TROJ_QOOLOGIC.A
C:\WINDOWS\lpt$vpn.518: TROJ_QOOLOGIC.G
C:\WINDOWS\lpt$vpn.518: TROJ_QOOLOGIC.C
C:\WINDOWS\lpt$vpn.518: TROJ_QOOLOGIC.B
C:\WINDOWS\lpt$vpn.518: TROJ_QOOLOGIC.A
C:\WINDOWS\unadbeh.exe: e:\Projects\Qoologic\PopupClient\FancyUninstall\Release\FancyUninstall.pdb
C:\WINDOWS\hmrho.dll: excl_urls=photobucket.com,c1.zedo.com,media.deskwizz.com,stats.eblocs.com,passportimages.com,banners.searchingbooth.com,ads234.com,click2.containsitall.com,media.fastclick.net,sandboxer.com,a.websponsors.com,ads.clickagents.com,trk.bestmagsdirect.com,toprebates.com,ad.doubleclick.net,as.casalemedia.com,m3.doubleclick.net,dw.dailywinner.net,img2.mailpostdirect.com,bv.channel.aol.com,adlog2.lzio.com,host239.ipowerweb.com,popups.ad-logics.com,clickserve.cc-dt.com,hits.clickandtrack.net,ads.mydailyhoroscope.net,c5.zedo.com,affiliates.4lowrates.com,couponage.com,ekmas.com,creativeby.viewpoint.com,mydailyhoroscope.net,images.trafficmp.com,actualdeals.com,download.websearch.com,aim-charts.pf.aol.com,aol.com,target.com,yahoo.com,microsoft.com,anrdoezrs.net,isg05.casalemedia.com,jbigpops.cjt1.net,whenusearch.com,trk.pcsecurityshield.com,license.hotbar.com,web.icq.com,sc.musicmatch.com,comcast.net,filter.belkin.com,clickit.go2net.com,adverts.lzio.com,windowsupdate.microsoft.com,v4.windowsupdate.microsoft.com,odysseusmarketing.com,join1.winhundred.com,advert.runescape.com,top-banners.com,sr.websearch.com,messenger.msn.com,download.abetterinternet.com,adserv.internetfuel.com,pops.browseraid.com,banners.pennyweb.com,tv.180solutions.com,s.clkoptimizer.com,adserv1.gruvmedia.com,cdn.icq.com,messenger.zango.com,smileycentral.com,wwp.icq.com,web.tickle.com,isapi60.weatherbug.com,websearch.com,hop.clickbank.net,media76.fastclick.net,mmm.media-motor.net,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,ww2.weatherbug.com,servedby.advertising.com,adsrv.qoologic.com,games.yahoo.com,weatherbug.com,jicmedia.cjt1.net,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,ar.atwola.com,ads.addynamix.com,wisapidata.weatherbug.com,popuppers.com,as.adwave.com,look2me.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,delfinproject.com,view.atdmt.com,mm.delfinproject.com,download.smileycentral.com,xadso.offeroptimizer.com,webpdp.gator.com,ayb.lop.com,stopzilla.com,pgq.yahoo.com,jmnad1.com,topicks.com,e.rn11.com,focusin.ads.targetnet.com,insider.msg.yahoo.com,m2.doubleclick.net,mail.yahoo.com,jcontent.bns1.net,ctl.twain-tech.com,master.mx-targeting.com,hotmail.com,searcheffect.com,ads.delfinproject.com,cfg.mywebsearch.com,akapp.whenu.com,newupdates.lzio.com,allaboutsearching.com,amch.questionmarket.com,adfarm.mediaplex.com,hotmail.msn.com,by.optimost.com,cdn-cf.aol.com,paypopup.com,popuptraffic.com,xadsq.offeroptimizer.com,jnictech.cjt1.net,xanga.com,count.exitexchange.com,servedby.adscpm.com,search200.com,cdn-aimtoday.aol.com,kill-pop-ups.com,us.update.companion.yahoo.com,qksrv.net,clickspring.net,xlime.offeroptimizer.com,sr.adwave.com,zone.msn.com,radio.launch.yahoo.com,ads.bidclix.com,counters.honesty.com,oz.valueclick.com,i.emarketresearchgroup.com,ads2.revenue.net,popup.msn.com,adsv2.delfinproject.com,u.clkoptimizer.com,ezula.com,server.iad.liveperson.net,loadingwebsite.com,pan-advert.com,t.trafficmp.com,clicktrk.com,aaabesthomepage.com,ads.exitexchange.com,us.a1.yimg.com,trafficmp.com,yimg.com,a.as-us.falkag.net,a1.yimg.com,z1.adserver.com,falkag.net,as-us.falkag.net,loginnet.passport.com,ads.inet1.com,pagead2.googlesyndication.com,login.passport.net,v8.alwaysupdatednews.com,adv.eblocs.com,alwaysupdatednews.com,fxfeeds.mozilla.org,cdn.aim.com,ar.atwola.com,c4.maxserving.com,maxserving.com,mediaplex.com,altfarm.mediaplex.com,topmoxie.com,global.msads.net,msads.net,banner.goldenpalace.com,goldenpalace.com,us.i1.yimg.com,cdn.comcast.net,us.yimg.com,us.js1.yimg.com,js1.yimg.com,switch.atdmt.com,atdmt.com,update32.searchmiracle.com,onemoresearch.net,
C:\WINDOWS\SYSTEM\pav.sig: Qoologic
C:\WINDOWS\SYSTEM\pav.sig: Qoologic
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\vsapi32.dll: ASPACK EXE
C:\WINDOWS\vsapi32.dll: ASPACK2 EXE
C:\WINDOWS\vsapi32.dll: ASPack 1.08.04
C:\WINDOWS\vsapi32.dll: ASPack 1.08.03
C:\WINDOWS\vsapi32.dll: ASPack 1.08.02b
C:\WINDOWS\vsapi32.dll: ASPack 1.08.01
C:\WINDOWS\vsapi32.dll: ASPack 1.08
C:\WINDOWS\vsapi32.dll: ASPack 1.07b
C:\WINDOWS\vsapi32.dll: ASPack 1.61
C:\WINDOWS\vsapi32.dll: ASPack 1.05b
C:\WINDOWS\vsapi32.dll: ASPack 1.03
C:\WINDOWS\vsapi32.dll: ASPack 1.02
C:\WINDOWS\vsapi32.dll: ASPack 1.01
C:\WINDOWS\vsapi32.dll: ASPack 1.00
C:\WINDOWS\SYSTEM\pav.sig: AsPack
----------------- HKLM Run Key ------------------
-------------- Strings.exe Umonitor Results -------------
C:\WINDOWS\SYSTEM\RWSAPI16.DLL: UMonitor
C:\WINDOWS\SYSTEM\CNHTMGR.DLL: UMonitor
C:\WINDOWS\SYSTEM\WCNNET16.DLL: UMonitor
C:\WINDOWS\SYSTEM\MRCO30.DLL: UMonitor
C:\WINDOWS\SYSTEM\ILMUI.DLL: UMonitor
C:\WINDOWS\SYSTEM\NSMODE.DLL: UMonitor
C:\WINDOWS\SYSTEM\KDRNEL32.DLL: UMonitor
C:\WINDOWS\SYSTEM\SOELL.DLL: UMonitor
C:\WINDOWS\SYSTEM\OOBCINT.DLL: UMonitor
C:\WINDOWS\SYSTEM\PKUSTAB.DLL: UMonitor
C:\WINDOWS\SYSTEM\FHNTEXT.DLL: UMonitor
C:\WINDOWS\SYSTEM\OZECNV32.DLL: UMonitor
C:\WINDOWS\SYSTEM\demigr.dll: UMonitor
C:\WINDOWS\SYSTEM\VFAR2232.DLL: UMonitor
C:\WINDOWS\SYSTEM\WBLP32T.DLL: UMonitor
C:\WINDOWS\SYSTEM\IJDKCS32.DLL: UMonitor
C:\WINDOWS\SYSTEM\IDSENG.DLL: UMonitor
C:\WINDOWS\SYSTEM\sgnsapi.dll: UMonitor
C:\WINDOWS\SYSTEM\BHNDFILE.DLL: UMonitor
C:\WINDOWS\SYSTEM\IU509CLS.DLL: UMonitor
C:\WINDOWS\SYSTEM\RWVPSP.DLL: UMonitor
C:\WINDOWS\SYSTEM\TCPI.DLL: UMonitor
C:\WINDOWS\SYSTEM\VKRSION.DLL: UMonitor
C:\WINDOWS\SYSTEM\FFPWPP.DLL: UMonitor
C:\WINDOWS\SYSTEM\xhlparse.dll: UMonitor
C:\WINDOWS\SYSTEM\NSQTWK.DLL: UMonitor
C:\WINDOWS\SYSTEM\MJSTDFMT.DLL: UMonitor
C:\WINDOWS\SYSTEM\mfjint35.dll: UMonitor
C:\WINDOWS\SYSTEM\CSMMDLG.DLL: UMonitor
C:\WINDOWS\SYSTEM\PUTORERC.DLL: UMonitor
C:\WINDOWS\SYSTEM\smbapi.dll: UMonitor
C:\WINDOWS\SYSTEM\essmtp.dll: UMonitor
C:\WINDOWS\SYSTEM\izwdial.dll: UMonitor
C:\WINDOWS\SYSTEM\MFLTUS40.DLL: UMonitor
C:\WINDOWS\SYSTEM\GUU32.DLL: UMonitor
C:\WINDOWS\SYSTEM\NBRSES.DLL: UMonitor
C:\WINDOWS\SYSTEM\MVPP32.DLL: UMonitor
C:\WINDOWS\SYSTEM\dovoiced.dll: UMonitor
C:\WINDOWS\SYSTEM\MQCPXL32.DLL: UMonitor
C:\WINDOWS\SYSTEM\dlmclien.dll: UMonitor
C:\WINDOWS\SYSTEM\TKPELIB.DLL: UMonitor
C:\WINDOWS\SYSTEM\RDCLTS3.DLL: UMonitor
C:\WINDOWS\SYSTEM\JET.DLL: UMonitor
C:\WINDOWS\SYSTEM\MEC40.DLL: UMonitor
C:\WINDOWS\SYSTEM\MWC40.DLL: UMonitor
C:\WINDOWS\SYSTEM\jpsd400.dll: UMonitor
C:\WINDOWS\SYSTEM\JXDW500.DLL: UMonitor
C:\WINDOWS\SYSTEM\WX5INF16.DLL: UMonitor
C:\WINDOWS\SYSTEM\NMRSIT.DLL: UMonitor
C:\WINDOWS\SYSTEM\dkwaved.dll: UMonitor
C:\WINDOWS\SYSTEM\RLCLTSCM.DLL: UMonitor
C:\WINDOWS\SYSTEM\tRembed.dll: UMonitor
C:\WINDOWS\SYSTEM\COHTMGRX.DLL: UMonitor
C:\WINDOWS\SYSTEM\COAXFR.DLL: UMonitor
C:\WINDOWS\SYSTEM\DVVENUM.DLL: UMonitor
C:\WINDOWS\SYSTEM\MALTUS40.DLL: UMonitor
C:\WINDOWS\SYSTEM\BZOWSEUI.DLL: UMonitor
C:\WINDOWS\SYSTEM\ANMCMPRS.DLL: UMonitor
C:\WINDOWS\SYSTEM\CLIMGX.DLL: UMonitor
C:\WINDOWS\SYSTEM\ulp10.dll: UMonitor
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"EnsoniqMixer"="C:\\WINDOWS\\starter.exe"
"Adaptec DirectCD"="C:\\PROGRA~1\\ADAPTEC\\DIRECTCD\\DIRECTCD.EXE"
"IndexSearch"="C:\\Program Files\\Scansoft\\PaperPort\\IndexSearch.exe"
"SetDefPrt"="C:\\Program Files\\Brother\\Brmfl03a\\BrStDvPt.exe"
"SystemTray"="SysTray.Exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"MMTray"="C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_tray.exe"
"WildTangent CDA"="RUNDLL32.exe C:\\PROGRA~1\\WILDTA~1\\APPS\\CDA\\CDAENG~1.DLL,cdaEngineMain"
"vptray"="C:\\PROGRA~1\\NORTON~1\\vptray.exe"
"Desktop Search"="C:\\WINDOWS\\isrvs\\desktop.exe"
"ffis"="C:\\WINDOWS\\isrvs\\ffisearch.exe"
"lehveayj"="c:\\windows\\system\\lehveayj.exe"
"nsvcin"="C:\\N20050308.EXE"
"Nsv"="C:\\WINDOWS\\SYSTEM\\nsvsvc\\nsvsvc.exe"
"picsvr"="C:\\WINDOWS\\SYSTEM\\PICSVR\\PICSVR.EXE"
"KavSvc"="C:\\WINDOWS\\miampr.exe"
"autoupdate"="rundll32 C:\\WINDOWS\\SYSTEM\\WINUP2DATE.DLL,SHStart"
"CreateCD"="C:\\PROGRA~1\\ADAPTEC\\EASYCD~1\\CREATECD\\CREATECD.EXE -r"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"