Thanks for helpinh on this...I tried to do it the easy way also, but this is my sons pc and you know how that goes
Here's the output log:
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
------- System Files in System Directory -------
Volume in drive C is 20040319
Volume Serial Number is 035C-1B08
Directory of C:\WINDOWS\SYSTEM
AUXDRV~1 ODS 5 07-23-05 10:01a AuxDrv32ds_k.ods
CPM DLL 226,080 07-23-05 9:59a CPM.DLL
SZELL32 DLL 226,080 07-23-05 9:59a SZELL32.DLL
DBMAP DLL 226,080 07-23-05 9:59a dbmap.dll
WFPLENC DLL 226,080 07-23-05 9:59a WFPLENC.DLL
CDOOSUSR DLL 226,080 07-23-05 9:59a CDOOSUSR.DLL
CKUTOA DLL 226,080 07-23-05 9:59a CKUTOA.DLL
DWMM DLL 226,080 07-23-05 9:59a DWMM.DLL
QPV DLL 227,616 07-17-05 12:06a QPV.DLL
UYER32 DLL 227,616 07-17-05 12:06a UYER32.DLL
CRM DLL 227,616 07-17-05 12:06a CRM.DLL
OAESVR DLL 227,616 07-17-05 12:06a OAESVR.DLL
ITHLPAPI DLL 227,616 07-17-05 12:06a ITHLPAPI.DLL
JGVAEE DLL 227,616 07-17-05 12:06a JGVAEE.DLL
MYTCP DLL 227,616 07-17-05 12:06a MYTCP.DLL
MBINCP16 DLL 227,616 07-17-05 12:06a MBINCP16.DLL
DDNDI DLL 227,616 07-17-05 12:06a DDNDI.DLL
MYCI DLL 227,616 07-17-05 12:06a MYCI.DLL
CHMNEW DLL 227,616 07-17-05 12:06a chmnew.dll
ACIPDLXX DLL 227,616 07-17-05 12:06a ACIPDLXX.DLL
SBCUR32 DLL 227,616 07-17-05 12:06a SBCUR32.DLL
WRICORE DLL 227,616 07-17-05 12:06a WRICORE.DLL
DLMSTOR DLL 227,104 07-11-05 6:06p DLMSTOR.DLL
FXSION32 DLL 227,104 07-11-05 6:06p FXSION32.DLL
DQVENUM DLL 227,104 07-11-05 6:06p DQVENUM.DLL
SRSINV DLL 227,104 07-11-05 6:06p SRSINV.DLL
8E55INDI DLL 227,104 07-11-05 6:06p 8E55INDI.DLL
MDDOCS DLL 227,104 07-11-05 6:06p MDDOCS.DLL
NJWDEV DLL 227,104 07-11-05 6:06p NJWDEV.DLL
VEDX16 DLL 227,104 07-11-05 6:06p VEDX16.DLL
CPUTOA DLL 227,104 07-11-05 6:06p CPUTOA.DLL
MGR2C DLL 227,104 07-11-05 6:06p MGR2C.DLL
MXDVDOPT DLL 227,104 06-24-05 3:53p MXDVDOPT.DLL
SRPDLL DLL 227,104 06-24-05 3:53p SRPDLL.DLL
WFDMLOG DLL 227,104 06-24-05 3:53p WFDMLOG.DLL
NTTPLWIZ DLL 227,104 06-24-05 3:53p NTTPLWIZ.DLL
QJIM32 DLL 227,104 06-24-05 3:53p QJIM32.DLL
OXGFS400 DLL 227,104 06-24-05 3:53p OXGFS400.DLL
CHSEQCHK DLL 227,104 06-24-05 3:53p CHSEQCHK.DLL
MHHTMLED DLL 227,104 06-24-05 3:53p MHHTMLED.DLL
DA32GT DLL 227,104 06-24-05 3:53p DA32GT.DLL
MQAFD DLL 227,104 06-24-05 3:53p MQAFD.DLL
MYRTEDIT DLL 227,104 06-24-05 3:53p MYRTEDIT.DLL
RIAENH DLL 227,104 06-24-05 3:53p RIAENH.DLL
AKIICDXX DLL 227,104 06-24-05 3:53p AKIICDXX.DLL
NHWDEV DLL 227,104 06-24-05 3:53p NHWDEV.DLL
RYRC32 DLL 227,104 06-24-05 3:53p RYRC32.DLL
WPASHEXT DLL 227,104 06-24-05 3:53p WPASHEXT.DLL
LROUSE16 DLL 227,104 06-24-05 3:53p LROUSE16.DLL
SLLFX DLL 227,104 06-24-05 3:53p SLLFX.DLL
WAPLOC DLL 227,104 06-24-05 3:53p WAPLOC.DLL
RNCLTSCM DLL 227,104 06-24-05 3:53p RNCLTSCM.DLL
CVM DLL 227,104 06-24-05 3:53p CVM.DLL
DZVVOX DLL 227,104 06-24-05 3:53p DZVVOX.DLL
WTADEFUI DLL 227,104 06-24-05 3:53p WTADEFUI.DLL
AFIICDXX DLL 227,104 06-24-05 3:53p AFIICDXX.DLL
BDOWSELC DLL 227,104 06-24-05 3:53p BDOWSELC.DLL
IVM32 DLL 227,104 06-24-05 3:53p IVM32.DLL
IXMUPG DLL 226,080 06-17-05 12:03a IXMUPG.DLL
SPHANNEL DLL 226,080 06-17-05 12:03a SPHANNEL.DLL
CERDS DLL 226,080 06-17-05 12:03a CERDS.DLL
MXRATING DLL 226,080 06-17-05 12:03a MXRATING.DLL
MZOEACCT DLL 226,080 06-17-05 12:03a mzoeacct.dll
DD32GT DLL 226,080 06-17-05 12:03a DD32GT.DLL
SOGE DLL 226,080 06-17-05 12:03a SOGE.DLL
WIVCORE DLL 226,080 06-17-05 12:03a WIVCORE.DLL
MIUTILSE DLL 226,080 06-17-05 12:03a MIUTILSE.DLL
WOCTHUNK DLL 226,592 05-10-05 5:24p WOCTHUNK.DLL
ARIFIL32 DLL 226,592 05-10-05 5:24p ARIFIL32.DLL
DHNMPNTW DLL 226,592 05-10-05 5:24p DHNMPNTW.DLL
JNEG1X32 DLL 226,592 05-10-05 5:24p JNEG1X32.DLL
CEYPTDLG DLL 226,592 05-10-05 5:24p CEYPTDLG.DLL
FYSRCH DLL 226,592 05-10-05 5:24p FYSRCH.DLL
DPEML DLL 226,592 05-10-05 5:24p DPEML.DLL
DCCPCSVC DLL 226,592 05-10-05 5:24p DCCPCSVC.DLL
DYVENUM DLL 226,592 05-10-05 5:24p DYVENUM.DLL
MAAFD DLL 226,592 05-10-05 5:24p MAAFD.DLL
MMAFD DLL 226,592 05-10-05 5:24p MMAFD.DLL
JLDW400 DLL 226,592 05-10-05 5:24p JLDW400.DLL
DTMSVINN DLL 226,592 05-10-05 5:24p DTMSVINN.DLL
DND8 DLL 226,592 05-10-05 5:24p dNd8.dll
DLUSIC16 DLL 226,592 05-10-05 5:24p DLUSIC16.DLL
OSUI400 DLL 226,592 05-10-05 5:24p OSUI400.DLL
PFDRV DLL 226,592 05-10-05 5:24p pfdrv.dll
QJDWIPES DLL 226,592 05-10-05 5:24p QJDWIPES.DLL
OJMREG DLL 226,592 05-10-05 5:24p OJMREG.DLL
ZCORT4AS DLL 226,592 05-10-05 5:24p ZCORT4AS.dll
SWMAN32 DLL 226,592 05-10-05 5:24p SWMAN32.DLL
MXG4DMOD DLL 226,592 05-10-05 5:24p MXG4DMOD.DLL
AAIV16XX DLL 226,592 05-10-05 5:24p AAIV16XX.DLL
IZENGINE DLL 226,592 05-10-05 5:24p izengine.dll
MBHTMLED DLL 226,592 05-10-05 5:24p MBHTMLED.DLL
JXNGLE DLL 226,592 05-10-05 5:24p Jxngle.dll
DADIAGN DLL 226,592 05-10-05 5:24p dadiagn.dll
MVIMRT DLL 226,592 05-10-05 5:24p MVIMRT.DLL
IOET16 DLL 226,592 05-10-05 5:24p IOET16.DLL
MAXML4A DLL 226,592 05-10-05 5:24p maxml4a.dll
GFIDE2X DLL 226,592 05-10-05 5:24p GFIDE2X.DLL
LPOUSE32 DLL 226,592 05-10-05 5:24p LPOUSE32.DLL
WK5INF32 DLL 226,592 05-10-05 5:24p WK5INF32.DLL
IASENG DLL 226,592 05-10-05 5:24p IASENG.DLL
CPRDS DLL 226,592 05-10-05 5:24p CPRDS.DLL
SQNCUI DLL 226,592 05-10-05 5:24p SQNCUI.DLL
EFTIER2 DLL 226,592 05-10-05 5:24p EFTIER2.DLL
IYWPHBK DLL 226,592 05-10-05 5:24p IYWPHBK.DLL
MCRD2X40 DLL 226,592 05-10-05 5:24p MCRD2X40.DLL
DAMSVINN DLL 226,592 05-10-05 5:24p DAMSVINN.DLL
ATIFIL32 DLL 226,592 05-10-05 5:24p ATIFIL32.DLL
DRMSVINN DLL 226,592 05-10-05 5:24p DRMSVINN.DLL
SCNDMAIL DLL 226,592 05-10-05 5:24p SCNDMAIL.DLL
GUI32 DLL 226,592 05-10-05 5:24p GUI32.DLL
CXMNCTR DLL 226,592 05-10-05 5:24p CXMNCTR.DLL
HNOIMG07 DLL 226,592 05-10-05 5:24p HNOIMG07.DLL
MD3216 DLL 226,592 05-10-05 5:24p MD3216.DLL
SFLWAPI DLL 227,104 03-23-05 8:39p SFLWAPI.DLL
MPHTMLER DLL 227,104 03-23-05 8:39p MPHTMLER.DLL
MOACM32 DLL 227,104 03-23-05 8:39p MOACM32.DLL
NCTPLWIZ DLL 227,104 03-23-05 8:39p NCTPLWIZ.DLL
OPE32 DLL 227,104 03-23-05 8:39p OPE32.DLL
DNNMPNTW DLL 227,104 03-23-05 8:39p DNNMPNTW.DLL
SRSCLASS DLL 227,104 03-23-05 8:39p SRSCLASS.DLL
WXPLOC DLL 227,104 03-23-05 8:39p WXPLOC.DLL
DVGSIG DLL 227,104 03-23-05 8:39p DVGSIG.DLL
SAC DLL 227,104 03-23-05 8:39p SAC.DLL
SQC DLL 227,104 03-23-05 8:39p SQC.DLL
OJPRT400 DLL 227,104 03-23-05 8:39p OJPRT400.DLL
MNNET32 DLL 227,104 03-23-05 8:39p MNNET32.DLL
NUSWAN16 DLL 227,104 03-23-05 8:39p NUSWAN16.DLL
MLCUIW32 DLL 227,104 03-23-05 8:39p MLCUIW32.DLL
OLTWA400 DLL 227,104 03-23-05 8:39p OLTWA400.DLL
STLFX DLL 227,104 03-23-05 8:39p STLFX.DLL
IEETCFG DLL 227,104 03-23-05 8:39p IEETCFG.DLL
IKGSHL DLL 227,104 03-23-05 8:39p IKGSHL.DLL
IK50_32 DLL 227,104 03-23-05 8:39p IK50_32.DLL
WVBVW DLL 227,104 03-23-05 8:39p WVBVW.DLL
MMCRLREV DLL 227,104 03-23-05 8:39p mmcrlrev.dll
DWDRM DLL 227,104 03-23-05 8:39p DWDRM.DLL
MBDVDOPT DLL 227,104 03-23-05 8:39p MBDVDOPT.DLL
MVAFD DLL 227,104 03-23-05 8:39p MVAFD.DLL
NKTURE DLL 227,104 03-23-05 8:39p NKture.dll
AEIDDC DLL 227,104 03-23-05 8:39p AEIDDC.DLL
RCCHED20 DLL 227,104 03-23-05 8:39p RCCHED20.DLL
DJMSSPXN DLL 227,104 03-23-05 8:39p DJMSSPXN.DLL
JJEG1X32 DLL 227,104 03-23-05 8:39p JJEG1X32.DLL
WVICORE DLL 227,104 03-23-05 8:39p WVICORE.DLL
NKTPLWIZ DLL 227,104 03-23-05 8:39p NKTPLWIZ.DLL
MWTCP DLL 227,104 03-23-05 8:39p MWTCP.DLL
SATUPX32 DLL 227,104 03-23-05 8:39p SATUPX32.DLL
MAANG DLL 227,104 03-23-05 8:39p MAANG.DLL
IQETCFG DLL 227,104 03-23-05 8:39p IQETCFG.DLL
UFDM32 DLL 227,104 03-23-05 8:39p UFDM32.DLL
SQCUR32 DLL 227,104 03-23-05 8:39p SQCUR32.DLL
EHTIER2 DLL 227,104 03-23-05 8:39p EHTIER2.DLL
DHDMOPRP DLL 227,104 03-23-05 8:39p dhdmoprp.dll
KGRNEL32 DLL 227,104 03-23-05 8:39p KGRNEL32.DLL
GXU32 DLL 227,104 03-23-05 8:39p GXU32.DLL
DLSTYLE DLL 227,104 03-23-05 8:39p DLSTYLE.DLL
DGD3D01 DLL 227,104 03-23-05 8:39p DGD3D01.DLL
RTAENH DLL 227,104 03-23-05 8:39p RTAENH.DLL
HWOIMN07 DLL 227,104 03-23-05 8:39p HWOIMN07.DLL
MAVCRT DLL 227,104 03-23-05 8:39p MAVCRT.DLL
MUIMRT16 DLL 227,104 03-23-05 8:39p MUIMRT16.DLL
MBCI DLL 227,104 03-23-05 8:39p MBCI.DLL
MJEXCH40 DLL 227,104 03-23-05 8:39p MJEXCH40.DLL
IDM32 DLL 227,104 03-23-05 8:39p IDM32.DLL
ICSS DLL 227,104 03-23-05 8:39p ICSS.DLL
HKOPCL07 DLL 227,104 03-23-05 8:39p HKOPCL07.DLL
DQICM DLL 227,104 03-23-05 8:39p DQICM.DLL
OLMDSPIF DLL 227,104 03-23-05 8:39p OLMDSPIF.DLL
CORDS DLL 227,104 03-23-05 8:39p CORDS.DLL
DVVOICE DLL 227,104 03-23-05 8:39p DVVOICE.DLL
IDFRARED DLL 227,104 03-23-05 8:39p IDFRARED.DLL
MRUTILSE DLL 227,104 03-23-05 8:39p MRUTILSE.DLL
DGVVOX DLL 227,104 03-23-05 8:39p DGVVOX.DLL
MDIDENT DLL 227,104 03-23-05 8:39p mdident.dll
MRIDENT DLL 227,104 03-23-05 8:39p mrident.dll
PXPARSE DLL 227,104 03-23-05 8:39p PXPARSE.DLL
IVMUPG DLL 227,104 03-23-05 8:39p IVMUPG.DLL
SUCUR32 DLL 227,104 03-23-05 8:39p SUCUR32.DLL
DFMSTOR DLL 227,104 03-23-05 8:39p DFMSTOR.DLL
180 file(s) 40,618,341 bytes
0 dir(s) 25,927.69 MB free
------- Hidden Files in System Directory -------
Volume in drive C is 20040319
Volume Serial Number is 035C-1B08
Directory of C:\WINDOWS\SYSTEM
AUXDRV~1 ODS 5 07-23-05 10:01a AuxDrv32ds_k.ods
FOLDER HTT 23,155 03-24-05 11:19p folder.htt
DESKTOP INI 271 03-24-05 11:19p desktop.ini
3 file(s) 23,431 bytes
0 dir(s) 25,927.66 MB free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{AD650611-56B3-C9B3-94F4-0E5643E06385}"=""
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
wocthunk.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
arifil32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dhnmpntw.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
jneg1x32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
cpm.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
szell32.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
ceyptdlg.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
fysrch.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dpeml.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dccpcsvc.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dyvenum.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
maafd.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
mmafd.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
jldw400.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dtmsvinn.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
qpv.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
uyer32.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
crm.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
dnd8.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dlusic16.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
osui400.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
pfdrv.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
qjdwipes.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
ojmreg.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
zcort4as.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
swman32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dbmap.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
dlmstor.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
fxsion32.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
mxg4dmod.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
aaiv16xx.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
izengine.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
mbhtmled.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
jxngle.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
dadiagn.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
mvimrt.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
ioet16.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
maxml4a.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
gfide2x.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
lpouse32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
wk5inf32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
iaseng.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
cprds.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
sqncui.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
eftier2.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
iywphbk.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
mcrd2x40.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
damsvinn.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
atifil32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
drmsvinn.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
scndmail.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
gui32.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
cxmnctr.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
hnoimg07.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
md3216.dll Tue May 10 2005 5:24:08p ..S.R 226,592 221.28 K
ixmupg.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
sphannel.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
cerds.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
mxrating.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
mzoeacct.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
dd32gt.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
soge.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
wivcore.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
miutilse.dll Fri Jun 17 2005 12:03:42a ..S.R 226,080 220.78 K
mxdvdopt.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
srpdll.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
wfdmlog.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
nttplwiz.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
qjim32.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
oxgfs400.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
chseqchk.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
mhhtmled.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
da32gt.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
mqafd.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
myrtedit.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
riaenh.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
akiicdxx.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
nhwdev.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
ryrc32.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
wpashext.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
lrouse16.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
sllfx.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
waploc.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
rncltscm.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
cvm.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
dzvvox.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
wtadefui.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
afiicdxx.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
bdowselc.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
ivm32.dll Fri Jun 24 2005 3:53:54p ..S.R 227,104 221.78 K
dqvenum.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
srsinv.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
8e55indi.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
mddocs.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
njwdev.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
vedx16.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
cputoa.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
mgr2c.dll Mon Jul 11 2005 6:06:44p ..S.R 227,104 221.78 K
wfplenc.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
oaesvr.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
ithlpapi.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
jgvaee.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
mytcp.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
mbincp16.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
ddndi.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
myci.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
chmnew.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
acipdlxx.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
sbcur32.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
wricore.dll Sun Jul 17 2005 12:06:16a ..S.R 227,616 222.28 K
cdoosusr.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
ckutoa.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
auxdrv~1.ods Sat Jul 23 2005 10:01:58a A.SH. 5 0.00 K
dwmm.dll Sat Jul 23 2005 9:59:02a ..S.R 226,080 220.78 K
114 items found: 114 files, 0 directories.
Total of file sizes: 25,629,477 bytes 24.44 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\USER.DAT: Find_Qoologic2.zip
C:\WINDOWS\USER.DAT: Find_Qoologic2.zip
C:\WINDOWS\USER.DAT: Find_Qoologic2
C:\WINDOWS\USER.DAT: Find_Qoologic2
C:\WINDOWS\USER.DAT: Find-Qoologic
C:\WINDOWS\USER.DAT: aFind-Qoologic
C:\WINDOWS\USER.DAT: Find-Qoologic.lnk
C:\WINDOWS\USER.DAT: qoologic trojan
C:\WINDOWS\USER.DAT: qoologic trojan removal
C:\WINDOWS\USER.DAT: pFind_Qoologic2.zip
C:\WINDOWS\USER.DAT: Find_Qoologic2.zip.lnk
C:\WINDOWS\USER.DAT: rFind-Qoologic
C:\WINDOWS\USER.DAT: Find-Qoologic.lnk
C:\WINDOWS\USER.DAT: jC:\WINDOWS\Desktop\Find_Qoologic2.zipic2.zip
C:\WINDOWS\USER.DAT: cFind_Qoologic2.zip
C:\WINDOWS\USER.DAT: Find_Qoologic2.zip.lnk
C:\WINDOWS\USER.DAT: cC:\WINDOWS\Desktop\Find_Qoologic2.zip
C:\WINDOWS\USER.DAT: cFind_Qoologic2.zip
C:\WINDOWS\USER.DAT: Find_Qoologic2.zip.lnk
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.P
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.N
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.I
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.E
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.D
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.G
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.C
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.B
C:\WINDOWS\VPTNFILE.741: TROJ_QOOLOGIC.A
C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.P
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.N
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.I
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.E
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.D
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.G
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.C
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.B
C:\WINDOWS\lpt$vpn.741: TROJ_QOOLOGIC.A
C:\WINDOWS\SYSTEM\pav.sig: Qoologic
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\vsapi32.dll: ASPACK EXE
C:\WINDOWS\vsapi32.dll: ASPACK2 EXE
C:\WINDOWS\vsapi32.dll: ASPack 1.08.04
C:\WINDOWS\vsapi32.dll: ASPack 1.08.03
C:\WINDOWS\vsapi32.dll: ASPack 1.08.02b
C:\WINDOWS\vsapi32.dll: ASPack 1.08.01
C:\WINDOWS\vsapi32.dll: ASPack 1.08
C:\WINDOWS\vsapi32.dll: ASPack 1.07b
C:\WINDOWS\vsapi32.dll: ASPack 1.61
C:\WINDOWS\vsapi32.dll: ASPack 1.05b
C:\WINDOWS\vsapi32.dll: ASPack 1.03
C:\WINDOWS\vsapi32.dll: ASPack 1.02
C:\WINDOWS\vsapi32.dll: ASPack 1.01
C:\WINDOWS\vsapi32.dll: ASPack 1.00
C:\WINDOWS\SYSTEM\pav.sig: .aspack
C:\WINDOWS\SYSTEM\pav.sig: :.aspackze
C:\WINDOWS\SYSTEM\pav.sig: .aspack.text
C:\WINDOWS\SYSTEM\pav.sig: H.aspack.text
C:\WINDOWS\SYSTEM\pav.sig: .aspack.text
C:\WINDOWS\SYSTEM\pav.sig: 4.aspack
C:\WINDOWS\SYSTEM\pav.sig: F<SW.aspack
C:\WINDOWS\SYSTEM\pav.sig: [.aspack
C:\WINDOWS\SYSTEM\pav.sig: .aspack0
C:\WINDOWS\SYSTEM\pav.sig: .aspack
C:\WINDOWS\SYSTEM\pav.sig: .aspack
C:\WINDOWS\SYSTEM\pav.sig:
[email protected]
C:\WINDOWS\SYSTEM\pav.sig: AsPack
----------------- HKLM Run Key ------------------
-------------- Strings.exe Umonitor Results -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"PCHealth"="C:\\WINDOWS\\PCHealth\\Support\\PCHSchd.exe -s"
"SystemTray"="SysTray.Exe"
"Logitech Utility"="Logi_MwX.Exe"
"LoadQM"="loadqm.exe"
"QuickTime Task"="\"C:\\WINDOWS\\SYSTEM\\QTTASK.EXE\" -atboottime"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"msnappau"="\"C:\\Program Files\\MSN Apps\\Updater\\01.03.0000.1005\\en-us\\msnappau.exe\""
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"