Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: C:\Documents and Settings\Anderson Dental\My Documents\dwnld\Find It NT-2K-XP\Find It NT-2K-XP
------- System Files in System32 Directory -------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 10:43 AM 224,796 j00s0ad7ed0.dll
01/24/2005 10:40 AM <DIR> dllcache
01/19/2005 02:16 PM 222,670 WYDMPS.dll
01/19/2005 02:14 PM 222,611 enpql1751.dll
01/17/2005 12:35 PM 225,802 wvnnls.dll
01/17/2005 12:31 PM 222,690 hr6u05j9e.dll
01/17/2005 12:28 PM 224,285 wkw32.dll
01/17/2005 09:56 AM 225,802 CqMp3Lib.dll
01/15/2005 01:54 PM 224,285 rJsrad.dll
01/14/2005 01:25 PM 223,190 g040lahm1d4a.dll
01/14/2005 01:17 PM 223,190 swardssp.dll
01/14/2005 12:54 PM 222,906 mffutil.dll
01/14/2005 12:19 PM 225,088 pvgfilt.dll
01/14/2005 12:10 PM 225,748 li32.dll
01/14/2005 12:03 PM 225,088 mktext40.dll
01/14/2005 11:59 AM 225,088 wcaueng.dll
01/14/2005 11:59 AM 225,447 lvno0953e.dll
01/14/2005 11:42 AM 224,238 ombcjt32.dll
01/14/2005 11:39 AM 225,849 dmmasf.dll
01/14/2005 11:22 AM 224,238 wuspdmod.dll
01/14/2005 11:04 AM 225,849 mjbsync.dll
01/14/2005 10:57 AM 224,238 mupbde40.dll
01/14/2005 10:47 AM 225,849 dCdxof.dll
01/14/2005 10:08 AM 224,238 rwfsaps.dll
01/14/2005 09:53 AM 224,430 sbhannel.dll
01/14/2005 08:34 AM 224,238 vqhelper.dll
01/13/2005 11:36 AM 7,168 Thumbs.db
01/13/2005 09:14 AM 224,430 kydpo.dll
01/12/2005 08:38 AM 224,238 hvoipr07.dll
01/11/2005 01:07 PM 226,024 izwdial.dll
01/11/2005 08:59 AM 224,238 immui.dll
01/10/2005 11:43 AM 226,024 ofuninst.dll
01/10/2005 10:58 AM 224,238 nqrssk.dll
01/10/2005 09:08 AM 224,238 iw41_qcx.dll
01/10/2005 09:07 AM 223,203 en4ql1h51.dll
01/10/2005 08:52 AM 223,203 cwbcatex.dll
01/10/2005 08:30 AM 223,203 kfdcz2.dll
01/07/2005 09:45 AM 225,752 mv40l9hm1.dll
01/07/2005 09:12 AM 223,203 srmpapi.dll
01/07/2005 08:48 AM 225,752 mgcpxl32.dLL
01/06/2005 09:35 AM 222,998 HFOtap07.dll
01/05/2005 09:22 AM 225,752 dPdim700.dll
01/05/2005 08:55 AM 222,998 oneprn.dll
01/04/2005 03:41 PM 225,752 mjtask.dll
01/04/2005 09:21 AM 225,634 amthz.dll
12/23/2004 09:03 AM 225,752 wjsdmoe.dll
12/22/2004 08:37 AM 225,634 mlports.dll
12/21/2004 09:11 AM 225,250 sFmlib.dll
12/20/2004 09:00 AM 224,257 ir20l5fm1.dll
07/27/2002 06:27 PM <DIR> Microsoft
48 File(s) 10,560,794 bytes
2 Dir(s) 5,578,973,184 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 10:40 AM <DIR> dllcache
01/13/2005 11:36 AM 7,168 Thumbs.db
07/31/2002 12:16 PM <DIR> GroupPolicy
07/19/2002 09:14 PM 488 WindowsLogon.manifest
07/19/2002 09:14 PM 488 logonui.exe.manifest
07/19/2002 09:14 PM 749 wuaucpl.cpl.manifest
07/19/2002 09:14 PM 749 cdplayer.exe.manifest
07/19/2002 09:14 PM 749 ncpa.cpl.manifest
07/19/2002 09:14 PM 749 nwc.cpl.manifest
07/19/2002 09:14 PM 749 sapi.cpl.manifest
8 File(s) 11,889 bytes
2 Dir(s) 5,578,973,184 bytes free
---------- Files Named "Guard" -------------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 01:47 PM 224,096 guard.tmp
1 File(s) 224,096 bytes
0 Dir(s) 5,578,969,088 bytes free
--------- Temp Files in System32 Directory --------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 01:47 PM 224,096 guard.tmp
08/03/2004 11:56 PM 1,236,480 msxml3.dll.tmp
08/23/2001 07:00 AM 2,577 CONFIG.TMP
3 File(s) 1,463,153 bytes
0 Dir(s) 5,578,969,088 bytes free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6AD29D9C-B235-4DCE-8533-FEA6CB45D366}"=""
------------ Keys Under Notify ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MS-DOS Emulation]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\m4po0e73eh.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM32\
amthz.dll Tue Jan 4 2005 9:21:16a ..S.R 225,634 220.34 K
cqmp3lib.dll Mon Jan 17 2005 9:56:32a ..S.R 225,802 220.51 K
cwbcatex.dll Mon Jan 10 2005 8:52:12a ..S.R 223,203 217.97 K
dcdxof.dll Fri Jan 14 2005 10:47:38a ..S.R 225,849 220.55 K
dmmasf.dll Fri Jan 14 2005 11:39:04a ..S.R 225,849 220.55 K
dpdim700.dll Wed Jan 5 2005 9:22:44a ..S.R 225,752 220.46 K
hfotap07.dll Thu Jan 6 2005 9:36:00a ..S.R 222,998 217.77 K
hvoipr07.dll Wed Jan 12 2005 8:38:14a ..S.R 224,238 218.98 K
immui.dll Tue Jan 11 2005 8:59:36a ..S.R 224,238 218.98 K
iw41_qcx.dll Mon Jan 10 2005 9:08:22a ..S.R 224,238 218.98 K
izwdial.dll Tue Jan 11 2005 1:07:40p ..S.R 226,024 220.73 K
kfdcz2.dll Mon Jan 10 2005 8:30:54a ..S.R 223,203 217.97 K
kydpo.dll Thu Jan 13 2005 9:14:12a ..S.R 224,430 219.17 K
li32.dll Fri Jan 14 2005 12:10:04p ..S.R 225,748 220.46 K
mffutil.dll Fri Jan 14 2005 12:54:12p ..S.R 222,906 217.68 K
mgcpxl32.dll Fri Jan 7 2005 8:48:24a ..S.R 225,752 220.46 K
mjbsync.dll Fri Jan 14 2005 11:04:34a ..S.R 225,849 220.55 K
mjtask.dll Tue Jan 4 2005 3:41:54p ..S.R 225,752 220.46 K
mktext40.dll Fri Jan 14 2005 12:03:36p ..S.R 225,088 219.81 K
mlports.dll Wed Dec 22 2004 8:37:06a ..S.R 225,634 220.34 K
mupbde40.dll Fri Jan 14 2005 10:57:48a ..S.R 224,238 218.98 K
nqrssk.dll Mon Jan 10 2005 10:58:26a ..S.R 224,238 218.98 K
ofuninst.dll Mon Jan 10 2005 11:43:50a ..S.R 226,024 220.73 K
ombcjt32.dll Fri Jan 14 2005 11:42:30a ..S.R 224,238 218.98 K
oneprn.dll Wed Jan 5 2005 8:55:26a ..S.R 222,998 217.77 K
pvgfilt.dll Fri Jan 14 2005 12:19:32p ..S.R 225,088 219.81 K
rjsrad.dll Sat Jan 15 2005 1:54:28p ..S.R 224,285 219.03 K
rwfsaps.dll Fri Jan 14 2005 10:08:16a ..S.R 224,238 218.98 K
sbhannel.dll Fri Jan 14 2005 9:53:38a ..S.R 224,430 219.17 K
sfmlib.dll Tue Dec 21 2004 9:11:34a ..S.R 225,250 219.97 K
srmpapi.dll Fri Jan 7 2005 9:12:14a ..S.R 223,203 217.97 K
swardssp.dll Fri Jan 14 2005 1:17:58p ..S.R 223,190 217.96 K
thumbs.db Thu Jan 13 2005 11:36:26a A.SH. 7,168 7.00 K
vqhelper.dll Fri Jan 14 2005 8:34:58a ..S.R 224,238 218.98 K
wcaueng.dll Fri Jan 14 2005 11:59:28a ..S.R 225,088 219.81 K
wjsdmoe.dll Thu Dec 23 2004 9:03:22a ..S.R 225,752 220.46 K
wkw32.dll Mon Jan 17 2005 12:28:12p ..S.R 224,285 219.03 K
wuspdmod.dll Fri Jan 14 2005 11:22:48a ..S.R 224,238 218.98 K
wvnnls.dll Mon Jan 17 2005 12:35:28p ..S.R 225,802 220.51 K
wydmps.dll Wed Jan 19 2005 2:16:34p ..S.R 222,670 217.45 K
40 items found: 40 files, 0 directories.
Total of file sizes: 8,768,848 bytes 8.36 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\system32\pav.sig: Qoologic
C:\WINDOWS\system32\pav.sig: Qoologic
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\system32\pav.sig: AsPack
----------------- HKLM Run Key ------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"B'sCLiP"="C:\\PROGRA~1\\B'SCLI~1\\Win2K\\BSCLIP.exe"
"Disc Detector"="C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"
"AHQInit"="C:\\Program Files\\Creative\\SBLive\\Program\\AHQInit.exe"
"AudioHQ"="C:\\Program Files\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Gainward"="C:\\WINDOWS\\TBPanel.exe /A"
"Logitech Utility"="Logi_MwX.Exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG Free\\avgcc.exe /STARTUP"
"gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
Also my find it log
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: C:\Documents and Settings\Anderson Dental\My Documents\dwnld\Find It NT-2K-XP\Find It NT-2K-XP
------- System Files in System32 Directory -------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 10:43 AM 224,796 j00s0ad7ed0.dll
01/24/2005 10:40 AM <DIR> dllcache
01/19/2005 02:16 PM 222,670 WYDMPS.dll
01/19/2005 02:14 PM 222,611 enpql1751.dll
01/17/2005 12:35 PM 225,802 wvnnls.dll
01/17/2005 12:31 PM 222,690 hr6u05j9e.dll
01/17/2005 12:28 PM 224,285 wkw32.dll
01/17/2005 09:56 AM 225,802 CqMp3Lib.dll
01/15/2005 01:54 PM 224,285 rJsrad.dll
01/14/2005 01:25 PM 223,190 g040lahm1d4a.dll
01/14/2005 01:17 PM 223,190 swardssp.dll
01/14/2005 12:54 PM 222,906 mffutil.dll
01/14/2005 12:19 PM 225,088 pvgfilt.dll
01/14/2005 12:10 PM 225,748 li32.dll
01/14/2005 12:03 PM 225,088 mktext40.dll
01/14/2005 11:59 AM 225,088 wcaueng.dll
01/14/2005 11:59 AM 225,447 lvno0953e.dll
01/14/2005 11:42 AM 224,238 ombcjt32.dll
01/14/2005 11:39 AM 225,849 dmmasf.dll
01/14/2005 11:22 AM 224,238 wuspdmod.dll
01/14/2005 11:04 AM 225,849 mjbsync.dll
01/14/2005 10:57 AM 224,238 mupbde40.dll
01/14/2005 10:47 AM 225,849 dCdxof.dll
01/14/2005 10:08 AM 224,238 rwfsaps.dll
01/14/2005 09:53 AM 224,430 sbhannel.dll
01/14/2005 08:34 AM 224,238 vqhelper.dll
01/13/2005 11:36 AM 7,168 Thumbs.db
01/13/2005 09:14 AM 224,430 kydpo.dll
01/12/2005 08:38 AM 224,238 hvoipr07.dll
01/11/2005 01:07 PM 226,024 izwdial.dll
01/11/2005 08:59 AM 224,238 immui.dll
01/10/2005 11:43 AM 226,024 ofuninst.dll
01/10/2005 10:58 AM 224,238 nqrssk.dll
01/10/2005 09:08 AM 224,238 iw41_qcx.dll
01/10/2005 09:07 AM 223,203 en4ql1h51.dll
01/10/2005 08:52 AM 223,203 cwbcatex.dll
01/10/2005 08:30 AM 223,203 kfdcz2.dll
01/07/2005 09:45 AM 225,752 mv40l9hm1.dll
01/07/2005 09:12 AM 223,203 srmpapi.dll
01/07/2005 08:48 AM 225,752 mgcpxl32.dLL
01/06/2005 09:35 AM 222,998 HFOtap07.dll
01/05/2005 09:22 AM 225,752 dPdim700.dll
01/05/2005 08:55 AM 222,998 oneprn.dll
01/04/2005 03:41 PM 225,752 mjtask.dll
01/04/2005 09:21 AM 225,634 amthz.dll
12/23/2004 09:03 AM 225,752 wjsdmoe.dll
12/22/2004 08:37 AM 225,634 mlports.dll
12/21/2004 09:11 AM 225,250 sFmlib.dll
12/20/2004 09:00 AM 224,257 ir20l5fm1.dll
07/27/2002 06:27 PM <DIR> Microsoft
48 File(s) 10,560,794 bytes
2 Dir(s) 5,578,973,184 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 10:40 AM <DIR> dllcache
01/13/2005 11:36 AM 7,168 Thumbs.db
07/31/2002 12:16 PM <DIR> GroupPolicy
07/19/2002 09:14 PM 488 WindowsLogon.manifest
07/19/2002 09:14 PM 488 logonui.exe.manifest
07/19/2002 09:14 PM 749 wuaucpl.cpl.manifest
07/19/2002 09:14 PM 749 cdplayer.exe.manifest
07/19/2002 09:14 PM 749 ncpa.cpl.manifest
07/19/2002 09:14 PM 749 nwc.cpl.manifest
07/19/2002 09:14 PM 749 sapi.cpl.manifest
8 File(s) 11,889 bytes
2 Dir(s) 5,578,973,184 bytes free
---------- Files Named "Guard" -------------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 01:47 PM 224,096 guard.tmp
1 File(s) 224,096 bytes
0 Dir(s) 5,578,969,088 bytes free
--------- Temp Files in System32 Directory --------
Volume in drive C is Primary
Volume Serial Number is 4C99-C904
Directory of C:\WINDOWS\System32
01/24/2005 01:47 PM 224,096 guard.tmp
08/03/2004 11:56 PM 1,236,480 msxml3.dll.tmp
08/23/2001 07:00 AM 2,577 CONFIG.TMP
3 File(s) 1,463,153 bytes
0 Dir(s) 5,578,969,088 bytes free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6AD29D9C-B235-4DCE-8533-FEA6CB45D366}"=""
------------ Keys Under Notify ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MS-DOS Emulation]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\m4po0e73eh.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM32\
amthz.dll Tue Jan 4 2005 9:21:16a ..S.R 225,634 220.34 K
cqmp3lib.dll Mon Jan 17 2005 9:56:32a ..S.R 225,802 220.51 K
cwbcatex.dll Mon Jan 10 2005 8:52:12a ..S.R 223,203 217.97 K
dcdxof.dll Fri Jan 14 2005 10:47:38a ..S.R 225,849 220.55 K
dmmasf.dll Fri Jan 14 2005 11:39:04a ..S.R 225,849 220.55 K
dpdim700.dll Wed Jan 5 2005 9:22:44a ..S.R 225,752 220.46 K
hfotap07.dll Thu Jan 6 2005 9:36:00a ..S.R 222,998 217.77 K
hvoipr07.dll Wed Jan 12 2005 8:38:14a ..S.R 224,238 218.98 K
immui.dll Tue Jan 11 2005 8:59:36a ..S.R 224,238 218.98 K
iw41_qcx.dll Mon Jan 10 2005 9:08:22a ..S.R 224,238 218.98 K
izwdial.dll Tue Jan 11 2005 1:07:40p ..S.R 226,024 220.73 K
kfdcz2.dll Mon Jan 10 2005 8:30:54a ..S.R 223,203 217.97 K
kydpo.dll Thu Jan 13 2005 9:14:12a ..S.R 224,430 219.17 K
li32.dll Fri Jan 14 2005 12:10:04p ..S.R 225,748 220.46 K
mffutil.dll Fri Jan 14 2005 12:54:12p ..S.R 222,906 217.68 K
mgcpxl32.dll Fri Jan 7 2005 8:48:24a ..S.R 225,752 220.46 K
mjbsync.dll Fri Jan 14 2005 11:04:34a ..S.R 225,849 220.55 K
mjtask.dll Tue Jan 4 2005 3:41:54p ..S.R 225,752 220.46 K
mktext40.dll Fri Jan 14 2005 12:03:36p ..S.R 225,088 219.81 K
mlports.dll Wed Dec 22 2004 8:37:06a ..S.R 225,634 220.34 K
mupbde40.dll Fri Jan 14 2005 10:57:48a ..S.R 224,238 218.98 K
nqrssk.dll Mon Jan 10 2005 10:58:26a ..S.R 224,238 218.98 K
ofuninst.dll Mon Jan 10 2005 11:43:50a ..S.R 226,024 220.73 K
ombcjt32.dll Fri Jan 14 2005 11:42:30a ..S.R 224,238 218.98 K
oneprn.dll Wed Jan 5 2005 8:55:26a ..S.R 222,998 217.77 K
pvgfilt.dll Fri Jan 14 2005 12:19:32p ..S.R 225,088 219.81 K
rjsrad.dll Sat Jan 15 2005 1:54:28p ..S.R 224,285 219.03 K
rwfsaps.dll Fri Jan 14 2005 10:08:16a ..S.R 224,238 218.98 K
sbhannel.dll Fri Jan 14 2005 9:53:38a ..S.R 224,430 219.17 K
sfmlib.dll Tue Dec 21 2004 9:11:34a ..S.R 225,250 219.97 K
srmpapi.dll Fri Jan 7 2005 9:12:14a ..S.R 223,203 217.97 K
swardssp.dll Fri Jan 14 2005 1:17:58p ..S.R 223,190 217.96 K
thumbs.db Thu Jan 13 2005 11:36:26a A.SH. 7,168 7.00 K
vqhelper.dll Fri Jan 14 2005 8:34:58a ..S.R 224,238 218.98 K
wcaueng.dll Fri Jan 14 2005 11:59:28a ..S.R 225,088 219.81 K
wjsdmoe.dll Thu Dec 23 2004 9:03:22a ..S.R 225,752 220.46 K
wkw32.dll Mon Jan 17 2005 12:28:12p ..S.R 224,285 219.03 K
wuspdmod.dll Fri Jan 14 2005 11:22:48a ..S.R 224,238 218.98 K
wvnnls.dll Mon Jan 17 2005 12:35:28p ..S.R 225,802 220.51 K
wydmps.dll Wed Jan 19 2005 2:16:34p ..S.R 222,670 217.45 K
40 items found: 40 files, 0 directories.
Total of file sizes: 8,768,848 bytes 8.36 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\system32\pav.sig: Qoologic
C:\WINDOWS\system32\pav.sig: Qoologic
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\system32\pav.sig: AsPack
----------------- HKLM Run Key ------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"B'sCLiP"="C:\\PROGRA~1\\B'SCLI~1\\Win2K\\BSCLIP.exe"
"Disc Detector"="C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"
"AHQInit"="C:\\Program Files\\Creative\\SBLive\\Program\\AHQInit.exe"
"AudioHQ"="C:\\Program Files\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Gainward"="C:\\WINDOWS\\TBPanel.exe /A"
"Logitech Utility"="Logi_MwX.Exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG Free\\avgcc.exe /STARTUP"
"gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
CAN SOMEONE PLEASE HELP ME!!!