Done it. Deleted old findit, downloaded and run the new one. Here's the log:
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
------- System Files in System Directory -------
Volume in drive C is HARD DISK
Volume Serial Number is 0211-1CDD
Directory of C:\WINDOWS\SYSTEM
IFMUPG DLL 227,104 15/03/05 19:21 IFMUPG.DLL
MXRPJT40 DLL 227,104 15/03/05 19:21 MXRPJT40.DLL
WFPLENC DLL 227,104 15/03/05 19:21 wfplenc.dll
WMKYSF EXE 401,408 11/01/05 14:11 wmkysf.exe
4 file(s) 1,082,720 bytes
0 dir(s) 1,642.37 MB free
------- Hidden Files in System Directory -------
Volume in drive C is HARD DISK
Volume Serial Number is 0211-1CDD
Directory of C:\WINDOWS\SYSTEM
BAND EXE 1,024 15/03/05 13:45 band.exe
VMSS <DIR> 03/03/05 16:32 vmss
WSXSVC <DIR> 03/03/05 16:32 wsxsvc
WMKYSF EXE 401,408 11/01/05 14:11 wmkysf.exe
ZLLICTBL DAT 4,212 27/11/04 17:12 zllictbl.dat
LXAIMA GID 45,735 05/02/04 19:10 lxaima.GID
DESKTOP INI 266 15/01/02 21:37 desktop.ini
5 file(s) 452,645 bytes
2 dir(s) 1,642.37 MB free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F06B1D22-1EDC-6EC8-A9F6-713D02526492}"=""
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
ifmupg.dll Tue 15 Mar 2005 19:21:54 ..S.R 227,104 221.78 K
wmkysf.exe Tue 11 Jan 2005 14:11:36 ..SHR 401,408 392.00 K
mxrpjt40.dll Tue 15 Mar 2005 19:21:54 ..S.R 227,104 221.78 K
band.exe Tue 15 Mar 2005 13:45:14 ...H. 1,024 1.00 K
wfplenc.dll Tue 15 Mar 2005 19:21:54 ..S.R 227,104 221.78 K
5 items found: 5 files, 0 directories.
Total of file sizes: 1,083,744 bytes 1.03 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\hosts.bak: 127.0.0.1 u.clkoptimizer.com #[Trojan-Downloader.Win32.Qoologic.f]
C:\WINDOWS\hosts.bak: 127.0.0.1 qoologic.com
C:\WINDOWS\hosts.bak: 127.0.0.1 adsrv.qoologic.com
C:\WINDOWS\hosts.bak: 127.0.0.1 updates.qoologic.com
C:\WINDOWS\hosts.bak: 127.0.0.1
www.qoologic.comC:\WINDOWS\hosts.20050311-185347.backup: 127.0.0.1 u.clkoptimizer.com #[Trojan-Downloader.Win32.Qoologic.f]
C:\WINDOWS\hosts.20050311-185347.backup: 127.0.0.1 qoologic.com
C:\WINDOWS\hosts.20050311-185347.backup: 127.0.0.1 adsrv.qoologic.com
C:\WINDOWS\hosts.20050311-185347.backup: 127.0.0.1 updates.qoologic.com #[TROJ_NARRATOR.A]
C:\WINDOWS\hosts.20050311-185347.backup: 127.0.0.1
www.qoologic.comC:\WINDOWS\hosts.20050311-185348.backup: 127.0.0.1 u.clkoptimizer.com #[Trojan-Downloader.Win32.Qoologic.f]
C:\WINDOWS\hosts.20050311-185348.backup: 127.0.0.1 qoologic.com
C:\WINDOWS\hosts.20050311-185348.backup: 127.0.0.1 adsrv.qoologic.com
C:\WINDOWS\hosts.20050311-185348.backup: 127.0.0.1 updates.qoologic.com #[TROJ_NARRATOR.A]
C:\WINDOWS\hosts.20050311-185348.backup: 127.0.0.1
www.qoologic.comC:\WINDOWS\hosts.20050311-190703.backup: 127.0.0.1 u.clkoptimizer.com #[Trojan-Downloader.Win32.Qoologic.f]
C:\WINDOWS\hosts.20050311-190703.backup: 127.0.0.1 qoologic.com
C:\WINDOWS\hosts.20050311-190703.backup: 127.0.0.1 adsrv.qoologic.com
C:\WINDOWS\hosts.20050311-190703.backup: 127.0.0.1 updates.qoologic.com #[TROJ_NARRATOR.A]
C:\WINDOWS\hosts.20050311-190703.backup: 127.0.0.1
www.qoologic.comC:\WINDOWS\hosts.20050311-191938.backup: 127.0.0.1 u.clkoptimizer.com #[Trojan-Downloader.Win32.Qoologic.f]
C:\WINDOWS\hosts.20050311-191938.backup: 127.0.0.1 qoologic.com
C:\WINDOWS\hosts.20050311-191938.backup: 127.0.0.1 adsrv.qoologic.com
C:\WINDOWS\hosts.20050311-191938.backup: 127.0.0.1 updates.qoologic.com #[TROJ_NARRATOR.A]
C:\WINDOWS\hosts.20050311-191938.backup: 127.0.0.1
www.qoologic.com -------------- Strings.exe Aspack Results -------------
----------------- HKLM Run Key ------------------
-------------- Strings.exe Umonitor Results -------------
C:\WINDOWS\SYSTEM\QMV.DLL: UMonitor
C:\WINDOWS\SYSTEM\RKCLTSCM.DLL: UMonitor
C:\WINDOWS\SYSTEM\OVADM400.DLL: UMonitor
C:\WINDOWS\SYSTEM\PASPL.DLL: UMonitor
C:\WINDOWS\SYSTEM\MYCMS.DLL: UMonitor
C:\WINDOWS\SYSTEM\NNTBIOS.DLL: UMonitor
C:\WINDOWS\SYSTEM\ADVGA.DLL: UMonitor
C:\WINDOWS\SYSTEM\PWPD.DLL: UMonitor
C:\WINDOWS\SYSTEM\MHXML3.DLL: UMonitor
C:\WINDOWS\SYSTEM\DYIMAN32.DLL: UMonitor
C:\WINDOWS\SYSTEM\ilvu9_32.dll: UMonitor
C:\WINDOWS\SYSTEM\OSESVR.DLL: UMonitor
C:\WINDOWS\SYSTEM\RYCDLL.dll: UMonitor
C:\WINDOWS\SYSTEM\RICLTSPX.DLL: UMonitor
C:\WINDOWS\SYSTEM\wjspdmoe.dll: UMonitor
C:\WINDOWS\SYSTEM\IQNPSTUB.DLL: UMonitor
C:\WINDOWS\SYSTEM\DVKMAINT.DLL: UMonitor
C:\WINDOWS\SYSTEM\AZF16.DLL: UMonitor
C:\WINDOWS\SYSTEM\OZE2DISP.DLL: UMonitor
C:\WINDOWS\SYSTEM\MXSTKPRP.DLL: UMonitor
C:\WINDOWS\SYSTEM\dq8vb.dll: UMonitor
C:\WINDOWS\SYSTEM\MMTASK.DLL: UMonitor
C:\WINDOWS\SYSTEM\lWprxy.dll: UMonitor
C:\WINDOWS\SYSTEM\wpv9vcm.dll: UMonitor
C:\WINDOWS\SYSTEM\DLRAW.DLL: UMonitor
C:\WINDOWS\SYSTEM\phapi.dll: UMonitor
C:\WINDOWS\SYSTEM\lyailpa.dll: UMonitor
C:\WINDOWS\SYSTEM\lbaisk0.dll: UMonitor
C:\WINDOWS\SYSTEM\DOVENUM.DLL: UMonitor
C:\WINDOWS\SYSTEM\CKMCAT.DLL: UMonitor
C:\WINDOWS\SYSTEM\iiagr5.dll: UMonitor
C:\WINDOWS\SYSTEM\mIpi32.dll: UMonitor
C:\WINDOWS\SYSTEM\dfscript.dll: UMonitor
C:\WINDOWS\SYSTEM\DACPROP.DLL: UMonitor
C:\WINDOWS\SYSTEM\dy8vb.dll: UMonitor
C:\WINDOWS\SYSTEM\MGCO30.DLL: UMonitor
C:\WINDOWS\SYSTEM\WKW32.DLL: UMonitor
C:\WINDOWS\SYSTEM\MCXML3.DLL: UMonitor
C:\WINDOWS\SYSTEM\dfmv2clt.dll: UMonitor
C:\WINDOWS\SYSTEM\DLngerous Creatures.dll: UMonitor
C:\WINDOWS\SYSTEM\WRDAP32.DLL: UMonitor
C:\WINDOWS\SYSTEM\ppgfilt.dll: UMonitor
C:\WINDOWS\SYSTEM\mzexch40.dll: UMonitor
C:\WINDOWS\SYSTEM\CAOOSUSR.DLL: UMonitor
C:\WINDOWS\SYSTEM\MLMG13W.DLL: UMonitor
C:\WINDOWS\SYSTEM\ocpdx32.dll: UMonitor
C:\WINDOWS\SYSTEM\MUCI.DLL: UMonitor
C:\WINDOWS\SYSTEM\DSSERIAL.DLL: UMonitor
C:\WINDOWS\SYSTEM\OYFIL400.DLL: UMonitor
C:\WINDOWS\SYSTEM\MMRPJT40.DLL: UMonitor
C:\WINDOWS\SYSTEM\mbpatcha.dll: UMonitor
C:\WINDOWS\SYSTEM\DNrtWeb.dll: UMonitor
C:\WINDOWS\SYSTEM\TNOLHELP.DLL: UMonitor
C:\WINDOWS\SYSTEM\VPODEC32.DLL: UMonitor
C:\WINDOWS\SYSTEM\lvaiutil.dll: UMonitor
C:\WINDOWS\SYSTEM\DDGEST.DLL: UMonitor
C:\WINDOWS\SYSTEM\RVCRT4.DLL: UMonitor
C:\WINDOWS\SYSTEM\dNdim700.dll: UMonitor
C:\WINDOWS\SYSTEM\mibsync.dll: UMonitor
C:\WINDOWS\SYSTEM\SDI_CI32.DLL: UMonitor
C:\WINDOWS\SYSTEM\lsaixc.dll: UMonitor
C:\WINDOWS\SYSTEM\VQAJET32.DLL: UMonitor
C:\WINDOWS\SYSTEM\DIKAPI32.DLL: UMonitor
C:\WINDOWS\SYSTEM\wppcd.dll: UMonitor
C:\WINDOWS\SYSTEM\VFR.DLL: UMonitor
C:\WINDOWS\SYSTEM\SBI_CI32.DLL: UMonitor
C:\WINDOWS\SYSTEM\SOTUPX.DLL: UMonitor
C:\WINDOWS\SYSTEM\dGdref.dll: UMonitor
C:\WINDOWS\SYSTEM\MP3216.DLL: UMonitor
C:\WINDOWS\SYSTEM\LRBAS06.DLL: UMonitor
C:\WINDOWS\SYSTEM\MQFS13W.DLL: UMonitor
C:\WINDOWS\SYSTEM\lsxlmpm.dll: UMonitor
C:\WINDOWS\SYSTEM\SUKIT432.DLL: UMonitor
C:\WINDOWS\SYSTEM\sfrrun.dll: UMonitor
C:\WINDOWS\SYSTEM\QJHNDLR.DLL: UMonitor
C:\WINDOWS\SYSTEM\RLCMQSVR.DLL: UMonitor
C:\WINDOWS\SYSTEM\ITGUTIL.DLL: UMonitor
C:\WINDOWS\SYSTEM\CFYPTUI.DLL: UMonitor
C:\WINDOWS\SYSTEM\liaijswr.dll: UMonitor
C:\WINDOWS\SYSTEM\DVGEST.DLL: UMonitor
C:\WINDOWS\SYSTEM\LUNKINFO.DLL: UMonitor
C:\WINDOWS\SYSTEM\akfsipc.dll: UMonitor
C:\WINDOWS\SYSTEM\IZMIGRAT.DLL: UMonitor
C:\WINDOWS\SYSTEM\JGEG2X32.DLL: UMonitor
C:\WINDOWS\SYSTEM\DRWSOCKX.DLL: UMonitor
C:\WINDOWS\SYSTEM\WK2_32.DLL: UMonitor
C:\WINDOWS\SYSTEM\SXTUP4.DLL: UMonitor
C:\WINDOWS\SYSTEM\SPCUR32.DLL: UMonitor
C:\WINDOWS\SYSTEM\orbcbcp.dll: UMonitor
C:\WINDOWS\SYSTEM\WJNTRUST.DLL: UMonitor
C:\WINDOWS\SYSTEM\MLCMS.DLL: UMonitor
C:\WINDOWS\SYSTEM\WLW32.DLL: UMonitor
C:\WINDOWS\SYSTEM\DQSERIAL.DLL: UMonitor
C:\WINDOWS\SYSTEM\DHCNDI.DLL: UMonitor
C:\WINDOWS\SYSTEM\vot3216.dll: UMonitor
C:\WINDOWS\SYSTEM\DKSKCP16.DLL: UMonitor
C:\WINDOWS\SYSTEM\wfvdmoe2.dll: UMonitor
C:\WINDOWS\SYSTEM\loaipsw.dll: UMonitor
C:\WINDOWS\SYSTEM\lQprxy.dll: UMonitor
C:\WINDOWS\SYSTEM\MHMC13W.DLL: UMonitor
C:\WINDOWS\SYSTEM\OHGFS400.DLL: UMonitor
C:\WINDOWS\SYSTEM\Mtvcp50.dll: UMonitor
C:\WINDOWS\SYSTEM\DOKMAINT.DLL: UMonitor
C:\WINDOWS\SYSTEM\MXJDBC10.DLL: UMonitor
C:\WINDOWS\SYSTEM\RNASIG.DLL: UMonitor
C:\WINDOWS\SYSTEM\RNCHED.DLL: UMonitor
C:\WINDOWS\SYSTEM\uvp10.dll: UMonitor
C:\WINDOWS\SYSTEM\SGntfNT.dll: UMonitor
C:\WINDOWS\SYSTEM\wcerror.dll: UMonitor