After running the findit.bat for about 20 minutes I finally go this :
------- System Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 2435-13D6
Directory of C:\WINDOWS\SYSTEM
QGENUT16 DLL 217,088 12-13-04 7:52p QGENUT16.DLL
MWRD2X40 DLL 217,088 12-13-04 7:52p MWRD2X40.DLL
LWPDF13N DLL 217,088 12-13-04 7:52p lwpdf13n.dll
NDDLL DLL 217,088 12-13-04 7:52p NDDLL.DLL
EXRES16 DLL 217,088 12-13-04 7:52p EXRES16.DLL
SORMDLL DLL 217,088 12-13-04 7:52p sormdll.dll
HPSETUP DLL 217,088 12-13-04 7:52p hpsetup.dll
MBCMS DLL 217,088 12-13-04 7:52p MBCMS.DLL
EWRES16 DLL 217,088 12-13-04 7:52p EWRES16.DLL
QQNBC16 DLL 217,088 12-13-04 7:52p QQNBC16.DLL
DFUSIC32 DLL 217,088 12-13-04 7:52p DFUSIC32.DLL
DSIMAN32 DLL 217,088 12-13-04 7:52p DSIMAN32.DLL
LCRAW12N DLL 217,088 12-13-04 7:52p LCRAW12N.DLL
HAP95EN DLL 217,088 12-13-04 7:52p HAP95EN.DLL
DAIME DLL 217,088 12-13-04 7:52p DAIME.DLL
AJYCFILT DLL 217,088 12-13-04 7:52p AJYCFILT.DLL
MCEXCH40 DLL 217,088 12-13-04 7:52p MCEXCH40.DLL
LGSMP13N DLL 217,088 12-13-04 7:52p LGSMP13n.dll
ETH27UIW DLL 217,088 12-13-04 7:52p ETH27UIW.DLL
MTIMG32 DLL 217,088 12-13-04 7:52p MTIMG32.DLL
SVI_CI32 DLL 217,088 12-13-04 7:52p SVI_CI32.DLL
LWIFF13N DLL 217,088 12-13-04 7:52p lwiff13n.dll
SZBD6W95 DLL 217,088 12-13-04 7:52p Szbd6w95.dll
LJSMP13N DLL 217,088 12-13-04 7:52p LJSMP13n.dll
MAIMSG DLL 217,088 12-13-04 7:52p maimsg.dll
HPLOFHAS EXE 385,024 11-04-04 6:27p hplofhas.exe
26 file(s) 5,812,224 bytes
0 dir(s) 8,641.80 MB free
------- System Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 2435-13D6
Directory of C:\WINDOWS\SYSTEM
QGENUT16 DLL 217,088 12-13-04 7:52p QGENUT16.DLL
MWRD2X40 DLL 217,088 12-13-04 7:52p MWRD2X40.DLL
LWPDF13N DLL 217,088 12-13-04 7:52p lwpdf13n.dll
NDDLL DLL 217,088 12-13-04 7:52p NDDLL.DLL
EXRES16 DLL 217,088 12-13-04 7:52p EXRES16.DLL
SORMDLL DLL 217,088 12-13-04 7:52p sormdll.dll
HPSETUP DLL 217,088 12-13-04 7:52p hpsetup.dll
MBCMS DLL 217,088 12-13-04 7:52p MBCMS.DLL
EWRES16 DLL 217,088 12-13-04 7:52p EWRES16.DLL
QQNBC16 DLL 217,088 12-13-04 7:52p QQNBC16.DLL
DFUSIC32 DLL 217,088 12-13-04 7:52p DFUSIC32.DLL
DSIMAN32 DLL 217,088 12-13-04 7:52p DSIMAN32.DLL
LCRAW12N DLL 217,088 12-13-04 7:52p LCRAW12N.DLL
HAP95EN DLL 217,088 12-13-04 7:52p HAP95EN.DLL
DAIME DLL 217,088 12-13-04 7:52p DAIME.DLL
AJYCFILT DLL 217,088 12-13-04 7:52p AJYCFILT.DLL
MCEXCH40 DLL 217,088 12-13-04 7:52p MCEXCH40.DLL
LGSMP13N DLL 217,088 12-13-04 7:52p LGSMP13n.dll
ETH27UIW DLL 217,088 12-13-04 7:52p ETH27UIW.DLL
MTIMG32 DLL 217,088 12-13-04 7:52p MTIMG32.DLL
SVI_CI32 DLL 217,088 12-13-04 7:52p SVI_CI32.DLL
LWIFF13N DLL 217,088 12-13-04 7:52p lwiff13n.dll
SZBD6W95 DLL 217,088 12-13-04 7:52p Szbd6w95.dll
LJSMP13N DLL 217,088 12-13-04 7:52p LJSMP13n.dll
MAIMSG DLL 217,088 12-13-04 7:52p maimsg.dll
HPLOFHAS EXE 385,024 11-04-04 6:27p hplofhas.exe
26 file(s) 5,812,224 bytes
0 dir(s) 8,571.80 MB free
------- System Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 2435-13D6
Directory of C:\WINDOWS\SYSTEM
QGENUT16 DLL 217,088 12-13-04 7:52p QGENUT16.DLL
MWRD2X40 DLL 217,088 12-13-04 7:52p MWRD2X40.DLL
LWPDF13N DLL 217,088 12-13-04 7:52p lwpdf13n.dll
NDDLL DLL 217,088 12-13-04 7:52p NDDLL.DLL
EXRES16 DLL 217,088 12-13-04 7:52p EXRES16.DLL
SORMDLL DLL 217,088 12-13-04 7:52p sormdll.dll
HPSETUP DLL 217,088 12-13-04 7:52p hpsetup.dll
MBCMS DLL 217,088 12-13-04 7:52p MBCMS.DLL
EWRES16 DLL 217,088 12-13-04 7:52p EWRES16.DLL
QQNBC16 DLL 217,088 12-13-04 7:52p QQNBC16.DLL
DFUSIC32 DLL 217,088 12-13-04 7:52p DFUSIC32.DLL
DSIMAN32 DLL 217,088 12-13-04 7:52p DSIMAN32.DLL
LCRAW12N DLL 217,088 12-13-04 7:52p LCRAW12N.DLL
HAP95EN DLL 217,088 12-13-04 7:52p HAP95EN.DLL
DAIME DLL 217,088 12-13-04 7:52p DAIME.DLL
AJYCFILT DLL 217,088 12-13-04 7:52p AJYCFILT.DLL
MCEXCH40 DLL 217,088 12-13-04 7:52p MCEXCH40.DLL
LGSMP13N DLL 217,088 12-13-04 7:52p LGSMP13n.dll
ETH27UIW DLL 217,088 12-13-04 7:52p ETH27UIW.DLL
MTIMG32 DLL 217,088 12-13-04 7:52p MTIMG32.DLL
SVI_CI32 DLL 217,088 12-13-04 7:52p SVI_CI32.DLL
LWIFF13N DLL 217,088 12-13-04 7:52p lwiff13n.dll
SZBD6W95 DLL 217,088 12-13-04 7:52p Szbd6w95.dll
LJSMP13N DLL 217,088 12-13-04 7:52p LJSMP13n.dll
MAIMSG DLL 217,088 12-13-04 7:52p maimsg.dll
HPLOFHAS EXE 385,024 11-04-04 6:27p hplofhas.exe
26 file(s) 5,812,224 bytes
0 dir(s) 8,359.05 MB free
------- Hidden Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 2435-13D6
Directory of C:\WINDOWS\SYSTEM
FOLDER HTT 13,122 12-26-04 5:32p folder.htt
DESKTOP INI 266 12-26-04 5:32p desktop.ini
E_QI021E GID 8,628 12-03-04 11:24p E_QI021E.GID
HPLOFHAS EXE 385,024 11-04-04 6:27p hplofhas.exe
CTF <DIR> 08-31-04 2:08p CTF
HPHIPCL GID 30,367 05-22-04 2:46p hphipcl.GID
HPFUIH05 GID 8,628 02-12-04 12:12a hpfuih05.GID
6 file(s) 446,035 bytes
1 dir(s) 8,641.78 MB free
---------------- User Agent ------------
------- Hidden Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 2435-13D6
Directory of C:\WINDOWS\SYSTEM
FOLDER HTT 13,122 12-26-04 5:32p folder.htt
DESKTOP INI 266 12-26-04 5:32p desktop.ini
E_QI021E GID 8,628 12-03-04 11:24p E_QI021E.GID
HPLOFHAS EXE 385,024 11-04-04 6:27p hplofhas.exe
CTF <DIR> 08-31-04 2:08p CTF
HPHIPCL GID 30,367 05-22-04 2:46p hphipcl.GID
HPFUIH05 GID 8,628 02-12-04 12:12a hpfuih05.GID
6 file(s) 446,035 bytes
1 dir(s) 8,571.80 MB free
---------------- User Agent ------------
------- Hidden Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 2435-13D6
Directory of C:\WINDOWS\SYSTEM
FOLDER HTT 13,122 12-26-04 5:32p folder.htt
DESKTOP INI 266 12-26-04 5:32p desktop.ini
E_QI021E GID 8,628 12-03-04 11:24p E_QI021E.GID
HPLOFHAS EXE 385,024 11-04-04 6:27p hplofhas.exe
CTF <DIR> 08-31-04 2:08p CTF
HPHIPCL GID 30,367 05-22-04 2:46p hphipcl.GID
HPFUIH05 GID 8,628 02-12-04 12:12a hpfuih05.GID
6 file(s) 446,035 bytes
1 dir(s) 8,359.05 MB free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{21A21720-5D09-11D9-B700-B4AC6A7A4D1F}"=""
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
qgenut16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
mwrd2x40.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lwpdf13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
nddll.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
exres16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
sormdll.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
hpsetup.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
mbcms.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ewres16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
qqnbc16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
dfusic32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
dsiman32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lcraw12n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
folder.htt Sun Dec 26 2004 5:32:30p ...H. 13,122 12.81 K
hap95en.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
daime.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ajycfilt.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
desktop.ini Sun Dec 26 2004 5:32:30p ...H. 266 0.26 K
mcexch40.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
e_qi021e.gid Fri Dec 3 2004 11:24:28p A..H. 8,628 8.43 K
lgsmp13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
eth27uiw.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
hplofhas.exe Thu Nov 4 2004 6:27:16p ..SHR 385,024 376.00 K
mtimg32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
svi_ci32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lwiff13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
szbd6w95.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ljsmp13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
maimsg.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
29 items found: 29 files, 0 directories.
Total of file sizes: 5,834,240 bytes 5.56 M
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
qgenut16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
mwrd2x40.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lwpdf13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
nddll.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
exres16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
sormdll.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
hpsetup.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
mbcms.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ewres16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
qqnbc16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
dfusic32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
dsiman32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lcraw12n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
folder.htt Sun Dec 26 2004 5:32:30p ...H. 13,122 12.81 K
hap95en.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
daime.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ajycfilt.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
desktop.ini Sun Dec 26 2004 5:32:30p ...H. 266 0.26 K
mcexch40.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
e_qi021e.gid Fri Dec 3 2004 11:24:28p A..H. 8,628 8.43 K
lgsmp13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
eth27uiw.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
hplofhas.exe Thu Nov 4 2004 6:27:16p ..SHR 385,024 376.00 K
mtimg32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
svi_ci32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lwiff13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
szbd6w95.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ljsmp13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
maimsg.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
29 items found: 29 files, 0 directories.
Total of file sizes: 5,834,240 bytes 5.56 M
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
qgenut16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
mwrd2x40.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lwpdf13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
nddll.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
exres16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
sormdll.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
hpsetup.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
mbcms.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ewres16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
qqnbc16.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
dfusic32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
dsiman32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lcraw12n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
folder.htt Sun Dec 26 2004 5:32:30p ...H. 13,122 12.81 K
hap95en.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
daime.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ajycfilt.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
desktop.ini Sun Dec 26 2004 5:32:30p ...H. 266 0.26 K
mcexch40.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
e_qi021e.gid Fri Dec 3 2004 11:24:28p A..H. 8,628 8.43 K
lgsmp13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
eth27uiw.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
hplofhas.exe Thu Nov 4 2004 6:27:16p ..SHR 385,024 376.00 K
mtimg32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
svi_ci32.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
lwiff13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
szbd6w95.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
ljsmp13n.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
maimsg.dll Mon Dec 13 2004 7:52:54p ..S.R 217,088 212.00 K
29 items found: 29 files, 0 directories.
Total of file sizes: 5,834,240 bytes 5.56 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\ncoget.dll: excl_urls=adsv2.delfinproject.com,popup.msn.com,i.emarketresearchgroup.com,u.clk
optimizer.com,ezula.com,ads2.revenue.net,banners.pennyweb.com,counters.honesty.c
o
m,ads.bidclix.com,oz.valueclick.com,radio.launch.yahoo.com,zone.msn.com,sr.adwav
e
.com,xlime.offeroptimizer.com,clickit.go2net.com,us.update.companion.yahoo.com,k
i
ll-pop-ups.com,qksrv.net,clickspring.net,cdn-aimtoday.Email Removed,search200.com,servedby.adscpm.com,xanga.com,count.exitexchange.com,jnict
ech.cjt1.net,xadsq.offeroptimizer.com,paypopup.com,popuptraffic.com,cdn-cf.Email Removed,allaboutsearching.com,Email Removed.msn.com,adfarm.mediaplex.com,by.optimost.com,amch.questionmarket.com,aka
pp.whenu.com,newupdates.lzio.com,cfg.mywebsearch.com,searcheffect.com,ads.delfin
p
roject.com,master.mx-targeting.com,Email Removed.com,ctl.twain-tech.com,mail.yahoo.com,m2.doubleclick.net,insider.msg.yahoo.com,focusin.ads.tar
getnet.com,e.rn11.com,jmnad1.com,topicks.com,ad.doubleclick.net,m3.doubleclick.n
e
t,as.casalemedia.com,pgq.yahoo.com,webpdp.gator.com,stopzilla.com,ayb.lop.com,xa
d
so.offeroptimizer.com,download.smileycentral.com,mm.delfinproject.com,view.atdmt
.
com,delfinproject.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,as.adwave.
c
om,popuppers.com,look2me.com,wisapidata.weatherbug.com,ads.addynamix.com,ar.atwo
l
a.com,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,weatherbug.com,jicm
e
dia.cjt1.net,games.yahoo.com,adsrv.qoologic.com,servedby.advertising.com,ww2.wea
t
herbug.com,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,mmm.med
i
a-motor.net,hop.clickbank.net,media76.fastclick.net,websearch.com,isapi60.weatherb
ug.com,web.tickle.com,messenger.zango.com,wwp.icq.com,smileycentral.com,adserv1.
g
ruvmedia.com,cdn.icq.com,s.clkoptimizer.com,tv.180solutions.com,pops.browseraid.
c
om,download.abetterinternet.com,adserv.internetfuel.com,messenger.msn.com,sr.web
s
earch.com,top-banners.com,advert.runescape.com,join1.winhundred.com,odysseusmarketing.com,v4.w
indowsupdate.microsoft.com,adverts.lzio.com,windowsupdate.microsoft.com,filter.b
e
lkin.com,comcast.net,sc.musicmatch.com,license.hotbar.com,trk.pcsecurityshield.c
o
m,web.icq.com,whenusearch.com,jbigpops.cjt1.net,isg05.casalemedia.com,yahoo.com,
E
mail Removed,anrdoezrs.net,microsoft.com,target.com,aim-charts.pf.Email Removed,download.websearch.com,actualdeals.com,images.trafficmp.com,mydailyhoros
cope.net,couponage.com,c5.zedo.com,ekmas.com,ads.mydailyhoroscope.net,creativeby
.
viewpoint.com,affiliates.4lowrates.com,hits.clickandtrack.net,jcontent.bns1.net,
c
lickserve.cc-dt.com,popups.ad-logics.com,adlog2.lzio.com,host239.ipowerweb.com,bv.channel.Email Removed,img2.mailpostdirect.com,dw.dailywinner.net,toprebates.com,trk.bestmagsdi
rect.com,ads.clickagents.com,a.websponsors.com,sandboxer.com,media.fastclick.net
,
click2.containsitall.com,ads234.com,http300.edge.ru4.com,adlog.com.com,rs.websea
r
ch.com,ads.com.com,server.iad.liveperson.net,
C:\WINDOWS\opnabu.dll: updates.qoologic.com
C:\WINDOWS\yuqpoz.dll: updates.qoologic.com
C:\WINDOWS\zuaqwm.exe: updates.qoologic.com
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\ncoget.dll: excl_urls=adsv2.delfinproject.com,popup.msn.com,i.emarketresearchgroup.com,u.clk
optimizer.com,ezula.com,ads2.revenue.net,banners.pennyweb.com,counters.honesty.c
o
m,ads.bidclix.com,oz.valueclick.com,radio.launch.yahoo.com,zone.msn.com,sr.adwav
e
.com,xlime.offeroptimizer.com,clickit.go2net.com,us.update.companion.yahoo.com,k
i
ll-pop-ups.com,qksrv.net,clickspring.net,cdn-aimtoday.Email Removed,search200.com,servedby.adscpm.com,xanga.com,count.exitexchange.com,jnict
ech.cjt1.net,xadsq.offeroptimizer.com,paypopup.com,popuptraffic.com,cdn-cf.Email Removed,allaboutsearching.com,Email Removed.msn.com,adfarm.mediaplex.com,by.optimost.com,amch.questionmarket.com,aka
pp.whenu.com,newupdates.lzio.com,cfg.mywebsearch.com,searcheffect.com,ads.delfin
p
roject.com,master.mx-targeting.com,Email Removed.com,ctl.twain-tech.com,mail.yahoo.com,m2.doubleclick.net,insider.msg.yahoo.com,focusin.ads.tar
getnet.com,e.rn11.com,jmnad1.com,topicks.com,ad.doubleclick.net,m3.doubleclick.n
e
t,as.casalemedia.com,pgq.yahoo.com,webpdp.gator.com,stopzilla.com,ayb.lop.com,xa
d
so.offeroptimizer.com,download.smileycentral.com,mm.delfinproject.com,view.atdmt
.
com,delfinproject.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,as.adwave.
c
om,popuppers.com,look2me.com,wisapidata.weatherbug.com,ads.addynamix.com,ar.atwo
l
a.com,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,weatherbug.com,jicm
e
dia.cjt1.net,games.yahoo.com,adsrv.qoologic.com,servedby.advertising.com,ww2.wea
t
herbug.com,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,mmm.med
i
a-motor.net,hop.clickbank.net,media76.fastclick.net,websearch.com,isapi60.weatherb
ug.com,web.tickle.com,messenger.zango.com,wwp.icq.com,smileycentral.com,adserv1.
g
ruvmedia.com,cdn.icq.com,s.clkoptimizer.com,tv.180solutions.com,pops.browseraid.
c
om,download.abetterinternet.com,adserv.internetfuel.com,messenger.msn.com,sr.web
s
earch.com,top-banners.com,advert.runescape.com,join1.winhundred.com,odysseusmarketing.com,v4.w
indowsupdate.microsoft.com,adverts.lzio.com,windowsupdate.microsoft.com,filter.b
e
lkin.com,comcast.net,sc.musicmatch.com,license.hotbar.com,trk.pcsecurityshield.c
o
m,web.icq.com,whenusearch.com,jbigpops.cjt1.net,isg05.casalemedia.com,yahoo.com,
E
mail Removed,anrdoezrs.net,microsoft.com,target.com,aim-charts.pf.Email Removed,download.websearch.com,actualdeals.com,images.trafficmp.com,mydailyhoros
cope.net,couponage.com,c5.zedo.com,ekmas.com,ads.mydailyhoroscope.net,creativeby
.
viewpoint.com,affiliates.4lowrates.com,hits.clickandtrack.net,jcontent.bns1.net,
c
lickserve.cc-dt.com,popups.ad-logics.com,adlog2.lzio.com,host239.ipowerweb.com,bv.channel.Email Removed,img2.mailpostdirect.com,dw.dailywinner.net,toprebates.com,trk.bestmagsdi
rect.com,ads.clickagents.com,a.websponsors.com,sandboxer.com,media.fastclick.net
,
click2.containsitall.com,ads234.com,http300.edge.ru4.com,adlog.com.com,rs.websea
r
ch.com,ads.com.com,server.iad.liveperson.net,
C:\WINDOWS\opnabu.dll: updates.qoologic.com
C:\WINDOWS\yuqpoz.dll: updates.qoologic.com
C:\WINDOWS\zuaqwm.exe: updates.qoologic.com
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\aukvby.dat: .aspack
----------------- HKLM Run Key ------------------
-------------- Strings.exe Umonitor Results -------------
C:\WINDOWS\SYSTEM\QGENUT16.DLL: UMonitor
C:\WINDOWS\SYSTEM\MWRD2X40.DLL: UMonitor
C:\WINDOWS\SYSTEM\lwpdf13n.dll: UMonitor
C:\WINDOWS\SYSTEM\NDDLL.DLL: UMonitor
C:\WINDOWS\SYSTEM\EXRES16.DLL: UMonitor
C:\WINDOWS\SYSTEM\sormdll.dll: UMonitor
C:\WINDOWS\SYSTEM\hpsetup.dll: UMonitor
C:\WINDOWS\SYSTEM\MBCMS.DLL: UMonitor
C:\WINDOWS\SYSTEM\EWRES16.DLL: UMonitor
C:\WINDOWS\SYSTEM\QQNBC16.DLL: UMonitor
C:\WINDOWS\SYSTEM\DFUSIC32.DLL: UMonitor
C:\WINDOWS\SYSTEM\DSIMAN32.DLL: UMonitor
C:\WINDOWS\SYSTEM\LCRAW12N.DLL: UMonitor
C:\WINDOWS\SYSTEM\HAP95EN.DLL: UMonitor
C:\WINDOWS\SYSTEM\DAIME.DLL: UMonitor
C:\WINDOWS\SYSTEM\AJYCFILT.DLL: UMonitor
C:\WINDOWS\SYSTEM\ipebase11.dll: ??0ECalMonitor@@QAE@PAUMONITOR_CAL@@@Z
C:\WINDOWS\SYSTEM\MCEXCH40.DLL: UMonitor
C:\WINDOWS\SYSTEM\LGSMP13n.dll: UMonitor
C:\WINDOWS\SYSTEM\ETH27UIW.DLL: UMonitor
C:\WINDOWS\SYSTEM\MTIMG32.DLL: UMonitor
C:\WINDOWS\SYSTEM\SVI_CI32.DLL: UMonitor
C:\WINDOWS\SYSTEM\lwiff13n.dll: UMonitor
C:\WINDOWS\SYSTEM\Szbd6w95.dll: UMonitor
C:\WINDOWS\SYSTEM\LJSMP13n.dll: UMonitor
C:\WINDOWS\SYSTEM\maimsg.dll: UMonitor
-------------- Strings.exe Umonitor Results -------------
C:\WINDOWS\SYSTEM\QGENUT16.DLL: UMonitor
C:\WINDOWS\SYSTEM\MWRD2X40.DLL: UMonitor
C:\WINDOWS\SYSTEM\lwpdf13n.dll: UMonitor
C:\WINDOWS\SYSTEM\NDDLL.DLL: UMonitor
-------------- Strings.exe Umonitor Results -------------
C:\WINDOWS\SYSTEM\QGENUT16.DLL: UMonitor
C:\WINDOWS\SYSTEM\MWRD2X40.DLL: UMonitor
C:\WINDOWS\SYSTEM\lwpdf13n.dll: UMonitor
C:\WINDOWS\SYSTEM\NDDLL.DLL: UMonitor
C:\WINDOWS\SYSTEM\EXRES16.DLL: UMonitor
C:\WINDOWS\SYSTEM\sormdll.dll: UMonitor
C:\WINDOWS\SYSTEM\hpsetup.dll: UMonitor
C:\WINDOWS\SYSTEM\MBCMS.DLL: UMonitor
C:\WINDOWS\SYSTEM\EWRES16.DLL: UMonitor
C:\WINDOWS\SYSTEM\QQNBC16.DLL: UMonitor
C:\WINDOWS\SYSTEM\DFUSIC32.DLL: UMonitor
C:\WINDOWS\SYSTEM\DSIMAN32.DLL: UMonitor
C:\WINDOWS\SYSTEM\LCRAW12N.DLL: UMonitor
C:\WINDOWS\SYSTEM\HAP95EN.DLL: UMonitor
C:\WINDOWS\SYSTEM\DAIME.DLL: UMonitor
C:\WINDOWS\SYSTEM\AJYCFILT.DLL: UMonitor
C:\WINDOWS\SYSTEM\ipebase11.dll: ??0ECalMonitor@@QAE@PAUMONITOR_CAL@@@Z
C:\WINDOWS\SYSTEM\MCEXCH40.DLL: UMonitor
C:\WINDOWS\SYSTEM\LGSMP13n.dll: UMonitor
C:\WINDOWS\SYSTEM\ETH27UIW.DLL: UMonitor
C:\WINDOWS\SYSTEM\MTIMG32.DLL: UMonitor
C:\WINDOWS\SYSTEM\SVI_CI32.DLL: UMonitor
C:\WINDOWS\SYSTEM\lwiff13n.dll: UMonitor
C:\WINDOWS\SYSTEM\Szbd6w95.dll: UMonitor
C:\WINDOWS\SYSTEM\LJSMP13n.dll: UMonitor
C:\WINDOWS\SYSTEM\maimsg.dll: UMonitor
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"SystemTray"="SysTray.Exe"
"EnsoniqMixer"="starter.exe"
"EPSON Stylus CX5400"="C:\\WINDOWS\\SYSTEM\\E_S4I2G1.EXE /P19 \"EPSON Stylus CX5400\" /O5 \"LPT1:\" /M \"Stylus CX5400\""
"kalvsys"="C:\\WINDOWS\\SYSTEM\\KALVXNL32.EXE"