HJT Log as follows:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:59:38, on 2008-07-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\mmm.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\HostsMan\hostssrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {018B27FF-E05F-4CB5-8763-540CB3FD457A} - C:\WINDOWS\system32\ddcDtRLd.dll
O2 - BHO: (no name) - {2ECE29C1-3F16-4ECA-A5CA-D618BC5752A4} - C:\WINDOWS\system32\awtsQHwW.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: {87831770-ea07-ffb8-ecf4-5756993538ad} - {da835399-6575-4fce-8bff-70ae07713878} - C:\WINDOWS\system32\cgdhng.dll
O2 - BHO: (no name) - {F8700F79-B2C1-4351-B025-AFED2CEEACC0} - C:\WINDOWS\system32\urqPjJDu.dll (file missing)
O4 - HKLM\..\Run: [PowerTweak Menu] C:\WINDOWS\system32\mmm.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe"
O4 - HKLM\..\Run: [BM07a76409] Rundll32.exe "C:\WINDOWS\system32\vowxgebi.dll",s
O4 - HKLM\..\Run: [04945795] rundll32.exe "C:\WINDOWS\system32\uonmotpm.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3711] command /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2372] cmd /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5524] command /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1816] cmd /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [HostsServer] "C:\Program Files\HostsMan\hostssrv.exe" --start
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O20 - Winlogon Notify: ddcDtRLd - C:\WINDOWS\SYSTEM32\ddcDtRLd.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
--
End of file - 5538 bytes
Unfortunately I seem to have allowed some stupid registry changes...
The Spybot log shows this:
2008-07-01 10:39:57 Allowed (based on user decision) value "SpybotDeletingB8737" (new data: "") deleted in System Startup user entry!
2008-07-01 10:39:58 Allowed (based on user decision) value "SpybotDeletingD5300" (new data: "") deleted in System Startup user entry!
2008-07-01 10:39:58 Allowed (based on user decision) value "04945795" (new data: "rundll32.exe "C:\WINDOWS\system32\uonmotpm.dll",b") added in System Startup global entry!
2008-07-01 10:40:03 Allowed (based on user decision) value "BM07a76409" (new data: "Rundll32.exe "C:\WINDOWS\system32\vowxgebi.dll",s") added in System Startup global entry!
2008-07-01 10:40:05 Allowed (based on user decision) value "SpybotDeletingA3711" (new data: "command /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"") added in System Startup global entry!
2008-07-01 10:40:06 Allowed (based on user decision) value "SpybotDeletingC2372" (new data: "cmd /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"") added in System Startup global entry!
2008-07-01 10:40:06 Allowed (based on user decision) value "SpybotDeletingA5524" (new data: "command /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"") added in System Startup global entry!
2008-07-01 10:40:06 Allowed (based on user decision) value "SpybotDeletingC1816" (new data: "cmd /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"") added in System Startup global entry!
2008-07-01 10:40:08 Allowed (based on user decision) value "SpybotDeletingA2859" (new data: "") deleted in System Startup global entry!
2008-07-01 10:40:09 Allowed (based on user decision) value "SpybotDeletingC8788" (new data: "") deleted in System Startup global entry!
2008-07-01 10:44:54 Denied (based on user decision) value "04945795" (new data: "") deleted in System Startup global entry!
I hope that I wasn't unclear...I really need help to remove this...please.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:59:38, on 2008-07-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\mmm.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\Program Files\HostsMan\hostssrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {018B27FF-E05F-4CB5-8763-540CB3FD457A} - C:\WINDOWS\system32\ddcDtRLd.dll
O2 - BHO: (no name) - {2ECE29C1-3F16-4ECA-A5CA-D618BC5752A4} - C:\WINDOWS\system32\awtsQHwW.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: {87831770-ea07-ffb8-ecf4-5756993538ad} - {da835399-6575-4fce-8bff-70ae07713878} - C:\WINDOWS\system32\cgdhng.dll
O2 - BHO: (no name) - {F8700F79-B2C1-4351-B025-AFED2CEEACC0} - C:\WINDOWS\system32\urqPjJDu.dll (file missing)
O4 - HKLM\..\Run: [PowerTweak Menu] C:\WINDOWS\system32\mmm.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe"
O4 - HKLM\..\Run: [BM07a76409] Rundll32.exe "C:\WINDOWS\system32\vowxgebi.dll",s
O4 - HKLM\..\Run: [04945795] rundll32.exe "C:\WINDOWS\system32\uonmotpm.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3711] command /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2372] cmd /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5524] command /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1816] cmd /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [HostsServer] "C:\Program Files\HostsMan\hostssrv.exe" --start
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O20 - Winlogon Notify: ddcDtRLd - C:\WINDOWS\SYSTEM32\ddcDtRLd.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
--
End of file - 5538 bytes
Unfortunately I seem to have allowed some stupid registry changes...
The Spybot log shows this:
2008-07-01 10:39:57 Allowed (based on user decision) value "SpybotDeletingB8737" (new data: "") deleted in System Startup user entry!
2008-07-01 10:39:58 Allowed (based on user decision) value "SpybotDeletingD5300" (new data: "") deleted in System Startup user entry!
2008-07-01 10:39:58 Allowed (based on user decision) value "04945795" (new data: "rundll32.exe "C:\WINDOWS\system32\uonmotpm.dll",b") added in System Startup global entry!
2008-07-01 10:40:03 Allowed (based on user decision) value "BM07a76409" (new data: "Rundll32.exe "C:\WINDOWS\system32\vowxgebi.dll",s") added in System Startup global entry!
2008-07-01 10:40:05 Allowed (based on user decision) value "SpybotDeletingA3711" (new data: "command /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"") added in System Startup global entry!
2008-07-01 10:40:06 Allowed (based on user decision) value "SpybotDeletingC2372" (new data: "cmd /c del "C:\WINDOWS\system32\awtsQHwW.dll_old"") added in System Startup global entry!
2008-07-01 10:40:06 Allowed (based on user decision) value "SpybotDeletingA5524" (new data: "command /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"") added in System Startup global entry!
2008-07-01 10:40:06 Allowed (based on user decision) value "SpybotDeletingC1816" (new data: "cmd /c del "C:\WINDOWS\system32\urqPjJDu.dll_old"") added in System Startup global entry!
2008-07-01 10:40:08 Allowed (based on user decision) value "SpybotDeletingA2859" (new data: "") deleted in System Startup global entry!
2008-07-01 10:40:09 Allowed (based on user decision) value "SpybotDeletingC8788" (new data: "") deleted in System Startup global entry!
2008-07-01 10:44:54 Denied (based on user decision) value "04945795" (new data: "") deleted in System Startup global entry!
I hope that I wasn't unclear...I really need help to remove this...please.
Last edited by a moderator: