first post here.. I have searched the internet and used alot of the info from the geek stop forums but i can not remove nail.exe and stop the aurora popup (think they are related)
i have turned off system restore.. and done a virus scan using avg.
i have also ran severall ewido scans.. and tried severall methods of removing nail.exe using Nail.exe /FULLREMOVE etc .. any help would be appreciated thank you =)
here are the logs from ewido and hijack below ...the computer was run in safe mode , i ran ewido and then did hijackthis and fixed the follwing but it never goes..
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
thinking it might be something to do with my netut80ex.vxd file/archive??
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:50:05, 06/05/2005
+ Report-Checksum: 273F9392
+ Date of database: 06/05/2005
+ Version of scan engine: v3.0
+ Duration: 20 min
+ Scanned Files: 62753
+ Speed: 50.40 Files/Second
+ Infected files: 54
+ Removed files: 45
+ Files put in quarantine: 43
+ Files that could not be opened: 0
+ Files that could not be cleaned: 8
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\Dan\Cookies\dan@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned without backup
C:\Documents and Settings\Dan\Cookies\dan@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned without backup
C:\Install Files\backups\backup-20050316-192208-925.dll -> Spyware.Apropos.e -> Cleaned with backup
C:\Install Files\backups\backup-20050505-193445-655.dll -> Spyware.180Solutions -> Cleaned with backup
C:\Install Files\biz\cgi\cgis4.exe -> Not-A-Virus.Tool.Scanner.CGIScan.40 -> Cleaned with backup
C:\Install Files\oldpc\ke\sckeylogger\SC-KeyLog\KL.dll -> TrojanSpy.Sckeylog.A -> Cleaned with backup
C:\Install Files\oldpc\ke\sckeylogger\SC-KeyLog\SC-KL.exe -> TrojanSpy.SCKeyLog.a -> Cleaned with backup
C:\Install Files\oldpc\ke\TinyKL\TinyKL.exe -> TrojanSpy.Tiny.101 -> Ignored
C:\Program Files\180search Assistant\saap.exe -> Spyware.180Solutions -> Cleaned with backup
C:\Program Files\180search Assistant\saaphook.dll -> Spyware.180solutions -> Cleaned with backup
C:\Program Files\AutoUpdate\libexpat.dll -> Spyware.Apropos -> Cleaned with backup
C:\Program Files\Common Files\qium\qiump.exe -> Spyware.Xupiter.m -> Cleaned with backup
C:\Program Files\CxtPls\ace.dll -> Spyware.PeopleOnPage -> Cleaned with backup
C:\Program Files\CxtPls\CxtPls.dll -> Spyware.Apropos.e -> Cleaned with backup
C:\Program Files\CxtPls\CxtPls.exe -> Spyware.Apropos.f -> Cleaned with backup
C:\Program Files\CxtPls\libexpat.dll -> Spyware.Apropos -> Cleaned with backup
C:\Program Files\CxtPls\ProxyStub.dll -> Spyware.Apropos -> Cleaned with backup
C:\Program Files\CxtPls\uninstaller.exe -> Spyware.Apropos.f -> Cleaned with backup
C:\Program Files\CxtPls\WinGenerics.dll -> Spyware.Apropos.f -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc1.exe -> Trojan.Nail -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc10\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc11\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc23\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc26.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc321.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc33.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc35.dll -> Spyware.Sahat.m -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc39.dll -> Spyware.Wintol.y -> Cleaned with backup
C:\RECYCLER\S-1-5-21-1960408961-1647877149-839522115-1004\Dc7\auto_update_install.exe -> Spyware.POP.dl -> Cleaned with backup
C:\WINDOWS\mm15201518.Stub.exe -> Spyware.EZula.ah -> Cleaned with backup
C:\WINDOWS\Nail.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\npbnbwyigz.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\seeve.exe -> Spyware.MediaMotor.f -> Cleaned with backup
C:\WINDOWS\svcproc.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\WINDOWS\switpa.exe -> Spyware.Atlas.a -> Cleaned with backup
C:\WINDOWS\system32\auto_update_uninstall.exe -> Spyware.Apropos -> Cleaned with backup
C:\WINDOWS\system32\DrPMon.dll -> Trojan.Agent.db -> Cleaned with backup
C:\WINDOWS\system32\eqopeam.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\WINDOWS\system32\exdl.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\WINDOWS\system32\exdl0.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\WINDOWS\system32\exdl1.exe -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\WINDOWS\system32\mac80ex.idf/C:/WINDOWS/system32/msbe.dll -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\WINDOWS\system32\mac80ex.idf/C:/Program Files/BullsEye Network/bin/adv.exe -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\WINDOWS\system32\mac80ex.idf/C:/Program Files/BullsEye Network/bin/adx.exe -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\WINDOWS\system32\mqexdlm.srg -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\WINDOWS\system32\msbe.dll -> Spyware.BargainBuddy.n -> Cleaned with backup
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/exdl.exe -> Spyware.BargainBuddy.q -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/mqexdlm.srg -> Spyware.BargainBuddy.q -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/exul.exe -> Spyware.BargainBuddy -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/javexulm.vxd -> Spyware.BargainBuddy -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/bbchk.exe -> Spyware.Bargainbuddy -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/msexreg.exe -> Spyware.Bargainbuddy -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/instsrv.exe -> Spyware.BargainBuddy -> Error during cleaning
C:\WINDOWS\system32\netut80ex.vxd/C:/WINDOWS/system32/exclean.exe -> Spyware.BargainBuddy -> Error during cleaning
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 13:30:28, on 06/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Install Files\spyware removal\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo 900] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /P22 "EPSON Stylus Photo 900" /O6 "USB001" /M "Stylus Photo 900"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo 900] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /A "C:\WINDOWS\system32\E_S3.tmp"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Smart Wizard Wireless Settings.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../UK/install.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1101133550817
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.c...utocomplete.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
thanks Dan