Here we go....
I did everything that you said and rebooted out of safe mode. Windows said that it could not find Nail.exe which is a good and bad thing. It seems that there is a control that is still looking for nail.exe but it does not exsit which is a good thing. Below is my logs. Thanks for all of the help!!!! You guys are great!!!
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:27:10 AM, 5/27/2005
+ Report-Checksum: 31F8E9E6
+ Date of database: 5/27/2005
+ Version of scan engine: v3.0
+ Duration: 57 min
+ Scanned Files: 129388
+ Speed: 37.73 Files/Second
+ Infected files: 39
+ Removed files: 39
+ Files put in quarantine: 39
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\james.DHS\Cookies\james@indiads[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\james.DHS\Cookies\
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\ACD\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\AEW\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\APC\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\BMM\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\EWG\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\FCD\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\GRO\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\HOH\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\JUC\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\OUY\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\PYH\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\RBX\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\RMM\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\ROL\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\ROS\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\RVG\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\RXO\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\SDH\aurareco.exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\SMK\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\SMX\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\temp.fr0392 -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\temp.frA385 -> Trojan.Agent.db -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\temp.frC5CB -> Trojan.Imiserv.c -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\YDW\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\YJW\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\james.DHS\Local Settings\Temp\ZJA\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\tim\Local Settings\Temporary Internet Files\Content.IE5\3XB9K0QD\hp2[1].htm -> Not-A-Virus.Exploit.HTML.Mht -> Cleaned with backup
C:\Program Files\MBKWBar\IEToolBar.dll -> Spyware.MBKWBar.a -> Cleaned with backup
C:\WINDOWS\enhtb.dll -> Spyware.NoName -> Cleaned with backup
C:\WINDOWS\enhtb.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\WINDOWS\enhuninstall.exe -> Spyware.NoName -> Cleaned with backup
C:\WINDOWS\Nail.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\remtm3.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\systb.dll -> Spyware.ImiBar.d -> Cleaned with backup
C:\WINDOWS\SYSTEM32\irvaso.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\WINDOWS\SYSTEM32\zfebdo.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\WINDOWS\wupdt.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 11:41:00 AM, on 5/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\New Folder\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [struor] c:\windows\system32\grmedos.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Access Anywhere Agent.LNK = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://cprplussuppo...ort/ieatgpc.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dhs.cprplus.com
O17 - HKLM\Software\..\Telephony: DomainName = dhs.cprplus.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dhs.cprplus.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ARMTech Resource Management (ARMSched) - Aurema Pty Limited - C:\Program Files\Aurema\ARMTech\bin\armtsched.exe
O23 - Service: ARMTech User/Session Synchronisation (ARMUSync) - Aurema Pty Limited - C:\Program Files\Aurema\ARMTech\bin\armtusync.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\DOWNLO~1\WebEx\319\atnthost.exe
O23 - Service: Crystal Report Application Server (CrystalReportApplicationServer) - Unknown owner - C:\Program Files\Common Files\Crystal Decisions\2.0\bin\querysrv.exe" -service -name JAMESM.RAS (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
Not logged into Safe mode....
Logfile of HijackThis v1.99.1
Scan saved at 1:04:01 PM, on 5/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\DOWNLO~1\WebEx\319\atnthost.exe
C:\WINDOWS\DOWNLO~1\WebEx\319\RAAGTAPP.EXE
C:\Program Files\Common Files\Crystal Decisions\2.0\bin\querysrv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\DOWNLO~1\WebEx\319\raagtx.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Visual Studio\Vfp98\VFP6.EXE
C:\Program Files\Microsoft Visual FoxPro 8\vfp8.exe
C:\New Folder\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.cprplus.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Definitive Homecare Solutions
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [struor] c:\windows\system32\grmedos.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Access Anywhere Agent.LNK = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://cprplussuppo...ort/ieatgpc.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dhs.cprplus.com
O17 - HKLM\Software\..\Telephony: DomainName = dhs.cprplus.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dhs.cprplus.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ARMTech Resource Management (ARMSched) - Aurema Pty Limited - C:\Program Files\Aurema\ARMTech\bin\armtsched.exe
O23 - Service: ARMTech User/Session Synchronisation (ARMUSync) - Aurema Pty Limited - C:\Program Files\Aurema\ARMTech\bin\armtusync.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\DOWNLO~1\WebEx\319\atnthost.exe
O23 - Service: Crystal Report Application Server (CrystalReportApplicationServer) - Unknown owner - C:\Program Files\Common Files\Crystal Decisions\2.0\bin\querysrv.exe" -service -name JAMESM.RAS (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
Thanks again,
James