I knew there might be some other adware installed, so I ran SpyBot, Adware, Norton Antivirus scans and removed a few things, but the Nail.exe problem still exists.
so then I ran Hijackthis and ewido security suite, and I've got the logs, but I don't know which to delete/clean, etc.
could someone please help me with this? I would really appreciate it.
thanks in advance!
HIJACKTHIS log
___________________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 下午 11:37:50, on 2005/6/12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\User\桌面\HijackThis.exe
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Search Relevancy - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - C:\PROGRA~1\Inventec\Dreye\DreyeMT\DREYEI~1.DLL
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [NPDTray] C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [imekrmig] C:\IME\IMKR\imekrmig.exe
O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ozmkgm] c:\windows\system32\kixszge.exe r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: 使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用影音傳送帶下載 - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: 使用影音傳送帶下載全部連結 - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: 全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.c.../NowStarter.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (趨勢科技線上掃毒程式) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab30149.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab30149.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EFF5C3AC-80F5-4386-BBDF-5F0194814F2F}: NameServer = 194.238.50.3,194.238.50.2
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: Norton AntiVirus 自動防護服務 (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
____________________________________________________________________
ewido log:
____________________________________________________________________
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 下午 11:55:42, 2005/6/12
+ Report-Checksum: 9B20F3F9
+ Date of database: 2005/6/12
+ Version of scan engine: v3.0
+ Duration: 23 min
+ Scanned Files: 60832
+ Speed: 43.01 Files/Second
+ Infected files: 42
+ Removed files: 42
+ Files put in quarantine: 42
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Program Files\DeskAd Service\DeskAdComm.dll -> Spyware.WinAD -> Cleaned with backup
C:\Program Files\DeskAd Service\DeskAdKeep.exe -> Spyware.WinAD.k -> Cleaned with backup
C:\Program Files\DeskAd Service\DeskAdServ.exe -> Spyware.WinAD.m -> Cleaned with backup
C:\setup.EXE_tobedeleted -> Trojan.VB.il -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP172\A0043961.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP172\A0044913.dll -> Spyware.Banex -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP172\A0044924.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP172\A0044930.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP172\A0044933.dll -> Spyware.Wheaterbug.a -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP172\A0044953.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP173\A0045060.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP173\A0045063.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP173\A0045067.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP173\A0045068.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045071.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045073.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045080.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045083.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045084.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045085.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045092.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP174\A0045093.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP175\A0045566.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP175\A0045594.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP175\A0045598.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP175\A0045599.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP175\A0045600.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0045601.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0046590.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0046594.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0046595.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0046597.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0046598.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{FD2D596F-75AC-4E2F-95B7-8C0278A8336C}\RP176\A0046607.dll -> Trojan.Agent.db -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\DeskAdX.dll -> Spyware.WinAD.f -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\lsp_.dll -> Spyware.Sahat.f -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SAHAgent_.exe -> Spyware.Sahat.f -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SahHtml_.exe -> Spyware.Sahat.f -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SAHUninstall_.exe -> Spyware.Sahat.f -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WEBInstaller.dll -> Spyware.SAHA -> Cleaned with backup
C:\WINDOWS\fihywufwzzf.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\nem220.dll -> TrojanDownloader.Dyfuca -> Cleaned with backup
::Report End
____________________________________________________________________
thanks in advance!!!