well after a few weeks of reading and playing around trying to rid myself of this and lord knows what other manifestations of it from my PC I found this site and after reading up as much as I could have taken the first necessary steps I hope in making this as easy as possible for all concerned, please find enclosed edwido and HJT logs ..hope this is right. look forward to any/all replies and help..thanks G :)
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:28:15 PM, 6/30/2005
+ Report-Checksum: 46AD2C0C
+ Date of database: 6/29/2005
+ Version of scan engine: v3.0
+ Duration: 37 min
+ Scanned Files: 171938
+ Speed: 76.78 Files/Second
+ Infected files: 34
+ Removed files: 34
+ Files put in quarantine: 34
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
E:\
+ Scan result:
C:\Documents and Settings\User Geek\Cookies\user [email]geek@34372167[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@67844141[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@ad2.pamedia.com[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@adsremote.scripps[2].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@adv.webmd[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@cgi-bin[2].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@exitexchange[2].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@fcstats.bcentral[2].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@geocities[2].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@jetstream.xtra.co[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@perf.overture[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@rb4.worldsex[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@www.myaffiliateprogram[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Cookies\user [email]geek@xtramail.xtra.co[1].txt[/email] -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\User Geek\Local Settings\Temp\temp.frCDF6 -> Trojan.Agent.db -> Cleaned with backup
C:\Program Files\Kazaa Lite K++\supertrick.txt -> Trojan.Qhost.av -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050617180530.zip/WINDOWS/system32/drivers/etc/hosts -> Trojan.Qhost.av -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050617180530.zip/WINDOWS/system32/nt77rj5k.exe -> Spyware.SAHA -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050617180530.zip/Documents and Settings/User Geek/Local Settings/Temporary Internet Files/Content.IE5/CRDJYEJL/seeve[1].exe -> Spyware.MediaMotor.f -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050617180530.zip/WINDOWS/seeve.exe -> Spyware.MediaMotor.f -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050617180530.zip/Documents and Settings/User Geek/Local Settings/Temporary Internet Files/Content.IE5/HIATC4E6/stubinstaller4292[1].exe -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050617180530.zip/WINDOWS/stubinstaller4292.exe -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050622184938.zip/Program Files/media access/mediaaccess.exe -> Spyware.WinAD -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\m67m.ocx -> Spyware.MediaMotor.a -> Cleaned with backup
C:\WINDOWS\jrmsq2g5.exe -> Spyware.SAHA -> Cleaned with backup
C:\WINDOWS\Nail.ex$ -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\qmhlysucpf.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\svcproc.ex$ -> Trojan.Stervis.c -> Cleaned with backup
C:\WINDOWS\system32\b61smoea.exe -> Spyware.SAHA -> Cleaned with backup
C:\WINDOWS\system32\cbxlzv.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\drivers\etc\hosts -> Trojan.Qhost.av -> Cleaned with backup
C:\WINDOWS\system32\drivers\etc\hosts.20050617-181657.backup -> Trojan.Qhost.av -> Cleaned with backup
C:\WINDOWS\system32\drivers\etc\hosts.20050622-185310.backup -> Trojan.Qhost.av -> Cleaned with backup
C:\WINDOWS\system32\ide21201.vxd -> Spyware.MediaPass -> Cleaned with backup
------------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:36:20 PM, on 6/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
c:\windows\system32\cbxlzv.exe
C:\Documents and Settings\User Geek\Desktop\Hijackthis.exe\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url]http://xtramsn.co.nz/home/[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [CleanRegPath] C:\PROGRA~1\ADSLUT~1\CleanReg.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SYSfit] C:\WINDOWS\SYSfit.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Backgammon - [url]http://download.games.yahoo.com/games/clients/y/at1_x.cab[/url]
O16 - DPF: Yahoo! Checkers - [url]http://download.games.yahoo.com/games/clients/y/kt4_x.cab[/url]
O16 - DPF: Yahoo! Dominoes - [url]http://download.games.yahoo.com/games/clients/y/dot8_x.cab[/url]
O16 - DPF: Yahoo! Pool 2 - [url]http://download.games.yahoo.com/games/clients/y/pote_x.cab[/url]
O16 - DPF: {00000000-0000-0000-0000-000020030000} - [url]http://www.celebritaspoglie.net/sex.exe[/url]
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - [url]http://static.windupdates.com/cab/MediaAccessVerisign/ie/bridge-c10.cab[/url]
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - [url]http://www.rovion.com/Controls/Rovion.cab[/url]
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - [url]http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab[/url]
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [url]http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120078293343[/url]
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab[/url]
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - [url]https://luckynugget.microgaming.com/luckynugget/FlashAX.cab[/url]
O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - [url]http://deposito.hostance.net/dialer/1044446.exe[/url]
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - [url]http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab[/url]
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
::Report End
Any further help would be greatly appreciated and welcomed :) of note I d/l the trojan remover via this site and I think changed the name of the nail.exe file and getting prompts still cant be found or whatever, have to excuse me as much as I try to inform myself and learn more I still feel lost when it comes to the nitty gritty of the pc workings.. :(