Alrite, i completed all the scans and here are the results:
for the Ewido Scan log:
———————————————————
ewido security suite - Scan report
———————————————————
+ Created on: 6:26:15 PM, 06/06/2005
+ Report-Checksum: 85AD9A02
+ Date of database: 06/06/2005
+ Version of scan engine: v3.0
+ Duration: 56 min
+ Scanned Files: 55957
+ Speed: 16.60 Files/Second
+ Infected files: 63
+ Removed files: 63
+ Files put in quarantine: 63
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
D:\
E:\
+ Scan result:
C:\WINDOWS\Nail.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\exbjsnwex.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\XPsys.exe -> TrojanDownloader.Delf.ia -> Cleaned with backup
C:\WINDOWS\24660.exe -> Spyware.Delf.bk -> Cleaned with backup
C:\WINDOWS\yahoo22.exe -> Spyware.Delf.bk -> Cleaned with backup
C:\WINDOWS\56561.exe -> Spyware.Delf.bk -> Cleaned with backup
C:\0xf9.exe -> TrojanDownloader.Apher -> Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq15.tmp -> Spyware.WebRebates -> Cleaned with backup
C:\Program Files\Baidu\bar\BaiduBar.dll -> Spyware.Baidu -> Cleaned with backup
C:\Documents and Settings\Jerry Liu\Local Settings\Temp\F.tmp\thnall1ac.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Jerry Liu\Local Settings\Temp\temp.fr2B81\WToolsA.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\Documents and Settings\Jerry Liu\Local Settings\Temp\temp.fr76B5\common.dll -> Spyware.WebSearch.aj -> Cleaned with backup
C:\Documents and Settings\Jerry Liu\Local Settings\Temp\temp.fr319C -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP895\A0122226.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP895\A0122289.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP896\A0122345.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP897\A0122391.exe -> Spyware.Cometsystems -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP897\A0122595.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP897\A0122742.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP897\A0122745.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP897\A0122830.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP897\A0122848.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP898\A0122880.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP899\A0122931.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP901\A0122949.DLL -> Spyware.MyWay -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP901\A0122952.dll -> Spyware.WildTangent.b -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP901\A0122962.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP902\A0122972.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP902\A0123120.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP902\A0123121.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP903\A0123122.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP903\A0123169.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP903\A0123228.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP903\A0123267.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP903\A0123270.exe -> TrojanDownloader.Dluca.a -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP904\snapshot\MFEX-85.DAT -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP904\snapshot\MFEX-96.DAT -> Spyware.WebSearch.aj -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP904\A0123303.exe -> Spyware.Wintol.y -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP904\A0123305.DLL -> Spyware.WebSearch.aj -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP904\A0123321.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP904\A0123322.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP905\A0123326.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP905\A0123503.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP905\A0123506.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP905\A0123528.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP905\A0123597.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP913\A0128171.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP913\A0128312.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP917\A0128583.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP917\A0128601.hta -> TrojanDropper.Inor.cj -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP917\A0128602.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP917\A0128603.dll -> Spyware.ToolBar.Alibabar -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP890\A0121846.dll -> Spyware.DlMax.a -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP891\A0121898.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP891\A0121935.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP892\A0122041.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP893\A0122138.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP907\A0123686.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP907\A0123723.exe -> TrojanDownloader.Delf.ia -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP907\A0123724.exe -> Spyware.Delf.bk -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP907\A0123726.exe -> TrojanDownloader.Delf.ia -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP909\A0126011.dll -> Spyware.ToolBar.Alibabar -> Cleaned with backup
C:\System Volume Information\_restore{D1E84DCE-4330-44F9-8DFD-BAD1526E8034}\RP909\A0126022.vxd -> Spyware.MediaPass -> Cleaned with backup
::Report End
And this is my current Hijackthis log, apparently i can't find the F2- REG:system.ini: Shell=Exlorer.exe C:\WINDOWS\Nail.exe (probably fixed)
Logfile of HijackThis v1.99.1
Scan saved at 6:29:50 PM, on 06/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
I:\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;;
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: Rogers Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra 'Tools' menuitem: Rogers &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\Yahoo!\browser\ysidebarIE.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: @Home - {6A6F838E-1561-4FB0-8BD1-27C6C1C66C08} -
http://home.excite.ca (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://home.excite.ca/
O16 - DPF: {11818680-FCF6-11D0-9808-0800092A4865} (FormFlow Form Control) -
https://www.cbs.gov.on.ca/obra/forms/Codebase/FormCtl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200207…meInstaller.exe
O16 - DPF: {4AD7DA15-AB2F-4C91-BEF5-3876DA4A2CCC} -
http://www.cambridgesoft.com/plugins/activ…/NetInstall.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/190b1c3b5316bb…ip/RdxIE601.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -
http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) -
http://player.bugs.co.kr/install/mv/XTools.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) -
http://install.wildtangent.com/bgn/partner…bad/install.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) -
http://player.bugs.co.kr/install/BugsLoader20041018.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) -
http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
Btw, Ewido is an excellent program, but im not quite sure if it fixed everything because my homepage still has issues, cant seem to convert it to my desired page such as yahoo.com or wutever. Your feedback would be greatly appreciated, Thank you!