Hey Engel

  • Thread starter Thread starter Ty
  • Start date Start date
T

Ty

Why do you use the same comment on everyones question?
I already did what you said. That don't do squat.
SO..if you don't have an answer don't reply.
 
How many people here have you helped today?

I'm sorry Engel's advice didn't do the job in your particular case, but he's
been helpful to lots of others.

In general, if the first answer doesn't help, it is better to come back and
say that and ask for further advice, rather than bad mouth the first person
who tried to help.
 
Because I asked a slight different question and he came
back with the same answer. I have read thread upon
thread and he says the same thing. It is like he posts
an autoreply. I didnt bad mouth him I just want to know
why he says the same thing over and over.
 
I scan with ad-aware 3 times a day. It keeps coming
back. All I want to know is why it keeps coming back. I
delete the NAIL.EXE and that didnt do anything either.
 
Hello Ty

This is my final answer

Get HijackThis from

http://tomcoyote.org/hjt/hjt199//HijackThis.exe

and let it Scan your system and Save Log. (Save it where
you can find it again.) then send the log to:
(http://aumha.net/viewforum.php?f=30)
(http://www.bleepingcomputer.com/forums/forum22.html)
(http://castlecops.com/forum67.html)
(http://forums.maddoktor2.com/index.php?showforum=17)
(http://www.spywarewarrior.com/viewforum.php?f=2)
(http://forums.spywareinfo.com/index.php?showforum=18)
(http://www.wilderssecurity.com/forumdisplay.php?f=24)
(http://boards.cexx.org/viewforum.php?f=1)
(http://www.malwarebytes.biz/forums/index.php?
showforum=5)
(http://forum.gladiator-antivirus.com/index.php)
(http://www.dslreports.com/forum/security)

Since HijackThis does not (yet) come with a install
routine, create a folder via Windows Explorer for
HijackThis, then move the file to this folder. This way
any backups created are saved in a legit folder. In too
many instances where the user runs HijackThis from a temp
folder and any backups are lost if that temp folder is
cleaned out. You should also make sure you are using the
latest version each and every time you run HijackThis, as
there are new detections added all the time.

Unzip, double-click "HijackThis.exe" and Press "Scan".

When the scan is finished, the "Scan" button will change
into a "Save Log" button.
Click: "Save Log" (generates: "hijackthis.log") HijackThis
Tutorial (recommended read)

http://www.spywareinfo.com/~merijn/htlogtutorial.html#o8
For Hijack this

Lavasoft also has a HijackThis section at their Forum.

Good luck

Engel
 
I will try Hijackthis again. I used it before. I just
want to know why...like everyone else...it all keeps
coming back. Why is it so hard to answer that? Is it
such a pain in the arse that no one has figured it out
yet? Because of these I keep getting annoying pop ups
and my pop up blockers dont get them nor does the norton
internet security pop up blocker.
 
It keeps coming back because there are three parts to this critter, and you
are only getting one, or perhaps two of them

Nail.exe is one piece. A second is a randomly named .exe

Take a look at running processes using the system explorers in Microsoft
Antispyware--you can spot the randomly named one--I forget what it calls
itself--there's something distinctive and unchanging in the left column, and
a random name on the right. If you end the process and refresh, it'll come
right back with a new name.

I found the third piece only by scanning with an antivirus tool. I used
Trend Micro's online housecall scanner.

This critter is active even in safe mode, so you need tools like killbox,
perhaps, to kill the active pieces. I did it by booting from the OS CD and
using the recovery console.

I cleaned this by hand, but there are now more automated methods. Ron
Kinner has a favorite tool, but I can't immediately find his post about it.
Here's a post from announcements which looks like it has a good set of
steps, though:
-----------------------------------------------------------------------
If you haven't had any luck with with Aurora heres how to get rid of it
without using that "my pc tuneup" (which I trust as far as I can throw it).
I've had success removing Aurora from customer's computers with this
process.

1)Before starting download a copy of NailFix, Hijack This, and either RegOCX
or Killbox which will help unregister stubborn files that do not want to
delete
2) Boot into Safe Mode
3) Run Nailfix. You icons will disappear for a second or two. This is
normal.
4) Next search for and delete the following files; nail.exe, bolger.dll,
aurora.exe, svcproc.exe, thnall1ac.html, poller.exe, uacupg.exe, DrPmon.dll.
Use Killbox or RegOCX to unregister any dlls that will not delete then try
them again. Stop any exe files that will not delete with Task Manager then
try them again.
5) Run Hijack This. check and remove any entries associated with nail.exe or
any of the other files listed above. Also check and remove these entries if
they exist:
BHO 549B5CA7-4A86-11D7-A4DF-000874180BB3
BHO FDD3B846-8D59-4ffb-8758-209B6AD74ACC
Toolbar ACB1E670-3217-45C4-A021-6B829A8A27CB
6) If you are comfortable with the registry you can also navigate to
HKEY_CurrentUser/Software/Aurora key and delete that key (if it still
exists) though it should not be absolutely necessary to do so.

Once you reboot it should be gone. Run Hijack This again to make sure that
the entries you removed are still gone. Check Task Manager to make sure none
of the programs you deleted are back and running. Check your Internet
connection. If you can surf for 15 minutes without an Aurora popup then it
is gone. Good luck.




--
 
Trojans like to hide installs in temp file locations, the registry, and
other places like System Restore and then run a monitor program that checks
to see if any of these places have been deleted by your anti-spy programs.
If they are, the info is replaced and you stay infected. Aurora is very
good at this. To kill aurora, you have to find the monitor and kill it
before you can kill the rest.

You need a process viewer, killbox, ccleaner, some antispyware program, turn
off System Restore and attack in Safe Mode with view hidden and system files
enabled.

Good luck.
 
Bill,

I used ABIRemover last week and it didn't work so I think Aurora has
mutated. This one requires hand-to-hand combat!
 
Yuck. I'm glad I've only seen one instance of it so far, first hand. That
would explain why the mypctuneup method didn't work, perhaps--it wouldn't
surprise me if their distribution methods were ahead of their removal
methods.

--
 
Back
Top