Are you seeing popups labelled Aurora?
Here's the registry location I believe is involved:
HJEY_LOCAL_MACHINE\SOFTWARE\Microsoft|Windows NT\CurrentVersion\Winlogon
Look at the Shell value--it should have Explorer.exe and nothing else in it.
It won't hurt to search the registry on "nail.exe" either.
You have found a file which is active even in safe mode, I suspect. One
approach to this is to use killbox:
http://www.bleepingcomputer.com/files/killbox.php
Another is to boot to the recovery console by booting with your original
Windows CD--use some care--this facility may not exist on some OEM recovery
CD's--and choosing R at the first prompt to start the recovery console.
This is a command line separate recovery facility which can see certain
parts of your installed Windows. It happens that this bug lives in the
parts it can see. You will definitely be able to delete this file from the
recovery console.