G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.general (More info?)

i had nail.exe and aurora runnin in my comp 4 days
i used microsoft antispyware, nav2005, mcafee 9.0, registry repair pro,
spyware doctor n system mechanic but to no avail
all detect the file n delete the file but the next time i scan there
bck again
tday suddenly all my .exe files stopped functionin. i cant reinstall
windows, run any antivirus or do anytin
wen i click a exe file it asks to choose program

pls help
dude_51189@yahoo.co.in
 

Susan

Distinguished
Apr 8, 2004
249
0
18,680
Archived from groups: microsoft.public.windowsxp.general (More info?)

Go to ChrisRLG's (MS-MVP) site http://malwareremoval.com/ and post a
hijackthis log. They will assist you with your problems.
<dude_51189@yahoo.co.in> wrote in message
news:1124472668.949856.279490@g47g2000cwa.googlegroups.com...
>i had nail.exe and aurora runnin in my comp 4 days
> i used microsoft antispyware, nav2005, mcafee 9.0, registry repair pro,
> spyware doctor n system mechanic but to no avail
> all detect the file n delete the file but the next time i scan there
> bck again
> tday suddenly all my .exe files stopped functionin. i cant reinstall
> windows, run any antivirus or do anytin
> wen i click a exe file it asks to choose program
>
> pls help
> dude_51189@yahoo.co.in
>
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.general (More info?)

dude_51189@yahoo.co.in wrote in news:1124472668.949856.279490
@g47g2000cwa.googlegroups.com:

> i had nail.exe and aurora runnin in my comp 4 days
> i used microsoft antispyware, nav2005, mcafee 9.0, registry repair pro,
> spyware doctor n system mechanic but to no avail
> all detect the file n delete the file but the next time i scan there
> bck again
> tday suddenly all my .exe files stopped functionin. i cant reinstall
> windows, run any antivirus or do anytin
> wen i click a exe file it asks to choose program
>
> pls help
> dude_51189@yahoo.co.in
>
>

You have to get rid of the nail.exe file first. nail.exe gets added to
the shell line in the registry. it also is re-added to that line by some
other program it starts. i realized this because i left the task manager
in the process view when i closed it. when i would re-open it, it would
then start in the processes tab. at the bottom it says the number of
processes. when i brought it up, for a fraction of a second it would say
22 processes, then 21 processes. the other program would hide itself from
the task manager, and re-create nail.exe if it is deleted. there was the
nail.exe in the shell line.

in order to delete nail.exe, you must start from a DOS boot disk and work
in straight DOS. if your hd is formatted NTFS, you'll have to get a boot
disk that enables ntfs read/write...try www.bootdisk.com .

once i was able to delete nail.exe, on a reboot, i got the error, 'file
not found', when it tried to start nail.exe from the shell line, since i
deleted it in DOS. the PC was easily cleaned with MS Anti-Spyware
afterwards, 2 or 3 safe-mode scans later all was clean.

question tho....if you have MS antispyware, didn't the realtime engine
pick this up when it was trying to edit the shell registry entry?
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.general (More info?)

Please download ewido security suite it is a free version of the program.
http://www.pcbutts1.com/downloads/ewidosetup.exe
Install ewido security suite
When installing, under "Additional Options" uncheck..
Install background guard
Install scan via context menu
Launch ewido, there should be an icon on your desktop, double-click it.
The program will now open to the main screen.
When you run ewido for the first time, you will get a warning "Database
could not be found!". Click OK. We will fix this in a moment.
You will need to update ewido to the latest definition files.
On the left hand side of the main screen click update.
Then click on Start Update.
The update will start and a progress bar will show the updates being
installed.
(the status bar at the bottom will display "Update successful")
Exit ewido. DO NOT SCAN YET.

Download CCleaner and install it, but do not run it yet.
http://www.pcbutts1.com/downloads/ccsetup122.exe

Please download this file: Revised Installer for the Nailfix Utility
http://www.pcbutts1.com/downloads/nailfix1.exe
Save it to your desktop.
DO NOT RUN IT YET.

Next configure Windows to show all files

Do one of the following:
In Windows XP, on the taskbar, click Start > My Computer.
In Windows 2000/Me/98, on the Windows desktop, double-click the My Computer
icon.
Do one of the following:
In Windows XP/2000/Me, on the Tools menu, click Folder Options.
In Windows 98, on the View menu, click Folder Options.
On the View tab, uncheck Hide file extensions for known file types.
Do one of the following:
In Windows XP/2000/Me, uncheck Hide protected operating system files. Then,
under the "Hidden files" folder, click Show hidden files and folders.
In Windows 98, in the Advanced Settings box, under the "Hidden files"
folder, click Show all files.
If you see a warning message, click Yes.
Click Apply.
Click OK.

Next, please reboot your computer in SafeMode by doing the following:
Restart your computer.After hearing your computer beep once during startup,
but before the Windows icon appears, press F8.Instead of Windows loading as
normal, a menu should appear
Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click on nailfix.exe.
Click "Next" in the setup
Make sure "Run Nailfix" is checked and click "Finish".
Your desktop and icons will disappear and reappear, and a window should open
and close very quickly --- this is normal.

Now open ewido and do a scan of your system.
Click on scanner
Click on Complete System Scan and the scan will begin.
NOTE: During some scans with ewido it is finding cases of false positives.**
You will need to step through the process of cleaning files one-by-one.
If ewido detects a file you KNOW to be legitimate, select none as the
action.
DO NOT select "Perform action on all infections"
If you are unsure of any entry found select none for now as the action.
Once the scan has completed, there will be a button located on the bottom of
the screen named Save report
Click Save report.
Save the report .txt file to your desktop or a location where you can find
it easily.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere
and the game "Risk")

Download HijackThis http://www.pcbutts1.com/downloads/HijackThis.zip
Now run HijackThis, click Scan, and place a checkmark next to each of the
following items:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Close all open windows except for HJT, then click the Fix Checked button.
Close HJT.

Locate and delete the following File
C:\WINDOWS\Nail.exe
For Windows NT or 2000 it would be
C:\winnt\Nail.exe

Now run CCleaner
Uncheck "Cookies" under "Internet Explorer".
If running Firefox: click on the "Applications" tab and uncheck "Cookies"
under "Firefox".
Click on Run Cleaner in the lower right-hand corner. This can take quite a
while to run.

Finally, restart your computer in normal mode and please post a new
HijackThis log, as well as the report log from the Ewido scan by using Add
Reply.

If IE is not working, the links I gave you are direct download links and
should work. If they don't then paste them into another browser or explorer
window. If you have no other browser then email me with a valid email
address and I will send you one. We will fix IE after all the spyware is
gone.



--


The best live web video on the internet http://www.seedsv.com/webdemo.htm
NEW Embedded system W/Linux. We now sell DVR cards.
See it all at http://www.seedsv.com/products.htm
Sharpvision simply the best http://www.seedsv.com



<dude_51189@yahoo.co.in> wrote in message
news:1124472668.949856.279490@g47g2000cwa.googlegroups.com...
>i had nail.exe and aurora runnin in my comp 4 days
> i used microsoft antispyware, nav2005, mcafee 9.0, registry repair pro,
> spyware doctor n system mechanic but to no avail
> all detect the file n delete the file but the next time i scan there
> bck again
> tday suddenly all my .exe files stopped functionin. i cant reinstall
> windows, run any antivirus or do anytin
> wen i click a exe file it asks to choose program
>
> pls help
> dude_51189@yahoo.co.in
>
 

Susan

Distinguished
Apr 8, 2004
249
0
18,680
Archived from groups: microsoft.public.windowsxp.general (More info?)

Supposedly Ewido has addressed the problems of false positives so that is
not relevant now. Also there can be other files that need to be removed
other than the Nail.exe which shows up as a F2 entry in the hijackthis log.
Go to ChrisRLG's site and do hijackthis log. All help is free!
"pcbutts1" <pcbutts1@seedsv.com> wrote in message
news:RspNe.145$Ux3.120@newssvr21.news.prodigy.com...
> Please download ewido security suite it is a free version of the program.
> http://www.pcbutts1.com/downloads/ewidosetup.exe
> Install ewido security suite
> When installing, under "Additional Options" uncheck..
> Install background guard
> Install scan via context menu
> Launch ewido, there should be an icon on your desktop, double-click it.
> The program will now open to the main screen.
> When you run ewido for the first time, you will get a warning "Database
> could not be found!". Click OK. We will fix this in a moment.
> You will need to update ewido to the latest definition files.
> On the left hand side of the main screen click update.
> Then click on Start Update.
> The update will start and a progress bar will show the updates being
> installed.
> (the status bar at the bottom will display "Update successful")
> Exit ewido. DO NOT SCAN YET.
>
> Download CCleaner and install it, but do not run it yet.
> http://www.pcbutts1.com/downloads/ccsetup122.exe
>
> Please download this file: Revised Installer for the Nailfix Utility
> http://www.pcbutts1.com/downloads/nailfix1.exe
> Save it to your desktop.
> DO NOT RUN IT YET.
>
> Next configure Windows to show all files
>
> Do one of the following:
> In Windows XP, on the taskbar, click Start > My Computer.
> In Windows 2000/Me/98, on the Windows desktop, double-click the My
> Computer icon.
> Do one of the following:
> In Windows XP/2000/Me, on the Tools menu, click Folder Options.
> In Windows 98, on the View menu, click Folder Options.
> On the View tab, uncheck Hide file extensions for known file types.
> Do one of the following:
> In Windows XP/2000/Me, uncheck Hide protected operating system files.
> Then, under the "Hidden files" folder, click Show hidden files and
> folders.
> In Windows 98, in the Advanced Settings box, under the "Hidden files"
> folder, click Show all files.
> If you see a warning message, click Yes.
> Click Apply.
> Click OK.
>
> Next, please reboot your computer in SafeMode by doing the following:
> Restart your computer.After hearing your computer beep once during
> startup, but before the Windows icon appears, press F8.Instead of Windows
> loading as normal, a menu should appear
> Select the first option, to run Windows in Safe Mode.
> Once in Safe Mode, please double-click on nailfix.exe.
> Click "Next" in the setup
> Make sure "Run Nailfix" is checked and click "Finish".
> Your desktop and icons will disappear and reappear, and a window should
> open and close very quickly --- this is normal.
>
> Now open ewido and do a scan of your system.
> Click on scanner
> Click on Complete System Scan and the scan will begin.
> NOTE: During some scans with ewido it is finding cases of false
> positives.**
> You will need to step through the process of cleaning files one-by-one.
> If ewido detects a file you KNOW to be legitimate, select none as the
> action.
> DO NOT select "Perform action on all infections"
> If you are unsure of any entry found select none for now as the action.
> Once the scan has completed, there will be a button located on the bottom
> of the screen named Save report
> Click Save report.
> Save the report .txt file to your desktop or a location where you can find
> it easily.
> **(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere
> and the game "Risk")
>
> Download HijackThis http://www.pcbutts1.com/downloads/HijackThis.zip
> Now run HijackThis, click Scan, and place a checkmark next to each of the
> following items:
>
> F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
>
> Close all open windows except for HJT, then click the Fix Checked button.
> Close HJT.
>
> Locate and delete the following File
> C:\WINDOWS\Nail.exe
> For Windows NT or 2000 it would be
> C:\winnt\Nail.exe
>
> Now run CCleaner
> Uncheck "Cookies" under "Internet Explorer".
> If running Firefox: click on the "Applications" tab and uncheck "Cookies"
> under "Firefox".
> Click on Run Cleaner in the lower right-hand corner. This can take quite a
> while to run.
>
> Finally, restart your computer in normal mode and please post a new
> HijackThis log, as well as the report log from the Ewido scan by using Add
> Reply.
>
> If IE is not working, the links I gave you are direct download links and
> should work. If they don't then paste them into another browser or
> explorer window. If you have no other browser then email me with a valid
> email address and I will send you one. We will fix IE after all the
> spyware is gone.
>
>
>
> --
>
>
> The best live web video on the internet http://www.seedsv.com/webdemo.htm
> NEW Embedded system W/Linux. We now sell DVR cards.
> See it all at http://www.seedsv.com/products.htm
> Sharpvision simply the best http://www.seedsv.com
>
>
>
> <dude_51189@yahoo.co.in> wrote in message
> news:1124472668.949856.279490@g47g2000cwa.googlegroups.com...
>>i had nail.exe and aurora runnin in my comp 4 days
>> i used microsoft antispyware, nav2005, mcafee 9.0, registry repair pro,
>> spyware doctor n system mechanic but to no avail
>> all detect the file n delete the file but the next time i scan there
>> bck again
>> tday suddenly all my .exe files stopped functionin. i cant reinstall
>> windows, run any antivirus or do anytin
>> wen i click a exe file it asks to choose program
>>
>> pls help
>> dude_51189@yahoo.co.in
>>
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.general (More info?)

The nailfix1.exe that I have supplied will remove all the other files. I
have removed nail/Aurora well over 25 times this way, it works.

--


The best live web video on the internet http://www.seedsv.com/webdemo.htm
NEW Embedded system W/Linux. We now sell DVR cards.
See it all at http://www.seedsv.com/products.htm
Sharpvision simply the best http://www.seedsv.com



"Susan" <dsnsacree@msn.com> wrote in message
news:Owy8BAPpFHA.1044@tk2msftngp13.phx.gbl...
> Supposedly Ewido has addressed the problems of false positives so that is
> not relevant now. Also there can be other files that need to be removed
> other than the Nail.exe which shows up as a F2 entry in the hijackthis
> log. Go to ChrisRLG's site and do hijackthis log. All help is free!
> "pcbutts1" <pcbutts1@seedsv.com> wrote in message
> news:RspNe.145$Ux3.120@newssvr21.news.prodigy.com...
>> Please download ewido security suite it is a free version of the program.
>> http://www.pcbutts1.com/downloads/ewidosetup.exe
>> Install ewido security suite
>> When installing, under "Additional Options" uncheck..
>> Install background guard
>> Install scan via context menu
>> Launch ewido, there should be an icon on your desktop, double-click it.
>> The program will now open to the main screen.
>> When you run ewido for the first time, you will get a warning "Database
>> could not be found!". Click OK. We will fix this in a moment.
>> You will need to update ewido to the latest definition files.
>> On the left hand side of the main screen click update.
>> Then click on Start Update.
>> The update will start and a progress bar will show the updates being
>> installed.
>> (the status bar at the bottom will display "Update successful")
>> Exit ewido. DO NOT SCAN YET.
>>
>> Download CCleaner and install it, but do not run it yet.
>> http://www.pcbutts1.com/downloads/ccsetup122.exe
>>
>> Please download this file: Revised Installer for the Nailfix Utility
>> http://www.pcbutts1.com/downloads/nailfix1.exe
>> Save it to your desktop.
>> DO NOT RUN IT YET.
>>
>> Next configure Windows to show all files
>>
>> Do one of the following:
>> In Windows XP, on the taskbar, click Start > My Computer.
>> In Windows 2000/Me/98, on the Windows desktop, double-click the My
>> Computer icon.
>> Do one of the following:
>> In Windows XP/2000/Me, on the Tools menu, click Folder Options.
>> In Windows 98, on the View menu, click Folder Options.
>> On the View tab, uncheck Hide file extensions for known file types.
>> Do one of the following:
>> In Windows XP/2000/Me, uncheck Hide protected operating system files.
>> Then, under the "Hidden files" folder, click Show hidden files and
>> folders.
>> In Windows 98, in the Advanced Settings box, under the "Hidden files"
>> folder, click Show all files.
>> If you see a warning message, click Yes.
>> Click Apply.
>> Click OK.
>>
>> Next, please reboot your computer in SafeMode by doing the following:
>> Restart your computer.After hearing your computer beep once during
>> startup, but before the Windows icon appears, press F8.Instead of Windows
>> loading as normal, a menu should appear
>> Select the first option, to run Windows in Safe Mode.
>> Once in Safe Mode, please double-click on nailfix.exe.
>> Click "Next" in the setup
>> Make sure "Run Nailfix" is checked and click "Finish".
>> Your desktop and icons will disappear and reappear, and a window should
>> open and close very quickly --- this is normal.
>>
>> Now open ewido and do a scan of your system.
>> Click on scanner
>> Click on Complete System Scan and the scan will begin.
>> NOTE: During some scans with ewido it is finding cases of false
>> positives.**
>> You will need to step through the process of cleaning files one-by-one.
>> If ewido detects a file you KNOW to be legitimate, select none as the
>> action.
>> DO NOT select "Perform action on all infections"
>> If you are unsure of any entry found select none for now as the action.
>> Once the scan has completed, there will be a button located on the bottom
>> of the screen named Save report
>> Click Save report.
>> Save the report .txt file to your desktop or a location where you can
>> find it easily.
>> **(Ewido for example has been flagging parts of AVG Anti-Virus,
>> pcAnywhere and the game "Risk")
>>
>> Download HijackThis http://www.pcbutts1.com/downloads/HijackThis.zip
>> Now run HijackThis, click Scan, and place a checkmark next to each of the
>> following items:
>>
>> F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
>>
>> Close all open windows except for HJT, then click the Fix Checked button.
>> Close HJT.
>>
>> Locate and delete the following File
>> C:\WINDOWS\Nail.exe
>> For Windows NT or 2000 it would be
>> C:\winnt\Nail.exe
>>
>> Now run CCleaner
>> Uncheck "Cookies" under "Internet Explorer".
>> If running Firefox: click on the "Applications" tab and uncheck "Cookies"
>> under "Firefox".
>> Click on Run Cleaner in the lower right-hand corner. This can take quite
>> a while to run.
>>
>> Finally, restart your computer in normal mode and please post a new
>> HijackThis log, as well as the report log from the Ewido scan by using
>> Add Reply.
>>
>> If IE is not working, the links I gave you are direct download links and
>> should work. If they don't then paste them into another browser or
>> explorer window. If you have no other browser then email me with a valid
>> email address and I will send you one. We will fix IE after all the
>> spyware is gone.
>>
>>
>>
>> --
>>
>>
>> The best live web video on the internet http://www.seedsv.com/webdemo.htm
>> NEW Embedded system W/Linux. We now sell DVR cards.
>> See it all at http://www.seedsv.com/products.htm
>> Sharpvision simply the best http://www.seedsv.com
>>
>>
>>
>> <dude_51189@yahoo.co.in> wrote in message
>> news:1124472668.949856.279490@g47g2000cwa.googlegroups.com...
>>>i had nail.exe and aurora runnin in my comp 4 days
>>> i used microsoft antispyware, nav2005, mcafee 9.0, registry repair pro,
>>> spyware doctor n system mechanic but to no avail
>>> all detect the file n delete the file but the next time i scan there
>>> bck again
>>> tday suddenly all my .exe files stopped functionin. i cant reinstall
>>> windows, run any antivirus or do anytin
>>> wen i click a exe file it asks to choose program
>>>
>>> pls help
>>> dude_51189@yahoo.co.in
>>>
>>
>>
>
>