Aurora, ABI Division of Direct Revenue, nail.exe [CLOSED] |
Aurora, ABI Division of Direct Revenue, nail.exe [CLOSED] |
Aug 2 2005, 09:04 PM
Post
#1
|
|
|
New Member ![]() Posts: 1 OS: Windows XP |
Hiya, this is my first time posting here (hope I have all the prerequisites, and I did follow that beginner's guide here). I'm having troubles with Aurora; it seems pretty well-known here. It's actually the second time my computer's been infected with it-- the first time I was able to take care of it looking at solutions posted here for other users.
I've tried the same methods I used last time, using the recommended programs like Ewido, CCleaner, and the nailfix. It doesn't work, though. Specifically, I get stuck when I'm in safe mode trying to run Ewido. The scan freezes; stuck for an hour on 0.0%. I've restarted and tried this several times. Skipping this and trying other thigns doesn't work, but I'm sure it's not just this one program getting stuck that's the problem... I was hoping that it would help to have more specified answers, instead of just going by everyone else's solutions. Here's the log! Logfile of HijackThis v1.99.1 Scan saved at 8:53:24 PM, on 8/2/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.exe c:\windows\system32\ncvkgc.exe D:\Program Files\Winamp\winampa.exe D:\Program Files\AIM\aim.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe D:\Program Files\SpywareGuard\sgmain.exe D:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [ofxvetr] C:\WINDOWS\System32\ofxvetr.exe O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe O4 - HKLM\..\Run: [mqqqhs] c:\windows\system32\ncvkgc.exe r O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - Startup: SpywareGuard.lnk = D:\Program Files\SpywareGuard\sgmain.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe O15 - Trusted Zone: http://www.neededware.com O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe |
|
|
oxygenthief Aurora, ABI Division of Direct Revenue, nail.exe [CLOSED] Aug 2 2005, 09:04 PM
LostAccount Sorry we didn't get to your log earlier; if yo... Aug 7 2005, 12:43 PM
LostAccount Due to lack of feedback, this topic has been close... Aug 22 2005, 10:22 AM![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
0 / 222 | 1st June 2005 - 08:15 PM Bill_Daddy started - last by Bill_Daddy |
|||||
![]() |
4 / 355 | 23rd September 2005 - 08:13 PM kimikat730 started - last by Armodeluxe |
|||||
![]() |
2 / 306 | 26th September 2005 - 04:20 AM asrai started - last by kool808 |
|||||
![]() |
4 / 428 | 3rd October 2005 - 11:17 PM mochister started - last by loophole |
|||||
|
Time is now: 22nd November 2009 - 12:02 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising