

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.
Reboot into Safe Mode by hitting the F8 key until menu shows up. In some systems, this may be the F5 key, so try that if F8 doesn't work.
Go to Start->Run and type in cmd and hit OK. Then type in the following (hit Enter after each line):
cd windows
nail.exe /FullRemove
exit
Delete these files:
C:\WINDOWS\NAIL.EXE
C:\WINDOWS\ASSEST.DLL There was no such file
C:\WINDOWS\FRENNK.DLL Got an error message that read: Cannot delete frennk: Access is denied
C:\Program Files\Ebates_MoeMoneyMaker\There was no such file
Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. While in the Registry Editor, navigate to:
HKEY_CURRENT_USER\Software\ and delete aurora
HKEY_CURRENT_USER\Software\ and delete Bolger
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon Driver and delete DrPMon.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\ZepMon Driver and delete DrPMon.dllThere was no such file
If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.
Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {302A3240-4805-4a34-97D7-1645A0B08410} - (no file)There was no such file
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here.
Edited by ShoalBear, 29 April 2005 - 01:48 PM.
Upon restarting there was a error message that it couldn't find c:/windows/Nail.exe I hope that was a good sign. Here is my HJT file...No problem, let's take a another shot at this:
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.
Download KillBox http://www.greyknigh...spy/KillBox.exe. Don't run it yet.
Reboot into Safe Mode by hitting the F8 key until menu shows up. In some systems, this may be the F5 key, so try that if F8 doesn't work.
Go to Start->Run and type in cmd and hit OK. Then type in each of the following (hit Enter key after each line):
cd windows
nail.exe /FullRemove
exit
Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. While in the Registry Editor, navigate to:
HKEY_CURRENT_USER\Software\ and delete aurora
HKEY_CURRENT_USER\Software\ and delete Bolger This file didn't exist
HKEY_CLASSES_ROOT\ and delete BolgerDll.BolgerDllObj
HKEY_CLASSES_ROOT\CLSID\ and delete {302A3240-4805-4a34-97D7-1645A0B08410}
HKEY_CLASSES_ROOT\Interface\ and delete {BB0D5ADC-028D-4185-9288-722DDCE2C757}
HKEY_CLASSES_ROOT\TypeLib\ and delete {92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon Driver and delete DrPMon.dll
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\ZepMon Driver and delete DrPMon.dllThis file didn't exist
If any of the above registry keys are giving you problems deleting, right click on them and click on Permissions. Then click on the Advanced button. Make sure the first box (Inherit from parent...) is checked. Click OK and OK. Then try deleting the entry again. Once you're done, close the Registry Editor.
Make sure to close any open browsers. Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O4 - HKLM\..\Run: [csbwgib] c:\windows\system32\hnlixo.exeThis file didn't exist
Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. For each of the following files below, check the box that says 'Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot):
C:\WINDOWS\System32\HNLIXO.EXE
C:\WINDOWS\ASSEST.DLL
C:\WINDOWS\FRENNK.DLL
C:\WINDOWS\Bolger.dll
c:\windows\svcproc.exe
c:\windows\Nail.exe
c:\windows\system32\DrPMon.dll
Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here. Post a new FindIt log also.
0 members, 1 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.