1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Aroura virus problem hijack-logfile posted help!!!!

Discussion in 'PC hardware help' started by rottingkd, Jun 5, 2005.

  1. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,165
    Likes Received:
    136
    Trophy Points:
    143
    is it displaying 16 bit windows subsystem error??
     
  2. rottingkd

    rottingkd Member

    Joined:
    May 16, 2005
    Messages:
    92
    Likes Received:
    0
    Trophy Points:
    16
    nop, it reads like this

    D:\awinsfx.exe is not a valid win32 application. it happens when i try to run the program



     
    Last edited: Jun 11, 2005
  3. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,165
    Likes Received:
    136
    Trophy Points:
    143
  4. rottingkd

    rottingkd Member

    Joined:
    May 16, 2005
    Messages:
    92
    Likes Received:
    0
    Trophy Points:
    16
    D:\ is my hard drive where I downloaded the awinsfx.exe. its from there that I try to open but I get that message.!
     
  5. rottingkd

    rottingkd Member

    Joined:
    May 16, 2005
    Messages:
    92
    Likes Received:
    0
    Trophy Points:
    16
    Ok softpedia and ken solved the problem, I don't get the pop-ups no more, but I get a warning box asking me what I want to do with the files. it askes " what shall be done with these files" and gives you options...
    -move file to quarantine directory
    -delete file
    -wipe file
    -rename file
    -deny access
    -allow access

    I already tried delete, deny, wipe, files. but they keep poping up! help? again.
     
  6. ken_919

    ken_919 Regular member

    Joined:
    Oct 31, 2004
    Messages:
    244
    Likes Received:
    0
    Trophy Points:
    26
  7. rottingkd

    rottingkd Member

    Joined:
    May 16, 2005
    Messages:
    92
    Likes Received:
    0
    Trophy Points:
    16
    ok I ran both programs, i keep getting those options I posted erlier. the Nail.exe is still in my C:\windows. i think Im just gonna have to format my drive! I give uP :( thanks for all your help....... and all your attepts.
     
  8. ken_919

    ken_919 Regular member

    Joined:
    Oct 31, 2004
    Messages:
    244
    Likes Received:
    0
    Trophy Points:
    26
    I forgot to have you do this, uncheck Nail from Startup (you should see Nail in the Startup tab when you go Start-Run-type "MSCONFIG" and go to the tab and unselect Nail). Then restart computer in safe mode and run AntiVir Xp.
     
    Last edited: Jun 12, 2005
  9. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,165
    Likes Received:
    136
    Trophy Points:
    143
    did you do this as i stated in my 1st post "than still in safemode go thru windows explorer to delete those files in these locations: C:\WINDOWS\Nail.exe &c:\windows\SvcProc.exe
    check msconfig/system.ini & msconfig/startup that the 2 files are gone."
     
  10. rottingkd

    rottingkd Member

    Joined:
    May 16, 2005
    Messages:
    92
    Likes Received:
    0
    Trophy Points:
    16
    yes ddp I did as you said, delete both .Nail&Svcproc in safe mode but Nail kept appearing back. Im gonna try running antivir in safe mode see what happends.. thanks
     
  11. Mr_Del

    Mr_Del Regular member

    Joined:
    Feb 3, 2005
    Messages:
    686
    Likes Received:
    0
    Trophy Points:
    26
    I can safely tell you that anti Virus will not pick this up. Microsoft anti-spy tries but is unable to. It will remove the affected REG entries but they show back up 10 seconds after doing so. Any correct solution to this will have to be done in safe mode. The REG entries will show back up even in safe mode. I think I had to go into Safe mode ADMIN for this one. Trying in normal mode will be like shooting yourself in the foot. I will look around and find the article that helped me I may have missed a step. Will post back when I find something.

    -Del
     
  12. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    Make a batch file with the information from the other site I gave you.You will probably have a better chance manually deleting it in command prompt.
     
  13. Mr_Del

    Mr_Del Regular member

    Joined:
    Feb 3, 2005
    Messages:
    686
    Likes Received:
    0
    Trophy Points:
    26
    OK Got something that may help. I hope anyway. Go here http://www.p2p-zone.com/underground/showthread.php?t=21601 .

    Pay no attention to the very last 2 posts. They are bots and show up in many forums on this topic. Their wording is always exactly the same but the names are different. The link they give takes you to the place that created Aurora. There is a file there that claims to remove it. It will not. In fact it may make things worse.

    -Del
     
  14. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    Here try this out this a batch file I made that will remove the virus for you http://s49.yousendit.com/d.aspx?id=0EICW965Q1VB92GRE1VJSKV7B9 .All you have to do is boot up in safe mode then run the batch file.The reason the virus keeps duplicating is becuase you are not completely deleting the virus.You are missing a part of the virus which makes it keep duplicating over again.
     
    Last edited: Jun 12, 2005
  15. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    Oh and rottingkd ignore Mr_Del,this person talks of nonesense.You would be more likely to get a virus from a P2P forum than you would a virus removal site that is dedicated to removing viruses.Yeah I know I might sound like an arse,but trust me Del he is better off checking out the other sites earlier on this page man.
     
    Last edited: Jun 12, 2005
  16. Mr_Del

    Mr_Del Regular member

    Joined:
    Feb 3, 2005
    Messages:
    686
    Likes Received:
    0
    Trophy Points:
    26
    On the same note your are even more likely to get a virus from an individual.

    -Del
     
  17. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    True,but I'm not going to give him a virus they are pointless.Whoever made them should be hunted down and killed for even making them so popular.
     
  18. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    Oh and if I did put a virus on the file,don't you think it would be bigger than 4KB.Think about this viruses are small,but not that small.They normally average out to 100KB,so whatever man.
     
    Last edited: Jun 12, 2005
  19. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    Besides even you said the P2P forum you gave to him has 2 bots that direct people to the cause of the virus.That doesn't seem like a very reliable source to be honest,for all we know it could direct him right back to the virus.
     
  20. L-Burna

    L-Burna Active member

    Joined:
    Mar 25, 2003
    Messages:
    2,260
    Likes Received:
    0
    Trophy Points:
    66
    If I offended you then my bad alright,just under the weather today and am feeling cranky is all. [​IMG]
     

Share This Page