Okay...this is weird

Discussion in 'Malware Help (A Specialist Will Reply)' started by msbehavin, Jul 27, 2005.

  1. msbehavin

    msbehavin Private E-2

    Sorry...I meant, I can delete nail.exe but it only reappears a few seconds later, until I've deleted it 3 times and then it stays gone but it is still on my computer because if I close windows explorer and then re-open it and go back to nail.exe, it's there again.

    When you asked if I see nail.exe, do you mean in my HJT log? If so, I can see F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe in my HJT log. If you meant, can I see it in windows explorer...yes.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Print or save this instructions locally because you must be offline and have no other Windows (like browsers or anything else running) before continuing.

    - Click Start > Run and type: cmd and then click OK! This brings up a command prompt window.

    Now leave the command prompt Window open and bring up Windows Task Manager by pressing CTRL-SHIFT-ESC simultaneously. Do not be alarmed when you see you Desktop (icons etc)disappear when you do the next steps. Do not close Task Manager until I tell you to do so.

    -Now locate explorer.exe in the Process list and right click on it and select End Process

    You should now only have two Windows showing Task Manager and the command prompt.

    - At the command prompt opens, type the below commands each follow by the enter key. Take note of what happens with each one and tell me about it later when you come back here:
    nail.exe /FullRemove
    cd c:\windows
    attrib -r -s -h nail.exe
    del nail.exe
    exit <--- this will close the command prompt window


    Now go back to Task Manager and click File, and select New Task (Run....). Enter explorer.exe into the popup and click OK. This should bring back your Desktop.

    Now get back online and come back here and tell me what happened.

    You can close Task Mana ger now if your Desktop came back okay. If it did not come back, just reboot your PC now.
     
  3. msbehavin

    msbehavin Private E-2

    Okay, I did exactly what you said and kept an eye on the Task Manager as I deleted all that stuff but nothing really happened. My school, Georgia Southern University, requires us to run this Clean Access program on our computers in order to have access to their internet and all I noticed that happened when I deleted all of those files was that I got a Clean Access popup that notified me that Aurora was currently running on my system. But nothing else happened that I know of, no error messages or anything...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you entered the del nail.exe command did it work with out any error messages?

    Have you rebooted since running the steps in the last message?

    Post a new HJT log.
     
  5. msbehavin

    msbehavin Private E-2

    Nope, no error messages. And no I have not rebooted, should I?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No do not reboot yet!

    Use Windows Explorer right now and tell me if you see the c:\windows\nail.exe file.
     
  7. msbehavin

    msbehavin Private E-2

    No, I don't see it and I'm not getting the popups anymore. Does that mean its really gone :) or could it still be hiding somewhere?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be hiding within another program! We will see after a reboot but first do the following:

    Use Windows Explorer and goto to c:\windows
    Locate the file named system.ini and open it with notepad or a similar file editor.
    Find the line that refers to nail.exe and delete it. It probably says something like: Shell=Explorer.exe C:\WINDOWS\Nail.exe
    Then save the file.
    Now get a HJT log. Is the F2 line with nail.exe on it gone?
     
  9. msbehavin

    msbehavin Private E-2

    There is no line that refers to nail.exe
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What about in your HJT log?
     
  11. msbehavin

    msbehavin Private E-2

    Yup, it is still there in the HJT log. Whoever created Aurora did a damn good job because it sure is a hassle to get rid of :eek: I know its triple the hassle for you because you actually have to figure this out, I'm just doing what you tell me! But take your time because I'm going to bed for the night! Thanks so much for your help so far :)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it has never been this difficult to remove. Something on your PC seems to be blocking the changes. Either one of the tools (maybe even the item for school) or possible a system file like explorer.exe has become infected.

    Have HJT fix the F2 line then scan again with HJT to make sure it is gone.
    If it is gone reboot (or power down for the night). We will see tomorrow (later today) if it comes back.

    Good night!
     
  13. msbehavin

    msbehavin Private E-2

    It seems to be gone, even after a reboot. :) I'll be back later today...good night!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good! Let us know tonight if it is still gone.

    Also, how is everything working now. We removed a load of bad stuff from your PC!
     
  15. msbehavin

    msbehavin Private E-2

    Everything still seems to be fine!! Is there anything else I should do?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well this time let's make sure we go thru all the steps in the below thread. Some you already have now (like the firewall and an AV). But make sure you check all the other steps (even Windows Update)!

    How to Protect yourself from malware!
     
  17. msbehavin

    msbehavin Private E-2

    Alright I followed all the steps this time, hopefully I won't be back here again (for a bad reason, I mean..haha) Thanks so much for your help, I really really appreciate it! You guys are my heroes! :)
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Hopefully you do not have any further malware problems;however, please realize that while running the steps in the How to thread does help a lot. No protection is perfect and the first line of security begins with the users of the PC. Watch what you click on. Read before clicking. Sometimes the answer is the opposite of what you think (they try to trick you). Always read software license and privacy agreements (you'll be surprised what is in some of them). Be very very careful of letting other people use your PC with full administrator priviledges.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds