c:\windows\Nail.exe

H

halhabour

Here is my Hijackthis results. I keep getting the damn
Nail.exe and other trojans even after noadware,registry
mechanic and ad-aware se professional say it is repaired
it. well this is not true.

Please help me as I have been trying so hard to get rid
of this damn pest. Tks!

Logfile of HijackThis v1.99.1
Scan saved at 1:51:12 PM, on 07/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
D:\Sunbelt Software\iHateSpam\siService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
D:\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Sunbelt Software\iHateSpam\siMailProxyServer.exe
D:\NoAdware3\NoAdware3.exe
c:\windows\system32\hrixnsk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft
AntiSpyware\GIANTAntiSpywareMain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJackThis\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe
C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [mpckokx] c:\windows\system32
\hrixnsk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32
\ctfmon.exe
O23 - Service: System Startup Service (SvcProc) -
Unknown owner - C:\WINDOWS\svcproc.exe
 
E

Engel

This is what Ron have to said

From: "Ron Kinner" <[email protected]> Sent: 4/27/2005
9:34:41 AM

News From The Spyware Front:

Following are the latest malware and therefore the hardest
to remove:

Called nail.exe aurora or bolger.
http://webhelper4u.com/tnewswritigs/bolger_aurora.html

Ewido seems to detect and remove one version which can
also be removed by disabling its service, booting into
Safe Mode and using HijackThis to get rid of the nail and
exe (with Explorer and Iexplore turned off) then Killbox
to remove nail on reboot. but there is another version
with a TODO file that requires a repair console delete or
you can go to the maker www.mypctuneup.com/aurora and run
their uninstall which gets rid of aurora but may install
something else. They make you fill out a form and then
will send you a code to use with the uninstaller. Use a
throwaway email address if you do and lie like crazy on
the form.

http://www.webhelper4u.com/tnewswritigs/mypctuneupmain.html

Another popular one right now is wp.exe which is the
smitfraud.c and which tears up the registry entries for
your desktop so you can't remove the warnign that
appears. Changes the registry to to add System under
Policies and adds some keys to limit the Display
Properties by removing Web and Background tabs.

This is it here:

http://securityresponse.symantec.com/avcenter/venc/data/tro
jan.desktophijack.html

(Same link but in smaller form since i guess that one will
wrap)

http://tinyurl.com/87n46

Then we have the bhoass.dll "Trojan.Win32.Agent.cx"

C:\WINNT\system32\bss.dll
C:\WINNT\bhoass.dll
C:\WINNT\system32\MSIMN32.EXE
C:\WINNT\system32\TASKMGRU.EXE
C:\WINNT\explorer32dbg.exe
C:\WINNT\iexplore_dbg.exe
C:\WINNT\ghj

this is just six of the files. There are about 10 in
all. The only way I can get rid of them is to use Killbox
to delete all of them on boot. And afterwards Explorer
(the desktop) won't run. Sample hjt log:

http://www.techsupportforum.com/computer/topic/49162-1.html

Also have a random named file that attaches itself to
winlogon notify and won't let go. Often seen in the
company of another random name file that pretends to be
Kavsvc or Navsvc. The Kavsvc file will sometimes go away
with mwav.exe from kaspersky. Nothing seems to work on
the winlogon notify critter. Believe it's a variation on
L2M.

O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\rlinzp.exe
O20 - Winlogon Notify: OemStartMenuData -
C:\WINDOWS\system32\p2r4lc9q1f.dll

None are removed completely by AntiSpy unless there has
been a new update that I don't know of..

One final tip. A lot of the new stuff seems to use the
Task Scheduler as a backup. Start, (Settings,) Control
Panel, Scheduled Tasks and remove any that you don't
recognize especially any that have a path that includes
the Application or Temp Folders.

Good luck

Engel
-----Original Message-----
Here is my Hijackthis results. I keep getting the damn
Nail.exe and other trojans even after noadware,registry
mechanic and ad-aware se professional say it is repaired
it. well this is not true.

Please help me as I have been trying so hard to get rid
of this damn pest. Tks!

Logfile of HijackThis v1.99.1
Scan saved at 1:51:12 PM, on 07/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
D:\Sunbelt Software\iHateSpam\siService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
D:\Sunbelt Software\iHateSpam\siSpamFilterEngine.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Sunbelt Software\iHateSpam\siMailProxyServer.exe
D:\NoAdware3\NoAdware3.exe
c:\windows\system32\hrixnsk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft
AntiSpyware\GIANTAntiSpywareMain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJackThis\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe
C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [mpckokx] c:\windows\system32
\hrixnsk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32
\ctfmon.exe
O23 - Service: System Startup Service (SvcProc) -
Unknown owner - C:\WINDOWS\svcproc.exe


.
 
A

AndyManc

Hi I've removed this a few times using reg fixes and
Different removers but tested the mypctuneup unistaller
last week and its really speeds things up when used with
a couple of other programs.



Stop svcproc by going to start then run and type :

services.msc

then press enter,press name on the services list to sort
them into order then find svcproc and right click and
choose properties,on this screen press 'stop' then change
the start up type from 'Automatic' to 'Disabled' , press
apply then exit .


The unistaller from mypctuneup helps but didnt remove
bolger.dll,DrPMon.dll as these were in the system restore
area(Not sure how as i never set a restore point) The
unistaller also didnt remove the random file in the
system folder,it also left a entry in windows >Lastgood


Ran aurora.exe(aurora dissapears) which created the
random names and the svcproc,nail and bolger entries in
hijack this.
These are the entries :

F2 - REG:system.ini: Shell=Explorer.exe
C:\WINDOWS\Nail.exe

O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-
1645A0B08410} - C:\WINDOWS\Bolger.dll

O4 - HKLM\..\Run: [Smtmiz] C:\WINDOWS\miahzo.exe (this
file changes it's name each time you boot - but it will
be in the same place in the log)

O23 - Service: System Startup Service (SvcProc) - Unknown
owner - C:\WINDOWS\svcproc.exe

R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant =


Every time i reboot the random filename in the windows
folder changes Plus get error messages saying cannot find
c/documents each time i reboot

Once i opened a internet window i started getting the pop-
ups for ringtones & top 30 chart tones,

Most of the scanners i used found the adware
(Spysweeper,spybot & adaware) but i left it all in place
to check the unistaller from mypctuneup


Downloaded the unistaller from www.mypctuneup.com and
saved it to desktop .


Ran the unistaller in normal mode as it needs to connect
to the internet,got the message saying it was now
uninstalled and i needed to reboot to finish the removal.

Rebooted and checked hijack This(random files and bolger
still exist Plus a new R0 search assistant line now
showing in Hijack this but no address at the end)

Nail.Svcproc & the run command for the random file have
been removed)


Next i ran Ewido on a full scan in safe mode (reboot and
keep tapping F8 then choose safe mode)and it found two
random files

C:\WINDOWS\LastGood\vhnxhlfnlqa.exe
C:\WINDOWS\system32\miahzo.exe

Spyware.BetterInternet -> Cleaned without backup



Ran Adaware SE on a full system scan which found the
remaining Aurora files which were in the system restore
area:

Heres some of the results page:


Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

VX2 Object Recognized!
Type : File
Data : A0000484.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume
Information\_restore{8FE56BBB-AC57-40EE-9F8C-616AA6F0D4ED}
\RP12\
FileVersion : 0, 12, 4, 96
ProductVersion : 0, 12, 4, 96
ProductName : bolger
CompanyName : Bolger
FileDescription : www.abetterinternet.com
InternalName : bolger
LegalCopyright : Copyright © 2005
OriginalFilename : bolger.dll
Comments : www.abetterinternet.com


VX2 Object Recognized!
Type : File
Data : A0000486.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume
Information\_restore{8FE56BBB-AC57-40EE-9F8C-616AA6F0D4ED}
\RP12\
FileVersion : 1, 0, 0, 5
ProductVersion : 1, 0, 0, 0
ProductName : DrPMon PrintMonitor
CompanyName : Direct Revenue
FileDescription : DrPMon PrintMonitor
InternalName : DrPMon
LegalCopyright : Copyright (C) 2005
OriginalFilename : DrPMon.dll


VX2 Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet
explorer\toolbar\webbrowser
Value : {0E5CBF21-D15F-11D0-8301-
00AA005B4383}


VX2 Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet
explorer\main\featurecontrol\feature_window_restrictions
Value : iexplore.exe


As it was showing 2 being in the system restore i removed
them anyway using Adaware to clear the reg entries Then
cleared the system restore and rebooted.

(To turn off system restore goto start > right click my
computer and choose properties >then system restore >
check the box that says ' turn off system restore ) then
apply and exit.This is required and it can be re-enabled
once you are clean by following the same as above but
unchecking the box turn off system restore .

I ran Hijack this and there was no traces left except the
new R0 search asssistant line so closed all
windows,checked that entry and pressed 'Fix Checked'

I also used Ccleaner on all 3 settings
(windows,applications and issues ) to remove any other
traces in the temp files then reset web settings (open a
internet window > goto tools on the top bar > then
internet options > then programs > and press 'Reset Web
Settings' then rebooted .


After running the unistaller from mypctuneup and both
Ewido and Adaware in safe mode and Ccleaner its now
cleared Aurora.
No scanners are showing any problems
(Ewido,Spysweeper,Spybot,Adaware etc..) plus the hijack
this log is clear


And no ringtone pop-ups :)



Regards Andy


Download These :


Ad-Aware SE

http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-
8022_4-10399602.html?tag=sptlt_s


Ewido Security Suite :

http://download.ewido.net/ewido-setup.exe


Ccleaner :

http://download.ccleaner.com/download119bin.asp








While im posting Here's results from Jordi Bosveld's site
for the main files of Aurora so you know what scanners
target them .



Aurora.exe


INFECTED/MALWARE
MD5 1f5cb7887de415347034735cc05480be
Packers detected: PE_PATCH
Scanner results
AntiVir Found nothing
Avast Found Win32:Trojano-1373
AVG Antivirus Found nothing
BitDefender Found Trojan.Spybi
ClamAV Found Trojan.W32.Spybi
Dr.Web Found Trojan.Spybi
F-Prot Antivirus Found nothing
Fortinet Found Adware/Abetterintrnt
Kaspersky Anti-Virus Found not-a-
virus:AdWare.BetterInternet.c
mks_vir Found nothing
NOD32 Found nothing
Norman Virus Control Found Sandbox: W32/Malware; [
General information ]

* File length: 217088 bytes.

[ Changes to filesystem ]
* Deletes file C:\WINDOWS\dvrszibcpua.exe.
* Creates file C:\WINDOWS\jwfbcd.exe.

[ Process/window information ]
* Creates a mutex amanlcprhxjgmhnuuyfbkxhmp.
* Enumerates running processes.
* Enumerates running processes several parses....
* Modifies other process memory.
* Creates a remote thread.
VBA32 Found AdWare.BetterInternet.c





Bolger.dll


Status: INFECTED/MALWARE
MD5 67da1e869864f3b17dbd66e58a3d29c5
Packers detected: -
Scanner results
AntiVir Found nothing
Avast Found Win32:Bolger
AVG Antivirus Found nothing
BitDefender Found Trojan.BettInet.172032.DLL
ClamAV Found nothing
Dr.Web Found not a virus Adware.BetterInternet
F-Prot Antivirus Found nothing
Fortinet Found Adware/Abetterintrnt
Kaspersky Anti-Virus Found not-a-
virus:AdWare.BetterInternet
mks_vir Found .Betterinternet.J
NOD32 Found nothing
Norman Virus Control Found W32/BetterInternet
VBA32 Found AdWare.BetterInternet



DrPMon.dll


Status: INFECTED/MALWARE
MD5 6f9c45b6886d1ba6df97914a78b48bf3
Packers detected: -
Scanner results
AntiVir Found TR/Click.Age.DB.Dll
Avast Found Win32:Trojano-1375
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found Trojan.Drpmon
F-Prot Antivirus Found nothing
Fortinet Found W32/Agent.DB-tr
Kaspersky Anti-Virus Found Trojan.Win32.Agent.db
mks_vir Found Trojan.Agent.Db
NOD32 Found Win32/Agent.DB
Norman Virus Control Found W32/Agent.CSZ
VBA32 Found Trojan.Win32.Agent.db




Nail.exe


Status: INFECTED/MALWARE
MD5 d959377938f29d91ca1cd533fea2efbb
Packers detected: ASPACK
Scanner results
AntiVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Adware.Nail.A
ClamAV Found nothing
Dr.Web Found Trojan.Nail
F-Prot Antivirus Found nothing
Fortinet Found W32/Nailed.A-tr
Kaspersky Anti-Virus Found not-a-
virus:AdWare.BetterInternet.b
mks_vir Found Trojan.Nail.B3
NOD32 Found nothing
Norman Virus Control Found nothing
VBA32 Found Trojan.Nail



svcproc.exe



Status: INFECTED/MALWARE
MD5 be4b9d69e562409d621a8bd4cf74a646
Packers detected: PE_PATCH, UPX
Scanner results
AntiVir Found TR/Stervice.C
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Trojan.Stervis.C
ClamAV Found nothing
Dr.Web Found Trojan.Stervis
F-Prot Antivirus Found W32/Agent.NN
Fortinet Found W32/Agent.NN
Kaspersky Anti-Virus Found Trojan.Win32.Stervis.c
mks_vir Found Trojan.Stervis.C
NOD32 Found nothing
Norman Virus Control Found nothing
VBA32 Found Trojan.Win32.Stervis.c

yuldnyt.exe (random filename)


Status: INFECTED/MALWARE
MD5 2173316d0b1da50219daf85545e85add
Packers detected: PE_PATCH
Scanner results
AntiVir Found nothing
Avast Found Win32:Trojano-1373
AVG Antivirus Found nothing
BitDefender Found Trojan.Spybi
ClamAV Found Trojan.W32.Spybi
Dr.Web Found Trojan.Spybi
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-
virus:AdWare.BetterInternet.c
mks_vir Found nothing
NOD32 Found nothing
Norman Virus Control Found Sandbox: W32/Malware; [
General information ]

* File length: 217088 bytes.

[ Changes to filesystem ]
* Deletes file C:\WINDOWS\dvrszibcpua.exe.
* Creates file C:\WINDOWS\jwfbcd.exe.

[ Process/window information ]
* Creates a mutex amanlcprhxjgmhnuuyfbkxhmp.
* Enumerates running processes.
* Enumerates running processes several parses....
* Modifies other process memory.
* Creates a remote thread.
VBA32 Found AdWare.BetterInternet.c




MyPCUninstaller.exe


Status:

(Sandbox emulation took a long time and/or runtime
packers were found, this is suspicious. Normally programs
aren't packed and don't force the sandbox into
lengthy emulation. Do realize no scanner issued any
warning, the file can very well
be harmless. Caution is advised, however.)
MD5 6fb6a7e947b13bdddddbf5f57b30c0ca


;)
..
 
A

AndyManc

I Forgot to add this in my last post,I used Hijack this
to fix the bolger line as it still existed after running
the uninstall from mypctuneup. Adaware detected Bolger in
the System restore area so probably would of removed the
C:\windows\bolger.dll as well if i had left it.

O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-
1645A0B08410} - C:\WINDOWS\Bolger.dll


Also I found alot of thnall1ac.html. files in the
prefetch folder.(This is the file that registers the
bolger.dll as when i was testing it was the file that
kept accessing the net as i was getting norton warnings
every 2 mins untill it started showing pop ups then the
warning stopped)

To check goto start then run and type

prefetch

and clear any found


Good Luck

Andy
 
S

Steven

I had the nail trojan in my system. This is what I did
to remove it (after running several programs that claimed
to remove it). Some of these steps may not be necessary,
but this process did remove the virus.
1. create a blank file in the windows directory - the
name doesn't matter.
2. reboot into safe mode - command prompt. This is the
only way to access the virus without it running. Regular
safe mode has the virus running, so it writes itself back
as soon as you delete it. (press F8 right after POST to
get the menu)
3. switch to the windows directory
4. delete nail.exe
5. rename the blank file to nail.exe
6. press ctrl-alt-del to reboot
7. reboot into safe mode. You should get a message that
nail.exe is not a valid program - just click ok.
8. run regedit
9. search for nail.exe
10. replace nail.exe with explorer.exe
11. scan your system - Trend internet security and
Microsoft antispyware work well.
12. reboot

That will get rid of nail.exe. I don't know about bolger.
 
A

AndyManc

If you really dont want to use the uninstaller from
mypctuneup then remove Aurora in this way:

To go for this manually here's the best way:



For Aurora Use This Fix

----------------------------------------------------------
For Xp Download Nailfix

http://andymanchesta.com/Downloads/nailfix.zip

Download the Remover to your desktop


windows 2000 download nailfix2k


http://andymanchesta.com/Downloads/nailfix2k.zip

----------------------------------------------------------
Download The ABI remover (Better Internet Remover)

http://andymanchesta.com/Downloads/ABIremover.zip


Download the Remover to your desktop
----------------------------------------------------------

Download latest Hijackthis and unpack it in its own folder
(either desktop or c/drive)

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

----------------------------------------------------------

Download Ewido Security Suite

http://download.ewido.net/ewido-setup.exe

----------------------------------------------------------
Download Ccleaner

http://download.ccleaner.com/download119bin.asp

----------------------------------------------------------


Reboot into Safe Mode by hitting the F8 key repeatedly
until a menu shows up (and choose Safe Mode from the list)


start the ABIRemover.exe, press install, wait (explorer
window will disapear)



in Safe Mode, please double-click on nailfix.bat (or
nailfix2k.bat if you have Windows 2000). Your desktop and
icons will disappear and reappear, and a window should
open and close very quickly.


Next run a full scan in Ewido



Hopefully this will kill this but you can check for
entries in hijack this,Reboot and run hijack this,choose
to run a scan and save the logfile,The entries related to
this are these:

F2 - REG:system.ini: Shell=Explorer.exe
C:\WINDOWS\Nail.exe

O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-
1645A0B08410} - C:\WINDOWS\Bolger.dll

O4 - HKLM\..\Run: [hjnyDA] C:\WINDOWS\kkuibquo.exe (this
file changes it's name - but it will
be in the same place in the log)

O23 - Service: System Startup Service (SvcProc) - Unknown
owner - C:\WINDOWS\svcproc.exe


If you find them put a tick beside them in hijack this
close all windows and choose fix checked



run a online virus scan to check for any other malware


Trend Micro http://housecall.antivirus.com/

Panda
http://www.pandasoftware.com/activescan/co...n_principal.h
tm


If you are clean again you can delete nailfix,ewido and
ABI remover if not post the hijack this log either on
here or to my email


Andy
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top