{"id":30,"date":"2005-06-16T14:02:00","date_gmt":"2005-06-16T14:02:00","guid":{"rendered":"http:\/\/www.noidea.us\/wordpress\/?p=30"},"modified":"2005-06-16T14:02:00","modified_gmt":"2005-06-16T14:02:00","slug":"nailaurora-fix","status":"publish","type":"post","link":"http:\/\/www.noidea.us\/wordpress\/2005\/06\/nailaurora-fix\/","title":{"rendered":"Nail\/Aurora Fix"},"content":{"rendered":"<p><![CDATA[<b>NOTE:  These instructions have been superseded with updated procedures for the nailfix installer and a new version of Ewido.  Please post a HijackThis Log in the Malware Removal Assistance forum here or at any of the <a href=\"http:\/\/asap.maddoktor2.com\/\">ASAP Member Sites.<\/a><\/b><br \/>\n\n\n<p>\nThe following are instructions to run the Nail\/Aurora popups fix.  This can be recognized by the following lines in HijackThis:<br \/>\n\n\n<p>\n<b>F2 &#8211; REG:system.ini: Shell=Explorer.exe C:\\WINDOWS\\Nail.exe\n\n\nO23 &#8211; Service: System Startup Service (SvcProc) &#8211; Unknown owner &#8211; C:\\WINDOWS\\svcproc.exe<br \/>\n<\/b><br \/>\n\n\n<p>\nI ALWAYS recommend starting this fix by posting a HijackThis log at one of the forums listed in the <a>Spyware Help Forums<\/a> <i>FIX LINK!<\/i> section.<br \/>\n\n\n<p>Please download, install, and update the free version of <a href=\"http:\/\/www.ewido.net\/\">Ewido trojan scanner<\/a>:<br \/>\n\n\n<ol>\n\n\n<li>When installing, under &#8220;Additional Options&#8221; <b>uncheck<\/b> &#8220;Install background guard&#8221; and &#8220;Install scan via context menu&#8221;.<br \/>\n\n\n<li>When you run ewido for the first time, you will get a warning &#8220;Database could not be found!&#8221;.  Click <b>OK<\/b>.  We will fix this in a moment.<br \/>\n\n\n<li>From the main ewido screen, click on <b>update<\/b> in the left menu, then click the <b>Start update<\/b> button.<br \/>\n\n\n<li>After the update finishes (the status bar at the bottom will display &#8220;Update successful&#8221;)<br \/>\n\n\n<li>Exit Ewido.  DO NOT scan yet.<br \/>\n<\/ol>\n\n<br \/>\n\n\n<p>\nDownload <a href=\"http:\/\/www.ccleaner.com\/\">CCleaner<\/a> and install, but do not run it yet.<br \/>\n\n\n<p>\nPlease download the <a href=\"\/download.php?f=nailfix.zip\">Nail\/Aurora Spyware Fix<\/a> from NoIdea.US.<br \/>\n\n\n<p>\nUnzip it to the desktop but do NOT run yet.<br \/>\n\n\n<p>\nReboot into Safe Mode.  To do this with Windows XP, you can follow these steps from <a>Microsoft<\/a>:<br \/>\n\n\n<ol>\n\n\n<li>Restart your computer and start pressing the F8 key on your keyboard. On a computer that is configured for booting to multiple operating systems, you can press the F8 key when you the Boot Menu appears.<br \/>\n\n\n<li>Select an option when the Windows Advanced Options menu appears, and then press ENTER.<br \/>\n\n\n<li>When the Boot menu appears again, and the words &#8220;Safe Mode&#8221; appear in blue at the bottom, select the installation that you want to start, and then press ENTER.<br \/>\n<\/ol>\n\n<br \/>\n\n\n<p>\nOnce in Safe Mode, please double-click on <b>nailfix.cmd<\/b> that you unzipped earlier.  Your desktop and icons will disappear and reappear, and a window should open and close very quickly &#8212; this is normal.<br \/>\n\n\n<p>\nNext, run <b>Ewido<\/b> again.<br \/>\n\n\n<ol>\n\n\n<li>Click on the <b>Scanner<\/b> button in the left menu, then click on the <b>Start<\/b> button.  This scan can take quite a while to run, so time to go get a drink and a snack&#8230;.<br \/>\n\n\n<li>If ewido finds anything, it will pop up a notification.  You can select &#8220;clean&#8221; and check the boxes &#8220;Perform action with all infections&#8221; and &#8220;Create encrypted backup&#8221; before clicking on <b>OK<\/b>.<br \/>\n\n\n<li>When the scan finishes, click on &#8220;Save Report&#8221;.  This will create a text file.  Make sure you know where to find this file again.<br \/>\n<\/ol>\n\n<br \/>\n\n\n<p>\nThen run <b>HijackThis<\/b>, click <b>Scan<\/b>, and place a checkmark by the following item:<br \/>\n\n\n<p>\n<b>F2 &#8211; REG:system.ini: Shell=Explorer.exe C:\\WINDOWS\\Nail.exe<\/b><br \/>\n\n\n<p>\nClose all open windows except for HijackThis and click <b>Fix Checked<\/b>.<br \/>\n\n\n<p>\nNow, run CCleaner.  <br \/>\n\n\n<ol>\n\n\n<li><b>Uncheck<\/b> &#8220;Cookies&#8221; under &#8220;Internet Explorer&#8221;.<br \/>\n\n\n<li><i>if running Firefox:<\/i> then click on the &#8220;Applications&#8221; tab and <b>uncheck<\/b> &#8220;Cookies&#8221; under &#8220;Firefox&#8221;.<br \/>\n\n\n<li>Click on <b>Run Cleaner<\/b> in the lower right-hand corner.  This can take quite a while to run.<br \/>\n<\/ol>\n\n<br \/>\n\n\n<p>\nFinally, restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.]]><\/p>\n","protected":false},"excerpt":{"rendered":"<p>NOTE: These instructions have been superseded with updated procedures for the nailfix installer and a new version of Ewido. Please post a HijackThis Log in the Malware Removal Assistance forum here or at any of the ASAP Member Sites. The following are instructions to run the Nail\/Aurora popups fix. This can be recognized by the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-30","post","type-post","status-publish","format-standard","hentry","category-computers"],"_links":{"self":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/posts\/30","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/comments?post=30"}],"version-history":[{"count":0,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/posts\/30\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/media?parent=30"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/categories?post=30"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.noidea.us\/wordpress\/wp-json\/wp\/v2\/tags?post=30"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}