Do you have any information as to what this file/program is: C:\WINDOWS\svcproc.exe ??? Nail.exe: Follow the EXACT steps, please: Go to >[color=black]this website[/color]< A download will begin automatically. This is one of the real nasty ones. It is just a tutorial on HijackThis.

In the worse case, Antivirus Software could identify all those pointers as infected, and then remove all of them, then I'd have nothing. Any kind of insight on how to remove these menaces would be greatly appreciated.Oh and I forgot to add I followed the directions on the post regarding where to get help C:\WINDOWS\system32\hqarlqh.exe <--- its very possible that this random named process may have renamed itself by now.

No, create an account now. It does not do any cleanup. Yes! Edited by Andy_veal, 10 May 2005 - 10:43 AM. 0 #5 bobbywilson Posted 11 May 2005 - 03:27 AM bobbywilson Banned Banned 20 posts Advice EditedThanks for your suggestion, though some

  2. Then click yes.
  Was your question answered?

I was updated to the latest as this was the first time I even installed ad-aware and checked that to begin with. Will I have to go onto all five screens on my machine and repeat the cleansing process to fully get rid of this bug? 0 dlh6213 27 11 Years Ago Hi Now run Ccleaner (installed while running the READ ME FIRST). Then skip step 3. 3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel),

Attached Files: log file 4.log File size: 10.3 KB Views: 2 simonrana, Sep 25, 2005 #15 chaslang MajorGeeks Admin - Master Malware Expert Staff Member You must have something installed that Save the logfile from the scan. I am an XFINITY Forum Expert and I am here to help.To learn more about XFINITY Forum Expert program click here.I am an XFINITY Forum Expert and I am here to My main goal:I do not want to run antivirus software and then find out that I cannot retrieve all of the external HDD files afterwards.

chaslang, Sep 26, 2005 #18 elmarice Private E-2 simonrana said: Correction - it's activities have now become apparent, it's another pop up one! I restarted in normal and it was gone there too. See if you can find the new one if it has renamed. Andrei M [blue]Microsoft Certified Professional[/blue]BullGuard | support[at]bullguard[dot]com---------If more than 24hrs have passed since my last reply on your thread, send me a private message to remind me.--------- Quote Report Back to

Again sorry... Then please run Ewido, and run a full scan. Right click on that file and choose Install. If not, skip to step 3. 2) Now right click on your desktop Internet Explorer icon and select Properties.

REGEDIT4 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bsto-1]Click to expand... Thanks alot for all your help! To do this with Windows XP, you can follow these steps from Microsoft: Restart your computer and start pressing the F8 key on your keyboard. We will fix this in a moment.

Here's the logfile- Logfile of HijackThis v1.99.1 Scan saved at 6:10:57 PM, on 4/13/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe I rebooted in Safe Mode, ran HJT and simply removed it with HJT. So from now on, do not reboot or shutdown after posting any logs. Log in or Sign up PCMech Community Forum Home Forums > Help & Discussion > Online Security > can't get rid of nail.exe/aurora...hijackthis log Discussion in 'Online Security' started by mojo3120,

mojo3120, May 26, 2005 #4 rjfvillarosa Moderator Staff Member Joined: Sep 15, 2004 Messages: 7,766 Location: Cardiff, Wales. This option can be changed when choosing your scan type.Select "Perform Full System Scan" and press "Next". You not only want to prevent losing files, you also want to ensure you don't reinfect your computer.

You will also see it in the O4 lines below.

Anyway, here is my Hijackthis log file: Logfile of HijackThis v1.99.1 Scan saved at 9:55:19 AM, on 6/26/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe I ran HJT one more time, and that one hasn't come back yet (fingers crossed) What exactly is this infection supposed to do? Almost all of the files on my two HDDs became camouflaged by 1kb pointers (but underlying the ,ink pointers are the real files). Do NOT run a scan yet.

this is the problem..... Using one of the canned speeches from Bootcamp? Nicki Nikdawn, May 31, 2005 #15 hobey19 usual suspect Joined: Jun 26, 2002 Messages: 2,051 Location: not here when you log in in safe mode, are you logging in as So I am not quick to jump.

Let's try the below steps to remove Nail.exe - Click Start > Run and type: cmd and then click OK! When it is done, it will show the results of the scan. Please run another HJT log, in the normal mode, and post it. Start here.

You will know you are at the end when you see the "Summary of this scan" information has been posted. If any requested files cannot be deleted, run Pocket Killbox and paste the full file path in the box and click on Delete on Reboot. The situation is further complicated in that this is a family machine and each family member has his/her own sign on screen, with its own startup menu. chaslang, Sep 21, 2005 #7 simonrana Private E-2 Sorry.

Shadow_Puter_Dude, Nov 6, 2005 #21 (You must log in or sign up to reply here.) Show Ignored Content Share This Page Your name or email address: Do you already have an Run TDS full scan/AVG full scan/Ad-aware full scan (and SpyBot if you have it).I managed to get rid of some die hard trojan/spyware crud using this method, give it a try Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\rtneg3.dll O3 - Toolbar: Yahoo! Please look into how I can be sure not to lose files before I start.

But what about fonts? Just go back to the link I gave you. Go to:- Start > Run > Type services.msc and click enter Scroll down and find the service called "System Startup Service" When you find it, double-click on it. fix the entry with hijackthis, and then still in safemode, run killbox and delete the file,as you did with the others.