republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Aurora and Nail.exe Infection? » And Oh yeah...
Search Topic:
Uniqs:
1635
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« RE EliteBar  
AuthorAll Replies


Karl Bode
News Guy
join:2000-03-02
And Oh yeah...

If you'd like to call and thank them:

Direct Revenue LLC
107 Grand Street
3rd Floor
New York, NY 10013
V: 646.613.0376
F: 646.613.0386


MysticGogeta
The Robot Devil
Premium
join:2005-03-14
League City, TX
clubs:
Wow thanks give it about 10 seconds and they will be busy i might send a letter for the hell of it, does ad-aware have a patch for it or no?

Thaler
Premium
join:2004-02-02
Encino, CA
reply to Karl Bode
Bah, wish they had an 800 number, I'd be more than happy to run up their phone bills with complaints.

Guess I'll have to settle on just running up their bandwidth costs.


dchrsf
DD

join:2003-08-28
Palm Harbor, FL

said by Thaler See Profile:

Bah, wish they had an 800 number, I'd be more than happy to run up their phone bills with complaints.

Guess I'll have to settle on just running up their bandwidth costs.
Can you PM me how to "running up their bandwidth costs"? :D
--
Quotes to live by: "Kill em' all, and let God sort em' out"


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse


2 edits
reply to Karl Bode
New York based? Go get 'em Elliot Spitzer!!!

Seriously, I think the attorney general's office should
add Direct Revenue to their existing lawsuit against
Intermix. Perhaps maybe even give it class action status.

And then there's this gem from Direct Revenue:

"the Aurora Ad Client is compliant with the branding
and removal standards of all major proposed
Federal legislation relating to online contextual
ads such as HR 2929."

This I guess would be the spyware vendor's equivalent of
a Murk (a bogus disclaimer put into spam messages that
claim they are in compliance with S.1618 or Can-Spam.)
So Rule #1 applies here as well: Spammers
Spyware Vendors Lie.


Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:
·Verizon FIOS
·Verizon Online DSL

Host:
Site Tools
W.O.W.
FairPoint
World of Warcraft
Alltel Axcess
reply to Karl Bode
IS THERE SOMETHING YOU DON'T WANT PEOPLE TO SEE?

Direct Revenue LLC
107 Grand Street
3rd Floor
New York, NY 10013
V: 646.613.0376
F: 646.613.0386

--
I call for a separation of church and idiot. - Lewis Black
What this country needs is a good five dollar plasma weapon.


novaflare
The Dragon Was Here
Premium
join:2002-01-24
Barberton, OH

reply to dchrsf
said by dchrsf See Profile:

said by Thaler See Profile:

Bah, wish they had an 800 number, I'd be more than happy to run up their phone bills with complaints.

Guess I'll have to settle on just running up their bandwidth costs.
Can you PM me how to "running up their bandwidth costs"? :D
Find their email adress and put it in your forum sigs for all your forums. It be sure to get picked up by spam bots harvesting emails lol
--
DSLR security chat at us.ausirc.net chanel #dslr_sec lets pack this channelopen source dns server for *nix and windows »powerdns.com


rit56

join:2000-12-01
New York, NY
reply to Mike
huh.. lower Soho, just near the Criminal Court...... on Center Street.


TheSaint

join:2002-01-25
Hanover Park, IL
clubs:
reply to Karl Bode
Just called and left a "nice" little message on their voicemail.


RonEl

@triton.edu
reply to dchrsf
Can't someone just set up an endless ping on their website?

How about an email script?

jbeckhamlat

join:2005-05-22
Chicago, IL

reply to Karl Bode
Direct Revenue /email their staff, deluge their st

RETALIATE!!!!!!!!!!!!!!!!!!!!!! read think, then think like they would think:;)

Direct Revenue CEO Joshua Abram said, "Since the first of the year our new distribution has featured branded ad clients, such as Ceres and Aurora. Now we are updating the installed base, as well, so that our brands are clearly visible throughout our distribution network. Additionally, our easy to use uninstall program will now be featured on all add/remove panels. This complements our proprietary uninstall program, MyPCTuneUp which is designed to remove Direct Revenue software in a simple and effective manner for those who wish to do so."

+++++
DON'T FORGET THE COLLECT CALL, from the wife or son, an operator might put that thru, the are probably packed with temps. CHIEF SCIENTIST?????

apply for a job to the resume email send a large VIDEO CLIP describing your abilities.

++++

Contact Information
Jonathan Cohen
(646) 442-6366
jcohen@direct-revenue.com

so would joshua be
jabram@....?

Please submit resumes with salary history to

resume@direct-revenue.com.

Andrew Pancer, CFO
Alan Murray, COO
Daniel Doman, CTO
Daniel Kaufman, Managing Partner
Rodney Hook, Chief Scientist
Chris Dowhan, VP Distribution
Josh Engroff, VP Client Services
Raffi Minassian, VP Operations

»www.direct-revenue.com/dr_team.php

home > about us > direct revenue management team

Joshua Abram, CEO
Andrew Pancer, CFO
Alan Murray, COO
Daniel Doman, CTO
Daniel Kaufman, Managing Partner
Rodney Hook, Chief Scientist
Chris Dowhan, VP Distribution
Josh Engroff, VP Client Services
Raffi Minassian, VP Operations

Joshua Abram: CEO

As CEO of Direct Revenue, Joshua Abram has been responsible for growing the company's user base by creating and managing the partnerships with providers of free consumer software and content. A veteran marketing entrepreneur, Abram has been a principal in several marketing and product development firms that serve the media, direct marketing and Internet industries. Abram has extensive experience in creating large-scale affinity marketing programs and in developing and launching advertiser-supported alternative media.

Prior to founding Direct Revenue, Abram co-founded Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine) and enabled advertisers to better target their online marketing efforts through software-based advertising. As Executive Vice President of Business Development, Abram led the enlistment of more than 140 leading merchants to participate in the Dash Merchant Alliance and spearheaded Dash's effort to gain distribution to individual users through partnerships with name brand marketers and other free software providers. Abram's successes resulted in distribution agreements with a variety of online marketers including GTE, United Airlines, Priceline.com, TD Waterhouse, Val Pak, AskJeeves and About.com.

top

Andrew Pancer: CFO

As CFO of Direct Revenue, Andrew Pancer leads the company's financial planning and accounting operations. With an M.B.A. from New York University's Stern School of Business and a Bachelor of Science in Business Administration from Washington University, St. Louis, Pancer's background includes more than 10 years of experience in building and directing financial operations within both corporate and entrepreneurial environments. He is also a Certified Public Accountant.

Prior to joining Direct Revenue, Pancer was CFO of About Inc. He was responsible for overseeing the financial operations of About.com, Sprinks and About Web Services. Prior to that he was Controller of ECS, the web development, direct marketing arm of Interactive Corporation. Prior to ECS, Andrew oversaw financial operations, workflow processes, internal control procedures and reporting requirements as Controller of Sterling Development, Inc. He gained initial exposure to finance and accounting through key positions at Ticketmaster, Inc. and KPMG Peat Marwick LLP.

top

Alan Murray: COO

As COO of Direct Revenue, Alan Murray has been responsible for generating revenues from Direct Revenue's user base and directing the company's technology development efforts. With a strong background in management, Murray has overseen internet companies as well as major industrial projects. He received a degree in engineering from the University of Kentucky.

In 1996, Murray founded CommerceInc, which later became Pipe9 Corp. As CEO, Murray oversaw the development of a Web-enabled database system that profiled more than 20 million businesses. Prior to his Internet experience, Murray built his management abilities by directing the design and construction of major industrial projects. From 1985 to 1996, Murray was a senior executive for two of the nation's largest industrial engineering consulting and contracting firms. As executive in charge, Murray was responsible for projects of up to $150 million, including the world's largest stainless steel finishing mill and the world's most advanced lubricant oil manufacturing plant.

top

Daniel Doman: CTO

As CTO of Direct Revenue, Daniel Doman is in charge of all things technical. With over twenty years of experience in technology and management, Doman has a proven track record of profitability in entrepreneurial ventures and a strong background in application, infrastructure design and product management. Doman's extensive technical experience includes "ground up" design and management of web and e-commerce operations and applications as well as integration with legacy systems.

Starting as a systems programmer at Information Builders, Doman became their Director of Programming by helping to develop new versions of their flagship product on a variety of new software and hardware platforms. After Information Builders, Doman joined DoubleClick in its early pre-IPO days, as Director of Engineering. He was involved in all aspects of their development and the evolution into DoubleClick's present status of industry leader.

In 2001, Doman joined Mediaport as CTO and founder. A joint venture founded by a consortium of the big three media buying agencies: Omnicom, Interpublic and WPP Group, Mediaport was founded to create an XML based system that would standardize the buying, selling and tracking of media across all media types. Doman was responsible for developing and modifying both the overall business and financial plan as Mediaport's investors evolved their own vision. Mediaport was successful in mapping out the data and decision points of the media buying process for all media types between all parties by rule and exception. This XML standard has been taken over and continues under the auspices of The American Association of Advertising Agencies.

top

Daniel Kaufman: Managing Partner

As Managing Partner of Direct Revenue, Daniel Kaufman has helped guide corporate strategy and has spearheaded the recent effort to recapitalize the company. A graduate of Williams College, Kaufman is an entrepreneur and established executive.

Prior to co-founding Direct Revenue, Kaufman was CEO of Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine) and enabled advertisers to better target their online marketing efforts through software-based advertising. In 1996, Kaufman founded IvyEssays, which offers internet based editing services and useful tools for college and graduate school applicants. Following the success of Ivy Essays, Kaufman co-authored four books on the admissions process published by Barron's.

In 1993, Kaufman founded a real estate partnership that now owns several hundred apartments in the greater Boston area. In 1992, he founded JIT Consulting, which provided analytical and research services in the telecom, media and computer industries to Gemini Consulting.

top

Rodney Hook: Chief Scientist

Rodney Hook brings extensive experience in relational database design and project management involving large-scale, high-profile applications. He has been a pioneer in the use of the Linux systems to manage extremely large, demanding database applications.

Prior to joining Direct Revenue, Hook oversaw the design and implementation of various 24/7 database-generated web applications for Pipe9. In this role, Hook led the team that built a data collection facility and resources to serve his clients, including American Express, Excite@home, and LookSmart.

Hook has served as the Vice President of Internet Systems for CommerceInc. In this capacity he served as architect for the development and the implementation of an 18 million record data warehouse of all US businesses. Hook oversaw a staff of technology professionals who were responsible for maintaining all aspects of technology operations.

top

Chris Dowhan: VP, Distribution

As VP of Distribution for Direct Revenue, Chris Dowhan is responsible for growing the company's user base by creating and managing the partnerships with providers of free consumer software and content. Dowhan, who has been with DR in different capacities since its inception, leverages a strong technology background to innovate distribution practices.

Prior to Direct Revenue, Dowhan co-founded Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine) and enabled advertisers to better target their online marketing efforts through software-based advertising. As EVP of Technology, Dowhan oversaw all aspects of project management, development, and QA in the Maynard, MA office of 60 employees.

Prior to Dash, Dowhan worked in a web marketing role with client/server tech startup companies, including OneWave in 1997 and Centra Software in 1998. Dowhan was responsible for promoting the software of both companies through online channels.

Along with Direct Revenue's Managing Partner Daniel Kaufman, Dowhan co-authored four books on the admissions process, which were published by Barron's.

top

Josh Engroff: VP, Client Services

As Vice President of Client Services, Josh Engroff manages the company's Account Management, CPA, and Network Analysis teams. Engroff brings 9 years of advertising and technology experience, previously as Client Partner at Agency.com, where he oversaw key accounts with Discovery Networks, Sony, Polo Ralph Lauren, and Honeywell. While there, Josh grew the revenue of the New York office by 50%, oversaw an integrated team of 30 designers, technologists, and project managers, and produced the Discovery Networks Upfront Sales presentation three years in a row.

Prior to Agency.com, Engroff was Senior Account Director at , a boutique agency specializing in Media & Entertainment clients. Engroff managed relationships with Neiman Marcus, Discovery and Sony. Engroff also helped co-found Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine). Engroff holds an M.A. from Princeton University and a B.A. in Economics from the University of Vermont. He is the recipient of Fulbright, Mellon and Truman fellowships.

top

Raffi Minassian: VP, Operations

As VP of Operations, Raffi Minassian is responsible for developing operational policies and expanding Direct Revenue's technical strategy. Most recently a special consultant for the foundation of the VOOM satellite project for Rainbow Media, Minassian brings 20 years of extensive background in technology and a successful history managing operations, technology and process oriented initiatives.

In 2001, Minassian served as Chief Technology Officer for Autolimo, a high caliber communication system that empowers limousine companies to heighten their traditional relationship with clients by providing efficient and effective methods for confirmations and reservations.

Minassian also was VP of Quality Assurance and Release Management at LivePerson, the leading provider of hosted solutions for managing online customer interactions. Prior to joining LivePerson, Minassian served as Director of Quality Assurance for DoubleClick, Inc., a provider of comprehensive Internet advertising solutions for advertisers and Web publishers worldwide.

Minassian holds a Bachelors Degree in Electrical Engineering from the Pratt Institute and a Masters of Computer Science from Long Island University.


pissed off girl

@comcast.n
reply to rit56
Re: And Oh yeah...

LOL..they probably feel more at home there so close to criminal court and/or it's convenience factor hence their asses will be there soon.


MSimcox

@qwest.net

reply to Karl Bode
Aurora Removal

Here is a list of most of the files from the Aurora virus (If you don't know what to do with these files, see below)
(If you use windows2000, replace C:\WINDOWS with C:\WINNT)

Main executables:
C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe (main installer)
C:\Documents and Settings\(User Name)\Local Settings\Temp\tp7543.exe (main installer)
C:\WINDOWS\vwzailkubk.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\tdtb.exe
C:\WINDOWS\svcproc.exe
C:\windows\system32\elitealp32.exe
C:\WINDOWS\system32\adlinstallwin32.exe
C:\adlinstallwin32.exe

These are malicious files, but I'm not positive if these are from Aurora. Either way delete them if you have them.
C:\WINDOWS\TASKMAN.exe
C:\WINDOWS\ilaijn.exe
C:\WINDOWS\ieuninst.exe
C:\WINDOWS\Q330994.exe

delete these directories (if they exist):
C:\temporary
c:\windows\browserxtras
C:\WINDOWS\EliteToolBar

main registry directory:
HKCU\Software\aurora

-------------------

The Aurora Virus (yes, it is a virus) is a quite a pest. Many people have tried ridding themselves of it by using antimalware/virus/spyware programs to no avail. The reason for this is because Aurora has a self duplicating, randomly named executable. This file is located in C:\windows\system32 and the name of it is six characters long (example: qwxogr.exe) The solution to this post is as follows.

I'm assuming you are computer literate and know how to use Microsofts's regedit.exe. If not, search this forum on how to use it.
Some files (exes, dlls) can be hidden from regedit.exe. I suggest you use Reglite instead.

Instructions for Aurora removal:

To make this process earier, follow these two steps:

1) Boot to safe mode
1a) Restart you computer
1b) Press the F8 key continuously until the Safe Mode screen appears
1c) Choose: Safe mode, with networking (If you need the references of the internet)

2) Show hidden and system files
Start > MyComputer > Tools Menu > FOlder Options > View Tab
Under the Hidden files and folders heading select Show hidden files and folders
Uncheck the Hide protected operating system files (recommended) option

It is not necessary, but if you wish to disable the annoying popup: "Windows File Protection" (which will appear many times during this process), navitgate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and modify the key "SFCDisable" from 0 to ffffff9d. If you would like to turn it back on later, just change the value back to 0.

C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe could possibly be the Aurora installer, delete this ASAP. (it could also be in your Temporary Internet Files folder)

Deleting Harmful Files
1) Clear temp dirs (temp AND temp internet files) and cookies

2) Navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run using regedit.exe or reglite (Some of the entries in this directory are required for certain programs to start when Windows starts (example: antivirus) I prefer to have only require Windows files load at startup, so I deleted these registry entries. If you wish to have the programs start when Windows does (which will take up CPU cycles and RAM) leave them there.

It take you a while to figure out which entries are harmful, and which are not. (If you see any random numbers or letters (example: alsh2lhjasl), they are harmful. Some of the malicious processes will be masked with names that look ligitimate such as "rundll32.exe". Under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run there will be some registry keys that are dlls, not exes. If you modify the key, you will see: 1) a mask (example: rundll32.exe) 2) the actual dll name to delete (located in c:\windows\system32)

3) Once you figure out which entries are harmful, right click them, select "modify" to find out where they are located.

4) After locating the files, delete them, then go back and delte the registry entries they were linked to. You must be in safe mode to delete some of the files, however, there is an alternative. Killbox will allow you to delete them in normal mode, but I will not provide instructions.

5) Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. Modify key: "Shell", Remove "C:\WINDOWS\Nail.exe" from "Explorer.exe C:\WINDOWS\Nail.exe" (There is a major vulnerability in windows' registry. Many executables listed in the registry do not contain the full pathname. The registry entry could therefore be point to a "fake" explorer.exe. To fix this change the "Shell" key from: "Explorer.exe" to "C:\WINDOWS\explorer.exe" Now you know for a surety that it points to the right executable.)

The following files are on a reciprocal duplicating system (meaning, when you delete one, the other one recreates it)

C:\WINDOWS\Nail.exe
C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe (main installer)
C:\Documents and Settings\(User Name)\Local Settings\Temp\tp7543.exe (main installer)
C:\WINDOWS\system32\adlinstallwin32.exe
C:\adlinstallwin32.exe

To permanently delete these files, follow these steps:

1) Create new text document and rename it to XXXX.exe or whatever you choose.
2) copy the the name of the file (example: Nail.exe)
3) shift+delete the file
4) Rename xxxx.exe by pasting the text Nail.exe before Nail.exe remakes itself
5) Right click the new Nail.exe and click read only
Leave this file in place, it is not harmful, it contains no code. Confirm this by checking the size of the file. It should be 0 bytes.
Repeat these steps for all five of the reciprocating files.

Delete these directories (if they exist):
C:\temporary
c:\windows\browserxtras

Delete the main Aurora registry directory:
HKCU\Software\aurora

Once you are finished, none of these files or directories should exist:

Files:
C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe (main installer)
C:\Documents and Settings\(User Name)\Local Settings\Temp\tp7543.exe (main installer)
C:\WINDOWS\vwzailkubk.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\tdtb.exe
C:\WINDOWS\svcproc.exe
C:\windows\system32\elitealp32.exe
C:\WINDOWS\system32\adlinstallwin32.exe
C:\adlinstallwin32.exe
C:\WINDOWS\TASKMAN.exe
C:\WINDOWS\ilaijn.exe
C:\WINDOWS\ieuninst.exe
C:\WINDOWS\Q330994.exe

Directories:
C:\temporary
c:\windows\browserxtras
C:\WINDOWS\EliteToolBar

Main registry directory:
HKCU\Software\aurora

The file that Windows File Protection keeps saying was replaced was Windows Media Player. If, after you have removed all of the harmful files, WMP doesn't work run the following program:
C:\Program Files\Windows Media Player\setup_wm.exe
If that doesn't update and fix WMP, then go to the Add/Remove Programs list and uninstall WMP. Once you restart your computer WMP should be reinstalled. If not insert your windows cd and install it.

--------
Prevention

Use a secure browser: Firefox or Opera (I actually prefer Opera).
Use Spybot and Ad-aware weekly. Keep the spyware definitions updated!
Use AVG Antivirus weekly. Keep the virus definitions updated!

Teach people who use your computer how to kill popups. (Clicking "yes" on popups will download malware, but so will clicking "no". Teach them to use CTRL+SHIFT+ESC to "end task".)

Further prevention
This is the best guide on prevention: »www.silentrunners.org/sr_disinfection.html

-------
Conclusion

Malware sucks! Hopefully this guide has helped you destroy the crux of your dismay, which is the sadist Aurora.

MSimcox
asatt@hotmail.com


dchrsf
DD

join:2003-08-28
Palm Harbor, FL
reply to Karl Bode
Re: And Oh yeah...

They should put this in the FAQ

MikeG0

join:2005-06-15
BS3 5RJ

reply to Karl Bode
I got this piece of scum sucking sh*tware on my PC and it screwed up XP - kept getting windows explorer error message. Took an IT company several hours to remove nail.exe, but couldn't fix XP and needed complete reinstall. I am going to send Direct Revenue the bill (not that a company like this would pay it I'm sure). I've lost days of work (luckily no data just time) plus the IT companies fees.

They claim they make it easy to uninstall - then why does it self reproduce itself when you try to get rid of it?? Other programmes unistall no problem what so ever - do they reproduce themselves when you try to uninstall them - course they don't.

I hate pop-ups on the web and can't see the point - I'm surfing the net trying to find something or another and bang...a pop-up advert for something unrelated jumps in my face. I make mental note not to buy that product.

Ban spyware and adware......NO ONE WANTS IT

REFUSE TO BUY PRODUCTS WHO ADVERTISE USING POP-UPS and make this nasty, invasive advertising technique a waste of time for advertisers.


mohito
Premium
join:2003-09-29
New York, NY

reply to jbeckhamlat
Re: Direct Revenue /email their staff, deluge their st

Does anyone know if the Daniel Doman, CTO of this is the same one that used to run a BBS a long time ago in NYC? I knew the name was familiar.

One listing is in here, as is my old BBS:
»bbslist.textfiles.com/212/oldschool.html
Forums » Aurora and Nail.exe Infection?« RE EliteBar  


Wednesday, 02-Dec 00:00:19 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [133] Comcast Releasing Promised Usage Meter
· [67] Baltimore To Ban Lazy Cable Installs
· [56] Broadband Killed The Game Console
· [50] Latest Consumer Reports Survey Not Kind To AT&T
· [49] Rogers Unveils The ISP Dream Model
· [40] Rural Carriers Quickly Embracing Fiber
· [35] Charter Exits Chapter 11
· [35] ACTA: Global Three Strikes
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [24] Midcontinent Socked With Easement Lawsuit
Most people now reading
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Download speeds very slow. [AT&T West]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Furnace starts, then shuts off. [Home Repair & Improvement]
· Options if ACTA is ratified [TekSavvy]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]