Search:  

 
 
   News
newer
Aurora and Nail.exe Infection?
Thank Direct Revenue for your problems
(old news - 06:48PM Thursday May 12 2005)
tags: security · spyware
Spyware vendor Direct Revenue last month launched Aurora, a new piece of scumware their PR department says: "is compliant with the branding and removal standards of all major proposed Federal legislation relating to online contextual ads." Except yeah, whoops, it isn't: it's an absolute monstrosity, and a nightmare to clean up after, as our users will attest. Both Spyware Warrior and VitalSecurity deconstruct this latest internet abomination.

If you've come here via Google looking to get this idiotic software removed, you should first try some decent spyware removal software like Adaware or Spybot (it's best to run both, occasionally). If that doesn't do it, you can find manual removal instructions here. Please consider signing up for a completely free Broadband Reports account and help our community fight Ad/Spy/Malware.

Related:
  1. 180Solutions Still At It
  2. 2006 Windows firewall 'Leak test'
  3. Direct Revenue Exposed
  4. Direct Revenue Exposed
  5. McAfee’s Security Threat Predictions
  6. Win2k Users Annoyed By Defender Snub
  7. BOClean Gets a New Home, Will Be Free
  8. Spyware By Sears
Forums » Aurora and Nail.exe Infection?
view: topics flat text 
Post a:
page: 1 · 2 · 3

Karl Bode
News Guy
join:2000-03-02

And Oh yeah...

If you'd like to call and thank them:

Direct Revenue LLC
107 Grand Street
3rd Floor
New York, NY 10013
V: 646.613.0376
F: 646.613.0386

MysticGogeta
The Robot Devil
Premium
join:2005-03-14
League City, TX
clubs:

Re: And Oh yeah...

Wow thanks give it about 10 seconds and they will be busy i might send a letter for the hell of it, does ad-aware have a patch for it or no?
AquaBlaze
Premium
join:2004-02-02
Encino, CA
Bah, wish they had an 800 number, I'd be more than happy to run up their phone bills with complaints.

Guess I'll have to settle on just running up their bandwidth costs.

dchrsf

join:2003-08-28
Palm Harbor, FL

Re: And Oh yeah...

said by AquaBlaze See Profile:

Bah, wish they had an 800 number, I'd be more than happy to run up their phone bills with complaints.

Guess I'll have to settle on just running up their bandwidth costs.
Can you PM me how to "running up their bandwidth costs"? :D
--
Quotes to live by: "Kill em' all, and let God sort em' out"

novaflare
The Dragon Was Here
Premium
join:2002-01-24
Barberton, OH

Re: And Oh yeah...

said by dchrsf See Profile:

said by AquaBlaze See Profile:

Bah, wish they had an 800 number, I'd be more than happy to run up their phone bills with complaints.

Guess I'll have to settle on just running up their bandwidth costs.
Can you PM me how to "running up their bandwidth costs"? :D
Find their email adress and put it in your forum sigs for all your forums. It be sure to get picked up by spam bots harvesting emails lol
--
DSLR security chat at us.ausirc.net chanel #dslr_sec lets pack this channelopen source dns server for *nix and windows »powerdns.com

RonEl

@triton.edu
Can't someone just set up an endless ping on their website?

How about an email script?

Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse
·RoadRunner Cable
·AT&T Yahoo


edit:
May 12th, @11:03PM

New York based? Go get 'em Elliot Spitzer!!!

Seriously, I think the attorney general's office should
add Direct Revenue to their existing lawsuit against
Intermix. Perhaps maybe even give it class action status.

And then there's this gem from Direct Revenue:

"the Aurora Ad Client is compliant with the branding
and removal standards of all major proposed
Federal legislation relating to online contextual
ads such as HR 2929."

This I guess would be the spyware vendor's equivalent of
a Murk (a bogus disclaimer put into spam messages that
claim they are in compliance with S.1618 or Can-Spam.)
So Rule #1 applies here as well: Spammers
Spyware Vendors Lie.

Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:
·Verizon Online DSL

Host:
Site Tools
FairPoint
World of Warcraft
Alltel Axcess
Verizon Wireless
IS THERE SOMETHING YOU DON'T WANT PEOPLE TO SEE?

Direct Revenue LLC
107 Grand Street
3rd Floor
New York, NY 10013
V: 646.613.0376
F: 646.613.0386

--
I call for a separation of church and idiot. - Lewis Black
What this country needs is a good five dollar plasma weapon.

rit56

join:2000-12-01
New York, NY

Re: And Oh yeah...

huh.. lower Soho, just near the Criminal Court...... on Center Street.

pissed off girl

@comcast.n

Re: And Oh yeah...

LOL..they probably feel more at home there so close to criminal court and/or it's convenience factor hence their asses will be there soon.

TheSaint

join:2002-01-25
Atascadero, CA
clubs:
Just called and left a "nice" little message on their voicemail.
jbeckhamlat

join:2005-05-22
Chicago, IL

RETALIATE!!!!!!!!!!!!!!!!!!!!!! read think, then think like they would think:;)

Direct Revenue CEO Joshua Abram said, "Since the first of the year our new distribution has featured branded ad clients, such as Ceres and Aurora. Now we are updating the installed base, as well, so that our brands are clearly visible throughout our distribution network. Additionally, our easy to use uninstall program will now be featured on all add/remove panels. This complements our proprietary uninstall program, MyPCTuneUp which is designed to remove Direct Revenue software in a simple and effective manner for those who wish to do so."

+++++
DON'T FORGET THE COLLECT CALL, from the wife or son, an operator might put that thru, the are probably packed with temps. CHIEF SCIENTIST?????

apply for a job to the resume email send a large VIDEO CLIP describing your abilities.

++++

Contact Information
Jonathan Cohen
(646) 442-6366
jcohen@direct-revenue.com

so would joshua be
jabram@....?

Please submit resumes with salary history to

resume@direct-revenue.com.

Andrew Pancer, CFO
Alan Murray, COO
Daniel Doman, CTO
Daniel Kaufman, Managing Partner
Rodney Hook, Chief Scientist
Chris Dowhan, VP Distribution
Josh Engroff, VP Client Services
Raffi Minassian, VP Operations

»www.direct-revenue.com/dr_team.php

home > about us > direct revenue management team

Joshua Abram, CEO
Andrew Pancer, CFO
Alan Murray, COO
Daniel Doman, CTO
Daniel Kaufman, Managing Partner
Rodney Hook, Chief Scientist
Chris Dowhan, VP Distribution
Josh Engroff, VP Client Services
Raffi Minassian, VP Operations

Joshua Abram: CEO

As CEO of Direct Revenue, Joshua Abram has been responsible for growing the company's user base by creating and managing the partnerships with providers of free consumer software and content. A veteran marketing entrepreneur, Abram has been a principal in several marketing and product development firms that serve the media, direct marketing and Internet industries. Abram has extensive experience in creating large-scale affinity marketing programs and in developing and launching advertiser-supported alternative media.

Prior to founding Direct Revenue, Abram co-founded Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine) and enabled advertisers to better target their online marketing efforts through software-based advertising. As Executive Vice President of Business Development, Abram led the enlistment of more than 140 leading merchants to participate in the Dash Merchant Alliance and spearheaded Dash's effort to gain distribution to individual users through partnerships with name brand marketers and other free software providers. Abram's successes resulted in distribution agreements with a variety of online marketers including GTE, United Airlines, Priceline.com, TD Waterhouse, Val Pak, AskJeeves and About.com.

top

Andrew Pancer: CFO

As CFO of Direct Revenue, Andrew Pancer leads the company's financial planning and accounting operations. With an M.B.A. from New York University's Stern School of Business and a Bachelor of Science in Business Administration from Washington University, St. Louis, Pancer's background includes more than 10 years of experience in building and directing financial operations within both corporate and entrepreneurial environments. He is also a Certified Public Accountant.

Prior to joining Direct Revenue, Pancer was CFO of About Inc. He was responsible for overseeing the financial operations of About.com, Sprinks and About Web Services. Prior to that he was Controller of ECS, the web development, direct marketing arm of Interactive Corporation. Prior to ECS, Andrew oversaw financial operations, workflow processes, internal control procedures and reporting requirements as Controller of Sterling Development, Inc. He gained initial exposure to finance and accounting through key positions at Ticketmaster, Inc. and KPMG Peat Marwick LLP.

top

Alan Murray: COO

As COO of Direct Revenue, Alan Murray has been responsible for generating revenues from Direct Revenue's user base and directing the company's technology development efforts. With a strong background in management, Murray has overseen internet companies as well as major industrial projects. He received a degree in engineering from the University of Kentucky.

In 1996, Murray founded CommerceInc, which later became Pipe9 Corp. As CEO, Murray oversaw the development of a Web-enabled database system that profiled more than 20 million businesses. Prior to his Internet experience, Murray built his management abilities by directing the design and construction of major industrial projects. From 1985 to 1996, Murray was a senior executive for two of the nation's largest industrial engineering consulting and contracting firms. As executive in charge, Murray was responsible for projects of up to $150 million, including the world's largest stainless steel finishing mill and the world's most advanced lubricant oil manufacturing plant.

top

Daniel Doman: CTO

As CTO of Direct Revenue, Daniel Doman is in charge of all things technical. With over twenty years of experience in technology and management, Doman has a proven track record of profitability in entrepreneurial ventures and a strong background in application, infrastructure design and product management. Doman's extensive technical experience includes "ground up" design and management of web and e-commerce operations and applications as well as integration with legacy systems.

Starting as a systems programmer at Information Builders, Doman became their Director of Programming by helping to develop new versions of their flagship product on a variety of new software and hardware platforms. After Information Builders, Doman joined DoubleClick in its early pre-IPO days, as Director of Engineering. He was involved in all aspects of their development and the evolution into DoubleClick's present status of industry leader.

In 2001, Doman joined Mediaport as CTO and founder. A joint venture founded by a consortium of the big three media buying agencies: Omnicom, Interpublic and WPP Group, Mediaport was founded to create an XML based system that would standardize the buying, selling and tracking of media across all media types. Doman was responsible for developing and modifying both the overall business and financial plan as Mediaport's investors evolved their own vision. Mediaport was successful in mapping out the data and decision points of the media buying process for all media types between all parties by rule and exception. This XML standard has been taken over and continues under the auspices of The American Association of Advertising Agencies.

top

Daniel Kaufman: Managing Partner

As Managing Partner of Direct Revenue, Daniel Kaufman has helped guide corporate strategy and has spearheaded the recent effort to recapitalize the company. A graduate of Williams College, Kaufman is an entrepreneur and established executive.

Prior to co-founding Direct Revenue, Kaufman was CEO of Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine) and enabled advertisers to better target their online marketing efforts through software-based advertising. In 1996, Kaufman founded IvyEssays, which offers internet based editing services and useful tools for college and graduate school applicants. Following the success of Ivy Essays, Kaufman co-authored four books on the admissions process published by Barron's.

In 1993, Kaufman founded a real estate partnership that now owns several hundred apartments in the greater Boston area. In 1992, he founded JIT Consulting, which provided analytical and research services in the telecom, media and computer industries to Gemini Consulting.

top

Rodney Hook: Chief Scientist

Rodney Hook brings extensive experience in relational database design and project management involving large-scale, high-profile applications. He has been a pioneer in the use of the Linux systems to manage extremely large, demanding database applications.

Prior to joining Direct Revenue, Hook oversaw the design and implementation of various 24/7 database-generated web applications for Pipe9. In this role, Hook led the team that built a data collection facility and resources to serve his clients, including American Express, Excite@home, and LookSmart.

Hook has served as the Vice President of Internet Systems for CommerceInc. In this capacity he served as architect for the development and the implementation of an 18 million record data warehouse of all US businesses. Hook oversaw a staff of technology professionals who were responsible for maintaining all aspects of technology operations.

top

Chris Dowhan: VP, Distribution

As VP of Distribution for Direct Revenue, Chris Dowhan is responsible for growing the company's user base by creating and managing the partnerships with providers of free consumer software and content. Dowhan, who has been with DR in different capacities since its inception, leverages a strong technology background to innovate distribution practices.

Prior to Direct Revenue, Dowhan co-founded Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine) and enabled advertisers to better target their online marketing efforts through software-based advertising. As EVP of Technology, Dowhan oversaw all aspects of project management, development, and QA in the Maynard, MA office of 60 employees.

Prior to Dash, Dowhan worked in a web marketing role with client/server tech startup companies, including OneWave in 1997 and Centra Software in 1998. Dowhan was responsible for promoting the software of both companies through online channels.

Along with Direct Revenue's Managing Partner Daniel Kaufman, Dowhan co-authored four books on the admissions process, which were published by Barron's.

top

Josh Engroff: VP, Client Services

As Vice President of Client Services, Josh Engroff manages the company's Account Management, CPA, and Network Analysis teams. Engroff brings 9 years of advertising and technology experience, previously as Client Partner at Agency.com, where he oversaw key accounts with Discovery Networks, Sony, Polo Ralph Lauren, and Honeywell. While there, Josh grew the revenue of the New York office by 50%, oversaw an integrated team of 30 designers, technologists, and project managers, and produced the Discovery Networks Upfront Sales presentation three years in a row.

Prior to Agency.com, Engroff was Senior Account Director at , a boutique agency specializing in Media & Entertainment clients. Engroff managed relationships with Neiman Marcus, Discovery and Sony. Engroff also helped co-found Dash, an Internet software company that simplified online shopping for consumers (named Best Shopping Tool of 1999 by Time Magazine). Engroff holds an M.A. from Princeton University and a B.A. in Economics from the University of Vermont. He is the recipient of Fulbright, Mellon and Truman fellowships.

top

Raffi Minassian: VP, Operations

As VP of Operations, Raffi Minassian is responsible for developing operational policies and expanding Direct Revenue's technical strategy. Most recently a special consultant for the foundation of the VOOM satellite project for Rainbow Media, Minassian brings 20 years of extensive background in technology and a successful history managing operations, technology and process oriented initiatives.

In 2001, Minassian served as Chief Technology Officer for Autolimo, a high caliber communication system that empowers limousine companies to heighten their traditional relationship with clients by providing efficient and effective methods for confirmations and reservations.

Minassian also was VP of Quality Assurance and Release Management at LivePerson, the leading provider of hosted solutions for managing online customer interactions. Prior to joining LivePerson, Minassian served as Director of Quality Assurance for DoubleClick, Inc., a provider of comprehensive Internet advertising solutions for advertisers and Web publishers worldwide.

Minassian holds a Bachelors Degree in Electrical Engineering from the Pratt Institute and a Masters of Computer Science from Long Island University.

mohito
Premium
join:2003-09-29
New York, NY

Re: Direct Revenue /email their staff, deluge their st

Does anyone know if the Daniel Doman, CTO of this is the same one that used to run a BBS a long time ago in NYC? I knew the name was familiar.

One listing is in here, as is my old BBS:
»bbslist.textfiles.com/212/oldschool.html

MSimcox

@qwest.net

Here is a list of most of the files from the Aurora virus (If you don't know what to do with these files, see below)
(If you use windows2000, replace C:\WINDOWS with C:\WINNT)

Main executables:
C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe (main installer)
C:\Documents and Settings\(User Name)\Local Settings\Temp\tp7543.exe (main installer)
C:\WINDOWS\vwzailkubk.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\tdtb.exe
C:\WINDOWS\svcproc.exe
C:\windows\system32\elitealp32.exe
C:\WINDOWS\system32\adlinstallwin32.exe
C:\adlinstallwin32.exe

These are malicious files, but I'm not positive if these are from Aurora. Either way delete them if you have them.
C:\WINDOWS\TASKMAN.exe
C:\WINDOWS\ilaijn.exe
C:\WINDOWS\ieuninst.exe
C:\WINDOWS\Q330994.exe

delete these directories (if they exist):
C:\temporary
c:\windows\browserxtras
C:\WINDOWS\EliteToolBar

main registry directory:
HKCU\Software\aurora

-------------------

The Aurora Virus (yes, it is a virus) is a quite a pest. Many people have tried ridding themselves of it by using antimalware/virus/spyware programs to no avail. The reason for this is because Aurora has a self duplicating, randomly named executable. This file is located in C:\windows\system32 and the name of it is six characters long (example: qwxogr.exe) The solution to this post is as follows.

I'm assuming you are computer literate and know how to use Microsofts's regedit.exe. If not, search this forum on how to use it.
Some files (exes, dlls) can be hidden from regedit.exe. I suggest you use Reglite instead.

Instructions for Aurora removal:

To make this process earier, follow these two steps:

1) Boot to safe mode
1a) Restart you computer
1b) Press the F8 key continuously until the Safe Mode screen appears
1c) Choose: Safe mode, with networking (If you need the references of the internet)

2) Show hidden and system files
Start > MyComputer > Tools Menu > FOlder Options > View Tab
Under the Hidden files and folders heading select Show hidden files and folders
Uncheck the Hide protected operating system files (recommended) option

It is not necessary, but if you wish to disable the annoying popup: "Windows File Protection" (which will appear many times during this process), navitgate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon and modify the key "SFCDisable" from 0 to ffffff9d. If you would like to turn it back on later, just change the value back to 0.

C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe could possibly be the Aurora installer, delete this ASAP. (it could also be in your Temporary Internet Files folder)

Deleting Harmful Files
1) Clear temp dirs (temp AND temp internet files) and cookies

2) Navigate to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run using regedit.exe or reglite (Some of the entries in this directory are required for certain programs to start when Windows starts (example: antivirus) I prefer to have only require Windows files load at startup, so I deleted these registry entries. If you wish to have the programs start when Windows does (which will take up CPU cycles and RAM) leave them there.

It take you a while to figure out which entries are harmful, and which are not. (If you see any random numbers or letters (example: alsh2lhjasl), they are harmful. Some of the malicious processes will be masked with names that look ligitimate such as "rundll32.exe". Under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run there will be some registry keys that are dlls, not exes. If you modify the key, you will see: 1) a mask (example: rundll32.exe) 2) the actual dll name to delete (located in c:\windows\system32)

3) Once you figure out which entries are harmful, right click them, select "modify" to find out where they are located.

4) After locating the files, delete them, then go back and delte the registry entries they were linked to. You must be in safe mode to delete some of the files, however, there is an alternative. Killbox will allow you to delete them in normal mode, but I will not provide instructions.

5) Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. Modify key: "Shell", Remove "C:\WINDOWS\Nail.exe" from "Explorer.exe C:\WINDOWS\Nail.exe" (There is a major vulnerability in windows' registry. Many executables listed in the registry do not contain the full pathname. The registry entry could therefore be point to a "fake" explorer.exe. To fix this change the "Shell" key from: "Explorer.exe" to "C:\WINDOWS\explorer.exe" Now you know for a surety that it points to the right executable.)

The following files are on a reciprocal duplicating system (meaning, when you delete one, the other one recreates it)

C:\WINDOWS\Nail.exe
C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe (main installer)
C:\Documents and Settings\(User Name)\Local Settings\Temp\tp7543.exe (main installer)
C:\WINDOWS\system32\adlinstallwin32.exe
C:\adlinstallwin32.exe

To permanently delete these files, follow these steps:

1) Create new text document and rename it to XXXX.exe or whatever you choose.
2) copy the the name of the file (example: Nail.exe)
3) shift+delete the file
4) Rename xxxx.exe by pasting the text Nail.exe before Nail.exe remakes itself
5) Right click the new Nail.exe and click read only
Leave this file in place, it is not harmful, it contains no code. Confirm this by checking the size of the file. It should be 0 bytes.
Repeat these steps for all five of the reciprocating files.

Delete these directories (if they exist):
C:\temporary
c:\windows\browserxtras

Delete the main Aurora registry directory:
HKCU\Software\aurora

Once you are finished, none of these files or directories should exist:

Files:
C:\Documents and Settings\(User Name)\Local Settings\Temp\toc_0032.exe (main installer)
C:\Documents and Settings\(User Name)\Local Settings\Temp\tp7543.exe (main installer)
C:\WINDOWS\vwzailkubk.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\tdtb.exe
C:\WINDOWS\svcproc.exe
C:\windows\system32\elitealp32.exe
C:\WINDOWS\system32\adlinstallwin32.exe
C:\adlinstallwin32.exe
C:\WINDOWS\TASKMAN.exe
C:\WINDOWS\ilaijn.exe
C:\WINDOWS\ieuninst.exe
C:\WINDOWS\Q330994.exe

Directories:
C:\temporary
c:\windows\browserxtras
C:\WINDOWS\EliteToolBar

Main registry directory:
HKCU\Software\aurora

The file that Windows File Protection keeps saying was replaced was Windows Media Player. If, after you have removed all of the harmful files, WMP doesn't work run the following program:
C:\Program Files\Windows Media Player\setup_wm.exe
If that doesn't update and fix WMP, then go to the Add/Remove Programs list and uninstall WMP. Once you restart your computer WMP should be reinstalled. If not insert your windows cd and install it.

--------
Prevention

Use a secure browser: Firefox or Opera (I actually prefer Opera).
Use Spybot and Ad-aware weekly. Keep the spyware definitions updated!
Use AVG Antivirus weekly. Keep the virus definitions updated!

Teach people who use your computer how to kill popups. (Clicking "yes" on popups will download malware, but so will clicking "no". Teach them to use CTRL+SHIFT+ESC to "end task".)

Further prevention
This is the best guide on prevention: »www.silentrunners.org/sr_disinfection.html

-------
Conclusion

Malware sucks! Hopefully this guide has helped you destroy the crux of your dismay, which is the sadist Aurora.

MSimcox
asatt@hotmail.com

dchrsf

join:2003-08-28
Palm Harbor, FL
They should put this in the FAQ
MikeG0

join:2005-06-15
BS3 5RJ

I got this piece of scum sucking sh*tware on my PC and it screwed up XP - kept getting windows explorer error message. Took an IT company several hours to remove nail.exe, but couldn't fix XP and needed complete reinstall. I am going to send Direct Revenue the bill (not that a company like this would pay it I'm sure). I've lost days of work (luckily no data just time) plus the IT companies fees.

They claim they make it easy to uninstall - then why does it self reproduce itself when you try to get rid of it?? Other programmes unistall no problem what so ever - do they reproduce themselves when you try to uninstall them - course they don't.

I hate pop-ups on the web and can't see the point - I'm surfing the net trying to find something or another and bang...a pop-up advert for something unrelated jumps in my face. I make mental note not to buy that product.

Ban spyware and adware......NO ONE WANTS IT

REFUSE TO BUY PRODUCTS WHO ADVERTISE USING POP-UPS and make this nasty, invasive advertising technique a waste of time for advertisers.

dchrsf

join:2003-08-28
Palm Harbor, FL

Where do you get it?

Not that I want it or anything, but is it jut floating around pr0n sites or somthing? Where can you get it?

If it's on the web, that's another reason I use Firefox..if not, I use it anyways.
--
Quotes to live by: "Kill em' all, and let God sort em' out"

RedXII1234
Premium,Mod
join:2001-02-26
localhost

Re: Where do you get it?

I seriously want to find a malicious URL with the adware/trojan so I can see what happens to a limited user.

DaveNJ
No Fear

join:1999-09-01
New Jersey
·Patriot Media
·Cingular Wireless
·Verizon Online DSL

send them a bill

Someone needs to send a bill to that fax machine for removal of there unwanted garbage. You should also ask if you could borrow there pcs for market research without there permission of course

plk
bo may sleep in loft
Premium
join:2002-04-20
Ogden, IA

class action lawsuit

So why can't we sue these companies?????? This is just a plain crock that this is even allowed. Severe financial penalties should always be a risk for advertisers. Just another example of our govt selling us out.
--
Thermaltake 2000a/Asus P4C-e/p4 3.4/ocz3500 2x512/WD.2x200g/raptor2x74 raid 0/ATI 9600/APC sua 1500/Logitech z-680/ Samsung 213t LCD/MX 1000

TheSaint

join:2002-01-25
Atascadero, CA
clubs:
·Charter Pipeline
·Comcast

Removal?

»www.direct-revenue.com/remove.php

Anyone tried this?

Wonder if it works.

I'm going to call their number with some of my night/weekend minutes and suggest others do likewise if you have cell phones. Let's fill up their voicemail.
--
The only thing necessary for the triumph of evil is for good men to do nothing. --- Edmund Burke
Kill your TV, then Internet Explorer: »www.mozilla.org

some guy

@66.84.x.x

Re: Removal?

to remove it, you have to install "mypctuneup" which is, you guessed it, more spyware

Hank Roberts

@publicisgroupe.com

Re: Removal?

Hey, MyPCTuneUp is not spyware. It does what is says, no gimmicks.

MyPCTuneUp removes Direct Revnue adware applications thoroughly and leaves no residual tracking, profiling or other devices.

MyPCTuneUp does not install any software; it is an uninstall program only. An unobtrusive marker is used to make sure it doesn’t install on the machine again.

MyPCTuneUp notes the computer name as part of the uninstall process, which allows verification that the uninstall has worked properly. It also allows monitoring of distributors that they are re-acquiring previously uninstalled end-users through inappropriate means. Other than that, noting the computer during the uninstall process provides no value to Direct Reevnue -- the company’s software is completely removed.
phqu2

join:2005-07-17
Jacksonville, FL

Re: Removal?

used it and still have nail.exe on my pc.

Listen

@insightBB.com

Well, I tried many different things to remove nail.exe and nothing anyone has said worked......

However, I was just about to say "screw it" and format my C drive (I'm smart enough to store everything important on my slave drive and 2 external drives).

So... I figured i'd just try the mypctuneup.com removal software. Well, it worked like a charm actually. I had to run Ad-Aware SE after I ran the removal tool, reboot and run Ad-Aware SE just once more for further cleanup.

I now have no adware on my PC and the Aurora pop-ups are gone completely. It works.... and no, it's not more adware.
I was actually extremely surprised that it worked myself, but it did. Anyone who doesn't believe me please feel free to continue having the Aurora headache. As for me, my PC is clean now so I have no concerns anymore.

Going through the registry and doing all kinds of key searches and this and that is completely pointless anyways because nothing anyone has posted about removal actually works. As for right now, the mypctuneup.com removal tool is the only thing that works. I'm sure Microsoft will release something (eventually) to remove it. But if you want to delete nail.exe RIGHT NOW... go get the removal tool.

Froh

@t3.se

Re: Removal?

You can remove nail.exe by making a textfile, rename it to nail.exe and make it read-only. Copy it into the windows dir and reboot. After that I was rid of it :P

Hope it works for you also. The Nail.exe is tha malware exe that reproduce it self and makes it impossible to remove aurora key in registry and delete the file nail.exe.

So try this and remove it from registry etc.

Good luck

SpookyCat113

@susc.susc
I've tried MyPCTuneUp and I still have the nail.exe file on my PC. What else can I try to get rid of it??

A person

@comcast.net
I tried that program, and ran hijack this to find that nail.exe was no longer there. I'm going to keep track of things on hijack this for the next few days and see if it comes back again.
Sodusme

join:2005-04-21
Sodus, MI
Dude you are a genius. Oh and kudo's to whoever posted that phone number. I have v.o.i.p so I can call them all day long and all night and fill up that voicemail of theirs for free! HAHAHAHAHA

dbp428

@rr.com

This is the company responsible for Nail in the first place.
it may work but you get more spy ware from them when you install it

see this web site for class action lawsuit against them

»netrn.net/spywareblog/archives/2···-aurora/

Thanatos69

@ntl.com

Re: Removal?

Shiat men!!

I picked up this m-f-ing piece of trash by clicking a dud file in Limewire whilst I was in pursuit of an elusive Keygen / Serial.

This has made my life miserable and I thought I had seen it all!

I threw everything and the kitchen sink at it and it don't die....which is more than I can say for members of Direct Revenue or whatever sh*theel firm they pose themselves by.

If anyone is going after these SOBs I recommend Glocks with .357 SIG hollowpoints. Ouch!

jimmydean4

better yet

send them a few trojans ads and viruses

alg
It's just a shot away
Premium
join:2001-04-10
Austin, TX
clubs:

fax

fax them goatse and tubgirl pics.

Blackhood5
I Escaped Convergys
Premium
join:2002-08-24
Tallahassee, FL
clubs:
·Comcast


edit:
May 12th, @09:22PM

SpySweeper

My brother somehow got this on his computer and I tried removing it by hand by following the steps at this »www.geekstogo.com/forum/The_Auro···893.html forum. Nothing worked and I kept getting tired of trying. Finally, I downloaded the free version of SpySweeper and it took it right out.

Neither Spybot nor Ad-Aware found it as of last weekend.

DaMaGeINC
The Lan Man
Premium
join:2002-06-08
Greenville, SC
clubs:

Why would you waste time trying to clean?

Just format the damn computer. If someone gets on my PC, and DL some crap. I dont even bother to see what I can do. Pop in my Xp CD, and format and install. Take less time doing that than having to try to clean and crap. And still, I wouldent want to use a computer that has been compromised by crapware in the first place.
--
inc.ath.cx
Have a Networking problem or question? Stop by the Networking Forum and let us help you.

qos

join:2003-09-19
Beverly Hills, CA

Re: Why would you waste time trying to clean?

Couldn't agree with you more!! Myself I like to re-image from a fully setup xp image "customized" for my needs...that save's alot of time rather than starting from scratch but nonetheless with a bad case of crapware a fresh OS is best IMO...
alfnoid
Premium,MVM
join:2002-02-18
If you don't go the making an image route try this link:
»www.nliteos.com/nlite.html
It is MUCH faster to do an install with a cd you have made from this.

peace
Indymike

join:2004-12-06
Indianapolis, IN
·Covad Communications

At last ...

.. I know who to blame for this. I spent two days working on a computer that got hit with this thing. Finally had to just wipe the hard-drive and start over. Hopefully, someone will tie it all together and generate a tool that remove this piece of garbage.

And now that I know where to send the bill, I will strongly suggest that to my customer.

I'm not a newbie by any stretch, but this one is NASTY! I'd love for someone to feed this back to this idiot.

TheSaint

join:2002-01-25
Atascadero, CA
clubs:

Re: At last ...

How does this one install itself in the first place? Bundleware? Activex?

djrobx

join:2000-05-31
Valencia, CA

I dealt with an Aurora infected PC this week.

All I can say is, "Compliant with removal standards" my (__|__)! I tried 3 major anti-spyware programs and none could clean it. I got rid of it manually, but geeze what a pain.
--
\\ROB - a part of the SCB local network

Grail Knight
Who Dares Wins
Premium
join:2003-05-31
Erie, PA

Re: I dealt with an Aurora infected PC this week.

So do you wish to share your manual removal notes?

Might come in handy for other users.

weatherman12

join:2001-02-23
Lake Havasu City, AZ

Re: I dealt with an Aurora infected PC this week.

I have run across this crap twice in the past week. After I couldn't remove it by standard means on the first one, I just put the client's hard drive in my computer and scanned it with KAV. It made it much easier to deal with, but still had a lot of junk left. Luckily, the processes show up in Process Explorer from Systernal. I just suspended the processes, then went into HijackThis to remove the startup items. Then I manually deleted the files and upon reboot, all was good. The second computer went a lot faster.
masrotaj

join:2003-07-09
Fort Lauderdale, FL
·Comcast

This little piece of nastiness just cost my customer $200.00 us and that was at a huge discount!!! didn't charge her for 6 hours of labor( so we both lost alot of money) So they owe me as well as her!!! I personally hope there is a painful evil hell so these bastards can take up residence there.
These guys should be sent to prison and hopefully meet up with some not nice relatives of their victims (yes victim is the exact word needed)
MaSrotaj

blacksky

join:2003-02-08
Bonita Springs, FL

Re: I dealt with an Aurora infected PC this week.

Hilarious stuff.... Founded in 2002, DR is backed by Insight Venture Partners. Looks like our former Secretary of the Treasury, Robert Rubin is a special limited partner...

revenge111

@aliant.net

heh

fax them a black piece of paper...should waste their toner quick

blufish

@rr.com

Mobile?

Hmmm doesnt the 646 manhattan area code consist of mobile numbers?

Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

To paraphrase Mark Twain

There are lies, damn lies, and then there are
adware company press releases. Direct Revenue's is
full of it...

Gozu_nz

@net.nz

peice of shit...

i think it installs with activeX, and yes this is the biggest problem i had for awhile. *sigh*
hottub

join:2005-05-15
Atlanta, GA

file a complaint with TRUSTe

go here »https://www.truste.org/pvr.php?page=complaint

file a formal complaint and put Direct Revenue on bad standings. the worst way to attacka a company is to give them a bad reputation with the general public.

Barish

@optonline.net

I fixed this bastard

My mom's computer was infested with spyware, adware, viruses, and everything in between, the whole 9 yards of BS. I was able to get rid of it all fairly simply except for one thing, those damn Aurora ads! After hours of searching and trying new ways to get rid of it, nothing worked. Nail.exe just kept replicating every time I deleted it. But I beat it, oh boy did I beat it. On a whim, I right clicked, and chose "New > Powerpoint Document" onto my desktop (I intended on text file, but clicked PP by accident.) I renamed it to Nail.exe, and replaced the real "Nail.exe" in my Windows folder with it, and I have been problem free. Usually I would refresh after deleting Nail.exe, and it would reappear. After many times refreshing due to unbelief, my dummy Nail.exe was not replaced! I didn't think it would be so simple as to replace it with a dummy file, but hopefully it will continue to work. Aurora free for 3 hours and running!

See 6 replies to this post

wykael

@charter.com

mypctuneup

Well I just ran mypctuneup, restarted, and it was still there, so that's bogus too.

KSTech

@weci.net

Re: mypctuneup

i ran the pctuneup as well, nail is still there.

carp-ware

@cgocable.ca
at least it worked for me.
Bubbles342

join:2005-05-19
San Antonio, TX

Calling DR tech support...

Has anyone tried calling these bastards?

If you have questions about our advertising software please press 4...For installation, general questions, or removal please go to our "support" site at www.mypctuneup.com.

To speak to a technical services representative please press O.

AND THEN IT HANGS UP ON YOU!

Someone should get these a-holes!

A Kittn

@res.rr

dummy file

previous poster saved a dummy file in Nail.exe's place. This is the only thing that has seemed to work for me. I took one of my mousechaser programs and renamed it Nail.exe, so now instead of their stupid adware starting up when explorer starts, I get a cute cat chasing my mouse...

however... whatever keeps changing the registry to explorer.exe C:windows/nail.exe thing will not go away. Even with windows restore and everything else. I suspect it is still sending tracking cookies as well because I changed my internet options to prompt for all cookies, and now I'm getting prompts even when I dont have a browser open. This is complete BS. Whoever fixed it manually, please tell... I seriously don't want to dump my HD because of these jerks. I have a game on there with a 10hour+ update that will have to be downloaded if I fresh install it

Killroyy

@cable.rogers

I think it's gone

The newest version of Spyware Doctor seems to work after using the dummy file. I cleaned aurora from the registry and got rid of the explorer.exe C:\windows\nail.exe entry too. Then I got rid of gokmosqtidb.exe and any other related files including the ones in temp and prefetch folders. Put in a dummy nail.exe and ran Spyware Doctor to get rid of the keyloggers and such, and so far it seems squeaky clean. It's worth a shot. Just remember to shut down system restore beforehand and check msconfig for bad startup exe's before rebooting. I didn't dare remove the dummy file until I was sure it's not coming back.

A kittn

@res.rr

Re: I think it's gone

I got rid of mine too finally, actually-- my husband performed the miracle with the help of a program called xp smoker.

turns out this pos from dr is in fact an activex thing and that must be how it renews itself after you change registry and file settings. xpsmoker allows you to change activex settings and many other settings, so this time when he fixed the registry and deleted nail, it did not come back.

you can get a free trial version of xpsmoker from their website. I'm glad to see people are beating