Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help,Don't know what to do


  • Please log in to reply
2 replies to this topic

#1 bdma9481

bdma9481

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:30 PM

Posted 27 June 2005 - 04:18 PM

my husband's laptop keeps acting up and we don't know what to do. We have mcafee anti-virus, but we keep getting these messages about these virus:

thnall
aurora
drpmon
nail

We cleaned and deleted these virus several times but they come up again about 5 mins. later.
I've tried to download some adware and spyware software but everytime I try to download the browser takes me to www.adsourcecorp.com with a Http404 error
We also get these icons on our desktop and in our windows folder. I don't know what to do please HELP...

BC AdBot (Login to Remove)

 


#2 Rarehunter

Rarehunter

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Local time:09:30 PM

Posted 27 June 2005 - 04:47 PM

Here's some info I found about your problem

Filename: Nail.exe

Description: This infection is a Abetterinternet adware variant. It is notoriously difficult to remove and is usually bundled with other malware that are hard to remove as well. One method that we have found that is able to remove this infection and the other malware that are bundled with it is the ewido security suite which you can download and try for free.
File Location: %WinDir%
Startup Type: If you are running Windows 95/98/ME, this startup entry is being started via the Shell= line in the Windows\system.ini file.

If you are running Windows NT/XP/2000/2003, this startup entry is being started via the Shell= line in the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Note: %Windir% refers to the Windows installation folder. By default, this is C:\Windows for Windows 95/98/ME/XP or C:\Winnt for Windows NT/2000.

This infection is also related to the other infection aurora.

Run and install this software to remove it. Ewido

I didn't find any info about the other infections, sorry.

If I helped you, please send me a personal message.
Rarehunter

#3 Enthusiast

Enthusiast

  • Members
  • 5,898 posts
  • OFFLINE
  •  
  • Location:Florida, USA
  • Local time:09:30 PM

Posted 27 June 2005 - 08:16 PM

If the above isn't a total cure then it's time you followed the instructions here for Hijack This and post a Hijack This log in the proper part of this forum.

How to get help here using Hijack This and get a team memberís assistance:

http://www.bleepingcomputer.com/forums/How...s_Log-t956.html




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users