| HKEY_CURRENT_USER\Software\aurora (delete whole section)
 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SvcProc (delete whole section)
 In the section...
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 ...you will see a very obvious value pointing to a file that Aurora has created in %System32%. The value will be...
 %System32%\randomname.exe r
 randomname is exactly that, but really easy to spot, both times I saw it, it was two different names, both were just 8 random characters long.
 in the key...
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
 It changes the value of the Shell key from...
 Explorer.exe
 to
 Explorer.exe %WindowsDir%\Nail.exe
 All I did here was change it back to Explorer.exe
 I haven't had any problems yet with this, so hopefully the above has killed it off for good.
 Pixie.
 
 
 |