HKEY_CURRENT_USER\Software\aurora (delete whole section) 
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SvcProc (delete whole section) 
In the section... 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run 
...you will see a very obvious value pointing to a file that Aurora has created in %System32%. The value will be... 
%System32%\randomname.exe r 
randomname is exactly that, but really easy to spot, both times I saw it, it was two different names, both were just 8 random characters long. 
in the key... 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon 
It changes the value of the Shell key from... 
Explorer.exe 
to 
Explorer.exe %WindowsDir%\Nail.exe 
All I did here was change it back to Explorer.exe 
I haven't had any problems yet with this, so hopefully the above has killed it off for good. 
Pixie.
 
  |