HKEY_CURRENT_USER\Software\aurora (delete whole section)
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SvcProc (delete whole section)
In the section...
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
...you will see a very obvious value pointing to a file that Aurora has created in %System32%. The value will be...
%System32%\randomname.exe r
randomname is exactly that, but really easy to spot, both times I saw it, it was two different names, both were just 8 random characters long.
in the key...
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
It changes the value of the Shell key from...
Explorer.exe
to
Explorer.exe %WindowsDir%\Nail.exe
All I did here was change it back to Explorer.exe
I haven't had any problems yet with this, so hopefully the above has killed it off for good.
Pixie.
|