﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / Security News and Software Updates &amp; Definitions  / How to ID &amp; Avoid Aurora Pop-ups/Nail.exe Infection / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Thu, 20 Nov 2008 03:39:52 GMT</lastBuildDate><ttl>20</ttl><item><title>How to ID &amp; Avoid Aurora Pop-ups/Nail.exe Infection</title><link>http://forum.tweaks.com/forum/Topic161369-59-1.aspx</link><description>One of Transponder's newer variants includes a &lt;FONT color=#3333dd&gt;replacement to their buddy.exe called&lt;/FONT&gt; &lt;FONT color=#3333dd&gt;&lt;STRONG&gt;Bolger.dll&lt;/STRONG&gt;&lt;/FONT&gt; and &lt;STRONG&gt;&lt;FONT color=#3333dd&gt;Aurora.exe&lt;/FONT&gt;&lt;/STRONG&gt;.  This is a nasty infection that has been up showing up everywhere in HijackThis logs around the security forum community. As such I have provided some information about this .dll and its related files to promote awareness and help avoid infection.&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#3333dd&gt;Aurora comes from Direct Revenue LLC: aka Offeroptimizer and Abetterinternet.com&lt;/FONT&gt;&lt;/STRONG&gt;. &lt;/P&gt;&lt;P&gt;Variant: Bolger.dll  &lt;BR&gt;File Name: Bolger.dll  &lt;BR&gt;CLSID: {302A3240-4805-4a34-97D7-1645A0B08410} &lt;BR&gt;Size: 172032&lt;BR&gt;Version: 0.12.4.96&lt;BR&gt;CRC-32: C8D089EF&lt;BR&gt;MD5: 67DA1E869864F3B17DBD66E58A3D29C5&lt;BR&gt;File version: 0, 12, 4, 96&lt;BR&gt;Company name: Bolger&lt;BR&gt;Internal name: bolger&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Components include&lt;/STRONG&gt;: &lt;FONT color=#3333dd&gt;Aurora.exe, &lt;STRONG&gt;svcproc.exe&lt;/STRONG&gt;, Poller.exe, uacupg.exe, &lt;STRONG&gt;Nail.exe&lt;/STRONG&gt;, DrPMon.dll, thnall1ac.html&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;- Svcproc.exe is the service which does not like to be stopped. &lt;/P&gt;&lt;P&gt;- Aurora.exe is their replacement to their buddy.exe that was created by the ceres.dll and speer.dll files.&lt;/P&gt;&lt;P&gt;- Thnall1ac.html is actually their thnall1ac.exe that does the registry registering of the bolger.dll when the thnall1ac.html is called.&lt;/P&gt;&lt;P&gt;- Nail.exe is the main reinfestational agent that generates a random named *.exe file around 74kb in the %windows% %system% folder. &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.webhelper4u.com/index.html"&gt;Webhelper4U&lt;/A&gt; has this posted on their site:&lt;/P&gt;&lt;P&gt;[quote]The Bolger.dll is foisted with exploits from the CWS loadcash.biz out of crackz.ws from the isearch bundled installer.  Like the ceres.dll with the buddy.exe, some of their offeroptimizer ads are still peddling Spyspotter software that their own popup ads act like adware types.  For Info on Spyspotter - see Eric Howes Rogue/Anti-spyware pages. &lt;/P&gt;&lt;P&gt;Below is the bolger.dll -Aurora.exe ad window: &lt;/P&gt;&lt;P&gt;"Spyware or Adware may be installed on your computer. If you are experiencing frequent computer crashes, unwanted or incessant pop-up ads or slower speeds your system may have been infected with Spyware or Adware. Click 'OK' to scan your PC."[/quote]&lt;/P&gt;&lt;P&gt;As stated on the Rogue/Anti-spyware list, false positives work as goad to purchase some anti-spyware software and others are installed via adware drive-by-downloads. &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#3333dd&gt;Rule of Thumb&lt;/FONT&gt;&lt;/STRONG&gt;: Pay attention to pop ups and be careful of what you click. &lt;FONT color=#dd3333&gt;&lt;STRONG&gt;Sometimes even clicking anywhere in the body of a message will redirect to a link or start a download without your knowledge - phishers use this a lot.&lt;/STRONG&gt;&lt;/FONT&gt; &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#3333dd&gt;WHAT TO DO IF YOU GET INFECTED&lt;/FONT&gt;&lt;/STRONG&gt;: &lt;/P&gt;&lt;P&gt;Please read and follow all instructions provided in the sticky at the top of the Hijack This Forum titled "&lt;STRONG&gt;&lt;FONT color=#3333dd&gt;READ BEFORE POSTING HIJACK THIS LOGS&lt;/FONT&gt;&lt;/STRONG&gt;" found &lt;A href="http://forum.tweakxp.com/forum/Topic4303-29-1.aspx"&gt;here&lt;/A&gt;. &lt;/P&gt;&lt;P&gt;When you have done that, follow the instructions for posting a log into the &lt;A href="http://forum.tweakxp.com/forum/Forum29-1.aspx"&gt;Hijack This Forum &lt;/A&gt;[not here] for evaluation.</description><pubDate>Fri, 13 May 2005 09:50:56 GMT</pubDate><dc:creator>quietman7</dc:creator></item></channel></rss>