Well, I got this same thing too... I was on limewire and downloaded some file with the name "keygen" in it. I work at a computer shop, so i know what I'm doing, and have McAfee, SpySweeper, Adaware, SpyBot, SpySubtrack, CWS, and XoftSpy; all of which have current updates.
Upon running this file called keygen, nothing happened, so i double clicked again... still nothing. So I scanned that directory for viruses. Nothing. Use all of the above software to scan for adware/spyware. Nothing. Preformed a full system scan using each one of the above pieces of software. Still nothing except a few cookies SpySweeper wanted to delete.
I had the same randomly named .EXE file in my task list, and every time I ended it, it was renamed and restarted... no matter how fast I tried to delete the file before it got renamed, I just couldn’t do it. I also found out that "Nail.exe", "pohoignlfyy.exe", and "svcproc.exe" were related to this, so I went into safe mode and deleted everything I could find. I also cleaned out the registry where it said the shell was "Explorer.EXE nail.exe" and everything else that people have mentioned before this post.
Well, tonight, at a friend's house, I noticed that same darn aurora thing on his CPU when he opens mozilla. So now I'm back... I wanna figure this out! I've been getting random lockups, and I just reinstalled windows on here a couple weeks ago...although the lockups could be related to my cooling... 2 days ago, my room was 90 degrees because the AC doesn’t work upstairs and because of the pollen, I could not open the Window, so my Athlon XP 2600+ was running at about 56-60 degrees C.
Next, I sent those files (Nail.exe", "pohoignlfyy.exe", and "svcproc.exe") and the randomly named file in the system32 folder to COMPUTER ASSOCIATES for analysis. I got an email back from some guy telling me it was related to VX2 transponder, another site told me it was related to ABetterInternet. Computer Associates also told me "The file has been identified as Win32.SillyDl.LR trojan. Aliases reported by other Antivirus products are listed here: (Trojan.Win32.Agent.cp) (BackDoor-CQQ) (Trojan Horse)"
After submitting it to McAfee's AVERT Labs in Tokyo, they told me: "These files are being considered for inclusion in our potentially unwanted program (PUP) definition files. If the sample meets our PUP criteria, detection and removal will be supported in a future DAT release for qualifying products I also got the idea from somewhere that this was related to something called "Buddy" virus.... don't remember where I got that info from...
About a week ago, SpySweeper came up and told be that it detected "ABetterInternet" running--this was like right after I had updated definitions from SpySweeper... After doing a full scan, SpySweeper removed it. I then downloaded the plug-in for Adaware (it think it was called VX2) and some other VX2 fix tool from Symantec and ran those, which found nothing. I thought that maybe I had gotten rid of it, but as I was using Adobe Premiere yesterday, I noticed the Aurora in the taskbar... I’m thinking that if you have a fast computer, you will see that task bar less, because it comes and goes so fast. But since my CPU was bogged down converting video, I was able to see that task bar icon for a good 10 seconds.
Anyways, I just did another REGEDIT and deleted some folder named "aurora"
Now I'm stuck... there's really nothing left I can think of to do... The file with the random name is no longer running in the task manager, and all of the "svchost" are either "SYSTEM", "LOCAL SERVICE", or "NETWORK SERVICE"... none with my user name, like a regular program would have... BUT, I still see this aurora sometimes... I'm not getting any pop-ups, although come to think of it, I did get one popup a couple of seconds after I click that original "keygen" file when I opened internet explorer, but none after then...
I have not tried the uninstall link that was provided because those usually contain more crap and are fake... PLUS, the person who was told to try it seems to be having the trouble still...as you can tell by his response with that eBay scam that popped up.
Anyways, just wondering if anyone had any other insight to this nasty thing... I might just give up for once and reformat again, since I just reformatted a couple weeks ago!
Talk to ya later,
Andrew Bucklin
Manager of Technical Service, MicroHelp, Inc.