3 Apprentice

 • 

8.8K Posts

June 7th, 2005 15:00

In order to get rid of the Aurora problem correctly you need to post a HiJackThis log in that forum and have someone look it over and try to fix this problem.

Normal anti-Spyware programs won't get rid of this for you.

Here are some things to do prior to posting the log.

Let's start from scratch and see what we come up with?

To begin with, pick 2 of these online scans and run them and see what they find. Let me know the results.
eTrust AntiVirus Web Scanner

Panda ActiveScan
Trend Micro
.

After that could you please go here and download AdAwareSE and delete what it finds. Then go here here and download its VX2 cleaner. Run it and delete what it finds.
After that go here and download SpyBot and run it. When Spybot is complete, it will be showing RED entries, BLACK entries, and GREEN entries in the window. Put a check mark beside the RED entries ONLY. Choose Fix Selected Problems and allow Spybot to fix the RED only entries.
Now go to here and download HiJackThis to its own folder that you create on your C:\ drive.
After it is downloaded open the program and click Scan and Save to log.

Post the log that it generate in the HJT forum..


Steve

167 Posts

June 7th, 2005 22:00

 

Message Edited by MACHADO458 on 07-16-200611:08 PM

34 Posts

June 9th, 2005 01:00

Hello guys,

I am having same trouble with Aurora, could you please take a look at my post in HijackThis forum. I tried your suggested methods but Aurora is there! Please help me.

http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=6175

167 Posts

June 9th, 2005 01:00

 

Message Edited by MACHADO458 on 07-16-200611:08 PM

21 Posts

June 10th, 2005 15:00

If these randomly generated files are still being found in your Hijackthis scans, then I would download processexplorer and autoruns from www.sysinternals.com. Do scans in safe mode and look for any un-named, authorless .dll's and .exe's. Kill these processes in processexplorer and un-check and delete these files from startup in autoruns. Then do another scan with Hijackthis. Also use ADSspy in the Misc. tools section of HJT to detect  the presence of alternate data streams. 

34 Posts

June 11th, 2005 13:00

Thank u guys.

I feel the system is clean now. Thanks a lot for your efforts.

3 Apprentice

 • 

8.8K Posts

June 12th, 2005 14:00

Machado,
You have threads you started in the HJT forum that are either incomplete or just plain wrong.

If you would take the time to read your PM's you would see what I am talking about.

I have cleaned up dozens of systems that are infected with Nail.exe and have a fix that is made just for that infection. It IS NOT difficult to remove, just takes a bit of time and knowledge.

Steve

Message Edited by zbestwun2001 on 06-12-2005 08:25 AM

No Events found!

Top