We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Strange messages started apearing - please help
Options
Comments
-
Spybots official site http://www.safer!networking.org/
Click on the English link.
Sounds like you have beed re!directed.:doh: Blue text on this forum usually signifies hyperlinks, so click on them!..:wall:0 -
Chenge the exclamation mark to a hyphen in my link above!!!!!:doh: Blue text on this forum usually signifies hyperlinks, so click on them!..:wall:0
-
angus1 wrote:Am a bit confused. I went in to spybotsearch and destroy and downloaded it but it took me to spyware doctor which did a scan, found 620 things wrong but I had to pay to fix it. I didn't do this, but if I did it was in dollars anyway.
Is this right ! I thought it was free to download spybot?
Thanks
That's a ripoff site (Spyware Doctor) ! they trick you into thinking you need to pay. (They also tell everyone that they have problems even when they are clean)
Spy Bot is very good and it's free
Microsoft also do an Antispyware program ! Google Microsoft Antispyware if you want to install it.0 -
Ever get the feeling you are wasting your time? :rolleyes:0
-
there is a full step by step guide to removing this sort of stuff here on the forum
http://forums.moneysavingexpert.com/showthread.html?t=133269
includes links to all the software you need and how to use itEx forum ambassador
Long term forum member0 -
Hi,
Not sure if you have resolved this problem yet, but if I remember correctly the aurora file relates to abetterinternet.com. If you look them up they do provide a removal tool, which by the way was the only one to work(I tried EVERYTHING), however you will need to use it in safe mode with an internet connection. I was a bit nervous at first as I do not like to disable my filewall for anything but it will remove it completely but it is alot of hassle. I spent god knows how many hours trying to remove that spyware(I'm not really sure that it what that is though!) Hope you can remove it completely!0 -
Thanks everyone for your suggestions. I've spent all day going through Browntoa's step by step instructions on the sticky as suggested and although it got rid of loads of stuff I still have the really bad ones left. I've posted a separate thread with the log file as the last stage of the sticky suggests, having used HijackThis - hope someone can have a look at it and advse.
I'll also try the website Kerry suggests. Thanks again - will let you know how I get on - better go now - goggle eyed having sat here all day trying to fix the bloomin thing.(Angus is my dog, not me ...)0 -
Hello Angus
Please use copy & paste to add your HJT log to this thread. Someone will look at it and give advice.
That nail/Auroroa thing you mentioned at the start can be awkward to remove but, with HJT, it should be easy to spot (a) if it's still on your PC and/or (b) if there are any "left overs" from an earlier incomplete removal.0 -
I had to post it in 2 parts - too big for one thread. Thanks for the help
Logfile of HijackThis v1.99.1
Scan saved at 00:20:06, on 04/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe(Angus is my dog, not me ...)0 -
Hi again
The HJT log shows you don't just have "leftovers" from a previous aurora/nail infection - you have the full blown version.
You also have at least two random trojan downloaders and other infections such as eplovy, Vundo/Winfixer, About:Blank/CoolWebSearch, a "ActivShop/e-zshopper" adware variant and the MyWebSearch parasite.
In your first post you said this PC is only a few months old. It wouldn't be a Dell would it? I ask because new Dells come pre-packaged from the factory with spyware already installed. Not the ones you have but it won't help.
You also say you have followed the advice in this thread (it's been mentioned twice so far in this thread)...
http://forums.moneysavingexpert.com/showthread.html?t=133269
....but, judging by this log, I don't think you have. Some things are missing.
As to fixing all this you have two options.
Either you can save all your documents somewhere else then do a complete reformat and reinstall all programs & documents OR we can go the hard way.
If you want to try and avoid the reformat then first do this.
I suggest you print this out to help you when working your way through this initial fix.
1. Update your copy of Ewido to the latest definitions and scan your whole system with it. There is a fix in Ewido for your Aurora/nail problem. I don't know why you still have that infection if you have aldready scanned with Ewido.
Post the Ewido scan report to this thread.
2. Next CoolWebSearch/About:Blank.
Go to this site .....
http://housecall.trendmicro.com/
You will see two free scans offered. Do the second one first .... the CWShredder scan. Hit the "Fix" button at the bottom of the scan window.
3. Now do the other scan ... and make sure Housecall does a full system scan.
It will fix some things but not others.
Post full details of anything it won't fix.
4. Download Ad-aware SE here…
http://www.lavasoftusa.com/
Install it if you don't have it already. Make sure it's the newest version and check for any updates before running it.
……. & VX2 Cleaner…….
Go here… http://www.lavasoftusa.com/ to get the plug-in for fixing VX2 variants. To run this tool choose Software > Add-ons (left navigation bar) then select VX2 Cleaner.
Follow the instructions to run it. If your system is clean it will say “Status System Clean”. Otherwise, you will have to click on the Clean button to remove the VX2 infection.
Also make sure to customize the settings in Ad-aware for better scan results by reading the article here…
http://www.greyknight17.com/spyware.htm#adware
Run the scan and fix everything that it finds.
When finished please post back here the following (there will be more work to do)....
Ewido scan report
Housecall details of unfixed items
new HJT log
and MOST IMPORTANTLY let us know how the computer is behaving now..0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.1K Banking & Borrowing
- 253.2K Reduce Debt & Boost Income
- 453.6K Spending & Discounts
- 244.1K Work, Benefits & Business
- 599.1K Mortgages, Homes & Bills
- 177K Life & Family
- 257.5K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards