Google Answers Logo
View Question
 
Q: Remove Aurora Spyware ( No Answer,   8 Comments )
Question  
Subject: Remove Aurora Spyware
Category: Computers > Security
Asked by: owoman-ga
List Price: $5.00
Posted: 03 May 2005 12:40 PDT
Expires: 02 Jun 2005 12:40 PDT
Question ID: 517296
I need help removing this spyware.  I ran hijacthis, following is my log file.
Logfile of HijackThis v1.99.1
Scan saved at 3:32:48 PM, on 5/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe
C:\WINDOWS\System32\umonit.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Lexmark 4200 Series\lxbmbmon.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Virtual Account Numbers\CitiUCS.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
c:\windows\system32\msnbjor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\F1U201.401\usbshare.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Timex\Timex Trainer\TBEggLaunch.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Quicken\bagent.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Adobe\Premiere Pro 1.5\Adobe Premiere Pro.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\Bill\LOCALS~1\Temp\~e5d141.tmp
C:\Program Files\Adobe\Photoshop CS\Photoshop.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\DOCUME~1\Bill\LOCALS~1\Temp\~e5d141.tmp
C:\DOCUME~1\Bill\LOCALS~1\Temp\~e5d141.tmp
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Bill\Local Settings\Temporary Internet
Files\Content.IE5\V3DZZLGS\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.memorylanenc.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.memorylanenc.com/
R3 - URLSearchHook: (no name) - {04079856-5845-4dea-848C-3ECD647AA554}
- C:\Program

Files\MySearch\SrchAstt\1.bin\MYSRCHAS.DLL
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} -
C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: Yahoo! Companion BHO -
{02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!

\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O2 - BHO: MySearch Search Assistant BHO -
{04079851-5845-4dea-848C-3ECD647AA554} - C:\Program

Files\MySearch\SrchAstt\1.bin\MYSRCHAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
- C:\Program Files\Adobe\Acrobat 7.0

\ActiveX\AcroIEHelper.dll
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} -
C:\WINDOWS\Bolger.dll
O2 - BHO: Google Toolbar Helper -
{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} -
C:\Program Files\Norton SystemWorks\Norton

AntiVirus\NavShExt.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile -
{D5233FCD-D258-4903-89B8-FB1568E7413D} -

mscoree.dll (file missing)
O2 - BHO: UCSBrowserHelper Class -
{F1D49A84-8656-43ce-AE3D-AABC1A12243E} -
C:\WINDOWS\system32\BhoUCS.dll
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton
SystemWorks\Norton

AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}
- C:\Program Files\Yahoo!

\Companion\Installs\cpn0\ycomp5_6_0_0.dll
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program 

Files\MySearch\bar\1.bin\S4BAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Lexmark 4200 Series] "C:\Program Files\Lexmark 4200
Series\lxbmbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark
4200 Series\Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\System32\umonit.exe
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air
Utility\AirCFG.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CitiUCS] C:\Program Files\Virtual Account
Numbers\CitiUCS.exe  /dontopenmycards
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program
Files\Common Files\Microsoft Shared\Works

Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program
Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint
Manager\ViewMgr.exe
O4 - HKLM\..\Run: [APL] "C:\Program Files\ACT\ACT for Win 7\APL.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [cxofwvx] c:\windows\system32\msnbjor.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft
ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton
SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-

AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN
Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: F1U201.401.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program
Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common 

Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Timex Trainer Launcher.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box
- C:\PROGRA~1\INCRED~1

\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &ieSpell Options - res://C:\Program
Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Backward Links - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program 

Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Check &Spelling - res://C:\Program
Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MI699F~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program
Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English -
res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
- C:\Program Files\Java\jre1.5.0_02

\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} -
C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell -
{0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program
Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7}
- C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options -
{1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program

Files\ieSpell\iespell.dll
O9 - Extra button: Create Mobile Favorite -
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4

\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}
- C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... -
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1

\MICROS~4\INetRepl.dll
O9 - Extra button: UCS - {4C730923-3961-439b-83D5-F4E445520422} -
C:\Program Files\Virtual Account

Numbers\CitiUCS.exe
O9 - Extra button: Attach Web page to ACT! contact -
{6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file

missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... -
{6F431AC3-364A-478b-BBDB-89C7CE1B18F6} -

mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MI699F~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
- C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}
- C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei-

2/SmileyCentralFWBInitialSetup1.0.0.8-2.cab
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure
Postal Account Registration) -

https://secure.stamps.com/download/us/registration/3_0_0_832/sdcregie.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} - 

http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - 

http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - 

http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - 

http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) - 

http://moneycentral.msn.com/cabs/pmupdate2.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - 

http://www2.verizon.net/update/msnwebinstall/includes/vzWebIns.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - 

https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - 

http://www2.incredimail.com/contents/setup/downloader_sp1/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control
4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - 

http://photos.msn.com/resources/neutral/controls/DigWebX2.cab?10,0,910,0
O23 - Service: Adobe LM Service - Unknown owner - C:\Program
Files\Common Files\Adobe Systems

Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
Corporation - C:\Program Files\Common Files\Symantec

Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec
Corporation - C:\Program Files\Common

Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec
Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program
Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. -
C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner -
C:\Program Files\Common Files\Macromedia

Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) -
Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) -
Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec
Corporation - C:\PROGRA~1\NORTON~1\NORTON~1

\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program
Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec
Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1

\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - C:\Program Files\Common

Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service
(default)) - Analog Devices, Inc. - C:\Program

Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -
C:\Program Files\Common Files\Symantec

Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation -
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: System Startup Service  (SvcProc) - Unknown owner -
C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\CCPD-

LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. -
C:\WINDOWS\system32\Tablet.exe
Answer  
There is no answer at this time.

Comments  
Subject: Re: Remove Aurora Spyware
From: arabianknight-ga on 03 May 2005 15:40 PDT
 
what kind of antispyware program do you use? if you dont have one than
download microsoft anti-spyware. before you run it, make sure it isnt
running on smart scan, scan it on full system scan. and if you have a
C:\ drive as well as a D:\ drive than make sure both of them or
checked for scanning. there is a chance that your anit-spyware program
might be infected as well, so click this link to scan it online, no
downloads required exept for an activex download you need. scan it for
spyware, or you can scan it for the full system scan if you would like
but it will increase the time, select both your c and d drive if you
have 2. and run the scan, it should find it and remove it. if the
problem presists just let me know.
Subject: Re: Remove Aurora Spyware
From: arabianknight-ga on 03 May 2005 15:42 PDT
 
wow i forgot to give you the links, my bad.

download microsoft anti-spyware:
http://www.microsoft.com/downloads/details.aspx?FamilyID=321cd7a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en


trendmicro online scan: http://housecall60.trendmicro.com/en/start_corp.asp?id=scan
Subject: Re: Remove Aurora Spyware
From: owoman-ga on 03 May 2005 16:28 PDT
 
Hi there, run Norton Anti-Virus.  I downloaded ewido security suite
14-day trial.  That seems to have fixed the problem.  If I still have
problems I will downlaod Microsoft AntiSpyware.

thanks
Subject: Re: Remove Aurora Spyware
From: casagozo-ga on 23 May 2005 09:09 PDT
 
Aurora is a malicious adware program that tries to make itself
impossible to remove.

Before fixing the problem, be sure to call the creators at Direct
Revenue, LLC in New York to let them know how you feel about them
causing so much anguish. Their phone number is 646-613-0376, and they
are located at 107 Grand Street, 3rd Floor in Manhattan.

Now for the fix...go to http://www.mypctuneup.com/ and use this uninstaller. 

Hopefully the anti-adware legislation going through Congress will help
put these scum out of business.
Subject: Re: Remove Aurora Spyware
From: rdagollum-ga on 01 Jun 2005 01:54 PDT
 
DO NOT INSTALL mypctuneup!!!

Note that they provide a tool to remove through an affiliate at
MYPCTuneup.com. So if you remove Aurora with MyPCTuneup?. notice that
you agree to allow them to install a web bug on your computer in
exchange for utilizing their uninstall software.(second paragraph of
their privacy policy) Also notice how their privacy policy langauge
dances around to avoid responsibility regarding the collection of
personally identifiable information about children under the age of
13. This strikes me as an incredibly tortured line of logic. As best I
can tell, they take a ?don?t ask don?t tell? position?. if we don?t
ask if you are under 13, we don?t know? therefore, we can?t be held
responsible for distributing information about children under the age
of 13. This is astounding! It would be like saying, since I didn?t
check to see if I had any communicable diseases, I can?t be held
responsbile for infecting anyone else. Seems like a different ethical
code than I would prefer!

?MyPCTuneUp, during the delivery and your use of the Uninstallation
Software(Software), does not collect any personally identifiable
information about you, such as your surname, address, telephone number
or e-mail address, nor does MyPCTuneUp require such information from
you before downloading or installing the Software. However, to enable
MyPCTuneUp provide and operate its Software, MyPCTuneUp collects
certain types of non-personally identifiable information about
individuals who install the Software. This information may include
your Internet protocol (IP) address, your domain, your operating
system, your browser version, type and language and your Internet
Service Provider.

MyPCTuneUp may use invisible tracking or counting devices known as
?web bugs? to register that a particular web page has been viewed
and/or ?cookies? or alphanumeric identifiers that MyPCTuneUp transfers
to your computer?s hard drive through your web browser to enable
MyPCTuneUp?s systems to recognize your web browser.

MyPCTuneUp may share non-personally identifiable aggregate information
about you with third parties.

Children?s Privacy Policy and Use ? The Software is not directed to
children. Because MyPCTuneUp cannot determine with any degree of
certainty whether a child is using a computer at a given time, this
?Children?s Privacy Policy and Use? explains MyPCTuneUp?s practices
regarding the collection and use of personally identifiable and
non-personally identifiable information from children under the age of
thirteen and provides important information regarding your rights
under federal law with respect to such information.

MyPCTuneUp does not knowingly collect personally identifiable
information from children under the age of thirteen. If MyPCTuneUp
becomes aware that it has inadvertently received personally
identifiable information and/or data from a user under the age of
thirteen, MyPCTuneUp will delete such past data from its records and
will cease to collect any new data from that computer, including any
non-personally identifiable data.

Since MyPCTuneUp does not knowingly collect any personally
identifiable information from children under the age of thirteen,
MyPCTuneUp also does not knowingly distribute such information to
third parties. Further, because MyPCTuneUp does not knowingly collect
any personally identifiable information from children under the age of
thirteen, it does not condition the participation in online activities
of a child under thirteen on providing personally identifiable
information.

if yuo want to get rid of this annoying pop up adware, i suggest
downloading 'adware away' to remove it. make sure you update it before
running scans for best results. I've added link where you can get a
copy of this prog from download.com.

http://www.download.com/Adware-Away/3000-8022_4-10382877.html?tag=lst-0-1
Subject: Re: Remove Aurora Spyware
From: askeen01-ga on 16 Jun 2005 20:44 PDT
 
this is for owoman-ga. i noticed that you have aws weather bug and
incredimail on your system. remove them now. they are know spyware and
adware linked programs. if you want the weather check the weather
channel and use gmail because its great. just remember to get rid of
weather bug and incredimail.

check out Spybot SD and Adaware ver 1.06 from download.com both very
good but would suggest buying or atleast trial of Spysweeper from
Webroot.
Subject: Re: Remove Aurora Spyware
From: jaimezamora-ga on 07 Aug 2005 15:22 PDT
 
owoman, use this app to check weather, it's free:

http://tropicdesigns.net/weatherpulse.php

Best,
Jaime
Subject: Re: Remove Aurora Spyware
From: masterofdoom-ga on 27 Aug 2005 20:52 PDT
 
HI owoman-ga ON REMOVING AURORA YOU NEED TO GO TO 
http://computerhelppc.tripod.com THEY HAVE THE UNINSTALLER THERE SEEMS
TO WORK STOPED ALL MY POP-UP

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy