Aurora / "A Better Internet" / VX2 / Transponder - How to Eliminate???

I

Ian

Hello Everyone,

My friend's computer is infected with spyware called "A Better Internet",
which is apparently also known as "Aurora", "VX2" or "Transponder".

I have spent several fruitless hours trying to remove this spyware, both
manually and using Norton Antivirus 2005, Lavasoft Ad-Aware 1.06 and a
program called Webroot Spy Sweeper 4.0. Lavasoft even has a special
"add-in" component called "VX2 Cleaner" that specifically targets this
spyware and even it is unsuccessful.

I find that this spyware is purely diabolical in its ability to evade
termination/deletion - none of these programs came anywhere close to getting
rid of it. When you terminate the program from Windows XP task manager, it
immediately restarts under two new program names.

Doing some research, I have found that you can actually go to the spyware
creator's website - www.abetterinternet.com - and that they offer an
uninstall program (as opposed to instructions for deleting the spyware). I
read in a previous post that someone had tried using the uninstall program
but that it didn't work for him. Being that these people have been so
sleazy / diabolical in how they make the spyware so resilient, I have severe
concerns about running their supposed uninstall program for fear that it
will do unknown things on my friend's computer (e.g. install something else
in addition to the subject spyware, etc.), and so I would only use it as an
absolute last resort.

My questions:

1. Does MSAS have the ability to get rid of "A Better Internet"? Reading
past posts in this newsgroup, I don't think it can (at the moment). Can it?

2. I found an earlier post that referred to a file called NAILFIX.BAT.
Unfortunately the two websites given as sources for this file don't work for
me. Can someone provide a correct location for obtaining the file?

3. Is there any good source of information on this particular spyware?
Searches I've done so far haven't been particularly successful.

Thanks in advance for all your help...
 
A

Alien

Dear Ian
ok well all ready posted lots about this infection. well
what you said is true most of the spyware removers cant
take this infection away and yes MS anti-spyware cant take
it away at the moment the best way that i found to detect
and remove this infection is by using a program called Ewido..

what follows is an answer that i gave another user some
time ago to help her remover this infection
-----------
lots of people say u need to install nail.exe but i didnt
do it because i dnt like the whole reboot in safe mode i
thought that there was an esayer way and well i found it..
if you download this program
http://www.ewido.net/en/download/
Ewido is a very good spyware and other bug remover its only
a 30 day trial but it should do just fine for you.. just
install it and download the updates and then scan.. it took
my aurora.exe off and all the other infections that came
with this.

if this scan doesnt work ten you can download the nail.exe
http://www.noidea.us/easyfile/file.php?dow...050515010747824

after u downloaded the nail.exe then just follow these steps
download Nailfix.exe
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the
following:
1) Restart your computer
2) After hearing your computer beep once during startup,
but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the
following site:
http://www.pchell.com/support/safemode.shtml



Once in Safe Mode, please double-click on Nailfix.cmd. Your
desktop and icons will disappear and reappear, and a window
should open and close very quickly --- this is normal.

Then please run Ewido, and run a full scan. Save the
logfile from the scan.

-----

well i mean from what you understood you dont relly need to
use nail.exe but if you want you can.

i hope i helped you
Alien
 
A

Alan

Once you have removed ABetterInternet, go to
c:\widows\prefetch and shred any files whose filenames
contain abetterinternet. This will keep the infection
from coming back.

Alan
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top