Aurora Malware: how to remove it?

I’ve got a particularly nasty bit of malware on my laptop, and I can’t seem to get rid of it.

I’ve run deep scans with updated versions of Spyware Stormer and Ad Aware, and neither can seem to catch this thing. Aurora works by opening popups all over the damn place, asking me to buy certain things and bullshit of that sort. In the proess it slows my computer to a crawl.

I searched the Dope, but there were no hits for “Aurora” and “malware” or “spyware.” I’ve also done some searching via google, and it seems there’s a program called Hijack This which can remove Aurora, but it’s only for advanced users. I know how to word process, email, and play a few video games, I’m certainly no advanced user. Any Dopers got any clues on how to beat this vile lil’ piece of malware? Or if Hijack This is the only way to get rid of it, could anybody explain to me how exactly I can go about doing so?

Thanks for the time and attention!

Google answers recommends this:

http://www.mypctuneup.com/evaluate.php?b=aurora

Excellent! Thank you, that seems to have done it. If you don’t mind me asking, what were your search terms? I ran searches for “aurora spyware” “aurora malware” and “remove aurora” but I didn’t find the program you listed.

Kind of curious about that myself. I recently had a client’s PC infected with Aurora and it was a royal pain in the ass to get it off. The final solution was a multistep process using several different tools as well as some registry hacking. In fact, another engineer who had nothing better to do at the time joined me just to see what it was all about and he was amazed at it’s tenaciousness. Only other one I have seen as bad as Aurora is CoolWeb. Anyway, neither of us in all of our searching came across that tool as a solution and if (as seems suggested) it did the trick in one simple go I am amazed and impressed.

I almost want to find another Aurora infected PC just to check it out.

BTW…make sure NAIL.EXE is gone out of your C:\WINDOWS directory to be 100% sure Aurora is gone. That program seemed to be at the heart of it. Absolutley amazing to see that program re-appear after some pretty harsh attempts at deleting it couldn’t stop it from coming back.

Don’t forget Spybot; run that as well as AdAware. I don’t know if it catches Aurora, but together those two dudes catch pretty much everything.

And:

Using “Aurora malware” (without the quotes) to search in google gives this. Looks pretty comprehensive to me:

http://www.google.com/search?hl=en&q=aurora+malware&btnG=Google+Search

Majorgeeks.com has a good malware forum you might check out in the future.

Trust me…Spybot and AdAware are not sufficient to kill Aurora. The dudes who make these things know that those two programs are popular and program to evade them. I had a CoolWeb one once that would see AdAware run and shut it down (I was kind of impressed despite being pissed off about it).

When I got rid of Aurora I used the tools and procedures you found via Google (exactly that in fact) and it worked but it wasn’t a nice, one-stop, get rid of Aurora thing that the tool mentioned earlier is.

Um… no offence, but I’m pretty sure that ‘mypctuneup’ page is owned by malware creating companies.
My brother had some browser add-on that re-directed the occasional google search to some other engine - when I called their number, they directed me to that place too.

If you search around though, it’s believed that while the mypctuneup tool does remove certain spyware, it installs others. So you may want to check, is all I’m saying. (Though perhaps the trade may be worth it).
Example site

Um… no offence, but I’m pretty sure that ‘mypctuneup’ page is owned by malware creating companies.
My brother had some browser add-on that re-directed the occasional google search to some other engine - when I called their number, they directed me to that place too.

If you search around though, it’s believed that while the mypctuneup tool does remove certain spyware, it installs others. So you may want to check, is all I’m saying. (Though perhaps the trade may be worth it).
Example site

And it’s definately responsible for double-posts.

This guy seems to think mypctuneup.com is malware.

On another page at the same site…

Damn… I missed this therad for a while, thought it died. So you’re saying that the program I just downloaded, even though it said it was installing nothing, still fucked me over… any hints on how to remove that new malware? Ad Aware and Spybot proved innefective against Aurora… will they fare any better against this new one?

Here is a thread at the Spyware Info forum that explains how to remove this pest, including a new tool designed specifically for it.

Here’s the scoop on “mypctuneup”:
http://www.spywarewarrior.com/rogue_anti-spyware.htm#products

Thanks for all the help! Stooooopid malware.