Not another Norton Triumph...
Tuesday, May 24th, 2005 01:40 pmIt appears that simply installing Norton on a PC isn’t enough to get rid of aurora. Neither is using the latest versions of adaware and no-adaware.
So far, other than slowing my machine down quite noticeably, and forcing me to surrender to certain applications’ insistence on net access, because of the constant warning pop-ups that prevent me from doing anything else, I’m not sure that Norton has delivered any benefit.
The next stage in my attempts to get rid of Aurora is to follow this procedure:
Before I do, however, can one of you techie types confirm for me that ‘regedit’ is a windows application hidden away somewhere in XP, or do I have to go elsewhere for it?
Any thoughts welcomed.
So far, other than slowing my machine down quite noticeably, and forcing me to surrender to certain applications’ insistence on net access, because of the constant warning pop-ups that prevent me from doing anything else, I’m not sure that Norton has delivered any benefit.
The next stage in my attempts to get rid of Aurora is to follow this procedure:
1. Start computer in safe mode.
2. search your computer for ceres.dll and delete it.
3. search for buddy.exe and delete it.
4. run a registry editor. I just use the standard regedit
5. search the entire registry for "ceres" but don't delete everything that comes up, only the entries that have "ceres" or "ceresdll" exclusively, so don't delete stuff like TWCEResources (example), they will come up because they have "CERes"
6. Search the entire registry for buddy.exe and delete away.
7. Restart your computer and you should have killed it!
Before I do, however, can one of you techie types confirm for me that ‘regedit’ is a windows application hidden away somewhere in XP, or do I have to go elsewhere for it?
Any thoughts welcomed.
(no subject)
Date: 2005-05-24 12:51 pm (UTC)(no subject)
Date: 2005-05-24 12:52 pm (UTC)Also, when you have deleted ceres.dll and buddy.exe, empty the Recycle bin. (step 3a)
Regedit is indeed a windows app. You get to it by Start -> Run -> type 'regedit'.
(no subject)
Date: 2005-05-24 12:56 pm (UTC)In summary, I would either double check with a real techie or do inordinate anounts of "research" (on the internet forums) to reassure myself before I edited any regsitry keys.
(no subject)
Date: 2005-05-24 01:04 pm (UTC)Read the instructions you've put above. Then open regedit. Then read the instructions again, just to be sure. Then go to it.
if you're nervous...
Date: 2005-05-24 01:10 pm (UTC)NB Make sure you set the export range to All. The export range is at the foot of the Export screen. Don't choose the option 'Selected Branch'
Disclaimer: I am a seat-of-the-pants merchant and have never actually bothered backing up my registry. Anyone know how to re-import the data in the case of cockup? Do you have to be in Safe Mode?
Re: if you're nervous...
Date: 2005-05-24 01:17 pm (UTC)(no subject)
Date: 2005-05-24 01:33 pm (UTC)(no subject)
Date: 2005-05-24 01:40 pm (UTC)There was a Pod online last night pretending to be you, you know.
(no subject)
Date: 2005-05-24 01:52 pm (UTC)(no subject)
Date: 2005-05-24 02:17 pm (UTC)It scans your registry and presents it in an easy to view and edit way (also an easy to edit and destroy your computer as well).
Then post a copy of you log file from Highjack this on the http://forums.spywareinfo.com/ and someone should tell you what to to delete using highjack this. Alternatively search those forums and look for someone with the same problem and follow the advice given.
Then stop using IE and get yourself Firefox so you won't ever have to do this again.
(no subject)
Date: 2005-05-24 02:21 pm (UTC)*pssst*
Date: 2005-05-24 02:24 pm (UTC)(no subject)
Date: 2005-05-24 02:36 pm (UTC)Re: *pssst*
Date: 2005-05-24 02:51 pm (UTC)(no subject)
Date: 2005-05-24 03:02 pm (UTC)Re: *pssst*
Date: 2005-05-24 03:27 pm (UTC)I already have the protective propeller beanie, so I am safe.
(no subject)
Date: 2005-05-24 03:54 pm (UTC)(no subject)
Date: 2005-05-24 07:55 pm (UTC)Those insturctions should do you well.
I can't remember what you posted previously, and sorry if this is teaching you to suck eggs, but make sure that you've got service pack 2 installed, get microsoft antispyware (it's beta but still rather good), avg free (from here) is better than norton, get security task manager from here, that'll list everything that's running and attempt to remove anything you don't like (go easy with it though, it's powerful).
Delete all temp files by doing a disk cleanup then removing windows/temp.
Turn system Restore off. Sounds dangerous but some things hide in there and you can't get them. You can turn it back on once you're clean.
After that you'll still need to go through your registry. Start, Run then type regedit and it'll open. Go easy with this too. Like step 5 says, don't go deleting things willy nilly cos you can fuck everything up.
If you want any help you can mail me on cowjam at cowjam dot co dot uk - I clean machines as part of my job (c:
(no subject)
Date: 2005-05-24 09:15 pm (UTC)It took me two attempts tonight, but so far, I think it's clear. Though when I've finished general faffing around, I'll do the disk clean up thang.
(no subject)
Date: 2005-05-24 09:55 pm (UTC)(no subject)
Date: 2005-05-24 09:58 pm (UTC)No more of them for me.
(no subject)
Date: 2005-05-25 11:18 am (UTC)1. Chuck PC in the trash
2. Buy a Mac :)