My computer has several pieces of spyware, including but not limited to "Aurora - part of the ABI Network" I tried to remove Aurora by booting into savemode runing nailfix.exe and scanning with ewido but it still came back. here are the results from my HiJackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 1:27:46 PM, on 7/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\crypse
rv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\Explorer.exe
c:\windows\system32\eaynby
.exe
C:\WINDOWS\system32\userin
it.exe
C:\Program Files\NaviSearch\bin\nls.e
xe
C:\Program Files\CashBack\bin\cashbac
k.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://websearch.drsnsrch.com/sidesearch.cgi?id=R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://websearch.drsnsrch.com/sidesearch.cgi?id=R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.exactsearch.net/sidesearchR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://websearch.drsnsrch.com/sidesearch.cgi?id=R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A
60BD91B74A
9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AuroraHandlerObj Class - {4AA870AC-8427-42a4-B92E-E
CD95619748
9} - C:\WINDOWS\AuroraHandler.d
ll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8
C3E1CE4B34
4} - C:\WINDOWS\System32\nvms.d
ll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-A
B25173A3E1
4} - C:\WINDOWS\System32\mscb.d
ll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-E
D6A80FD66D
A} - C:\WINDOWS\System32\msbe.d
ll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
1B4C16F92E
B} - (no file)
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [crxoniy] c:\windows\system32\eaynby
.exe r
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\MSMSGS.EXE
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = havis.local
O17 - HKLM\Software\..\Telephony
: DomainName = havis.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = havis.local
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = havis.local
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\meconf
.dll
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypse
rv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: OracleOraHome81ClientCache
- Unknown owner - C:\oracle\ora81\BIN\ONRSD.
EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe