callinghome.biz

  • Thread starter Thread starter JRivet
  • Start date Start date
Hi J

Its safe to say you are infected by BetterInternet in
some way but its hard to know exactly what at this stage.

When I tested some of BetterInternet files recently I got
the following detections :

Duad.exe = Trojan.Win32.Agent.ay /CallingHome.Biz.A

Poller.exe = Trojan.StartupNameshifterBK/Adw.CallingHome

So its something from BetterInternet but I cannot help
more at this stage as there could be alot more files
involved than this, Clearing Temp files and Prefecch
files would help and Using scanners such as Ewido as they
also remove alot of these files, If it was Aurora you
would notice straight away because of repeated Pop-ups
when you use IE but you don't mention that so Its hard to
know what you have without seeing a Hijack This log.

Maybe try Ewido and MSAS & Ccleaner in safe mode and see
if they can then remove the problem if not use Hijack
This and seek advise from the experts to make it easier
for you to fix.You can post the log on many sites, here's
acouple of the main ones ( Tomcoyote & SpywareInfo ) but
there is more that can help you with this if you check
some of the search engines.

Reply here if you need help with anything

Regards Andy
 
Noticed a spelling mistake on prefetch in my first reply
so wanted to repost to correct it,

Clear temp and 'Prefetch' files after using the scanners
in safe mode.

To clear Temp files

Goto start menu then run and type

%temp%

delete the contents of that folder

Goto Control Panel then Internet Options

On the page that opens press Delete files and include all
offline content


To Clear Prefetch files Goto start run and type

prefetch

Then delete the contents of that folder,

Andy
 
Back
Top