Hi Sam ,
Im not sure if this is going to be much help ,Im just
testing a fix on Aurora
(Note** its not the fix im posting here ,this one works
well but im trying a new fix which i will post when its
tested ) ,
Its downloaded a file called poller.exe in its setup and
this poller.exe when scanned by MSAS detects
Trojan.Startup.Nameshifter.BK
Ive always thought this was a different problem but it
may just mean you have Aurora on your system,
For Aurora Use This Fix (Copy it to notepad so you can
still view it in safe mode )
Once in Safe mode Its important you do not reboot untill
you finish all the steps or it will do as you say and
change its name and try do a fresh install !
----------------------------------------------------------
Download Nailfix to your desktop (I've gone back to my
download as the Author's links have gone down)
Nailfix
http://xsorbit26.com/users5/andymanchesta/index.php?
action=dlattach;topic=3719.0;id=303
----------------------------------------------------------
Download The ABI remover (Better Internet Remover)
http://andymanchesta.com/Downloads/ABIremover.zip
Download the Remover to your desktop
----------------------------------------------------------
Download Ewido Security Suite
http://download.ewido.net/ewido-setup.exe
install and get all updates while in normal mode & run in
safe mode
----------------------------------------------------------
Download AD-Aware SE
http://www.download.com/3000-2144-10045910.html
install and get all updates while in normal mode & run in
safe mode
----------------------------------------------------------
Download Ccleaner
http://download.ccleaner.com/download121bino.asp
----------------------------------------------------------
You may need to empty your system restore points,Drpmon &
Bolger.dll is sometimes left in the restore area.To turn
off system restore goto start then right click my
computer then goto properties then system restore.
Check the box 'Turn off system restore' then press apply
and exit
Reboot into Safe Mode by hitting the F8 key repeatedly
until a menu shows up (and choose Safe Mode from the list)
start the ABIRemover.exe, press install, wait (explorer
window will disapear)
in Safe Mode, double-click on nailfix.bat. Your desktop
and icons will disappear and reappear, and a window
should open and close very quickly.
Next run a full scan with Ewido & Ad-aware SE (Ewido will
find the random named files in the system folder and
windows/last good folder if they exist.Ad-aware will
detect and remove DrPmon and Bolger.dll )
Goto start then run and type
prefetch
delete the contents of this folder
Run Ccleaner and remove anything found,also use
the 'issues' button and fix any problems that are
detected.
Reboot & Re-Enable System Restore (Goto start again,then
right click my computer,then choose properties & goto
system restore) Un-check the box 'turn off system
restore' and press apply
Your done !
Let me know if you have any problems
Regards
Andy