what is Win32:Trojano-191 [Trj]?

G

Guest

I keep getting this warning from my AV prog ( Avast) each time I turn on IE6. I delete it and then it pops up again and I delete it and then I'm ok...for awhile.

I have run spy spy sweeper and run (and eliminated) "supposed" virues...but I keep getting this AV warning when I use IE6.

I need some help here. I can find a virus definition for Win32:Trojano-191 [Trj]
Which sometimes reads Win32:Trojano-180 [Trj] or Win32:Trojano-201 [Trj].

My AV prog says its in the C:/windows/system32/flmao.dll.
So I delete that and then I get another warning that says the virus is in c:/windows/system32/crih32.exe or some other "xxxx".exe file.

The first location is always the same and (ie flmao.dll) but the subsequent ones vary. Its like the first one must be generating the others. I can't permanently delete that sucker!

All advise is welcomed.
 
K

Kelly Cotter

mackchi said:
I keep getting this warning from my AV prog ( Avast) each time I turn
on IE6. I delete it and then it pops up again and I delete it and
then I'm ok...for awhile.

I have run spy spy sweeper and run (and eliminated) "supposed"
virues...but I keep getting this AV warning when I use IE6.

I need some help here. I can find a virus definition for
Win32:Trojano-191 [Trj]
Which sometimes reads Win32:Trojano-180 [Trj] or Win32:Trojano-201
[Trj].

My AV prog says its in the C:/windows/system32/flmao.dll.
So I delete that and then I get another warning that says the virus
is in c:/windows/system32/crih32.exe or some other "xxxx".exe file.

The first location is always the same and (ie flmao.dll) but the
subsequent ones vary. Its like the first one must be generating the
others. I can't permanently delete that sucker!

All advise is welcomed.

1st of all i'd download and run these
http://www.lavasoftusa.com/software/adaware/ adaware

http://www.safer-networking.org/index.php?page=download spybot

http://www.safer-networking.org/index.php?page=download cwshredder
also do a full virus scan
 
J

Jan Il

Hi mackchi :)

It is likely you have parasites, spyware, adware, malware, or hijackware on
your system causing the problem, which your antivirus will not detect, as it
does not have the same definitions.

Try this and see if it helps.

Tools > Internet Options > Advanced > Browsing
Uncheck the Enable 3rd party browser extensions

Then do the following to clean the cause from your system:

Download and install, then you *MUST* update the programs prior to running
to be sure they have the latest definitions, then run the programs below.
They are free and very effective. Be sure to run both SpyBot and Adaware,
as what one does not detect the other may. It is important that you do all
the steps and follow all directions carefully:

IMPORTANT:
Before trying to remove spyware using the programs below, download a copy of
LSPFIX from the URL below - some malware may kill your internet connection
when it is removed, this program will enable you to regain your connection.
http://www.cexx.org/lspfix.htm

Also get a copy of WINSOCKFIX available at:
http://www.spychecker.com/program/winsockxpfix.html

It is important that you run the programs in the order that they are listed
here. The first three programs will clear your machine of all other items so
that you can have a clear HiJackThis Log for the experts to read and analyze
for you.

(NOTE: If you can not download these programs from the Internet, if your PC
has CD read capabilities, go to another computer with CD-ROM burning
capabilities. Create a folder on the hard drive of the other computer called
HOLD, download the programs to that folder, then burn that folder to a CD.
Copy the HOLD folder to your HD and then install the programs from there
and run them. After you have IE access again, update all programs where
possible to get the latest definitions and run them again to be sure there
are no lingering items on the system.

CWShredder: Free
http://tinyurl.com/2l9kl

SpyBot Search & Destroy: Free
http://download.com.com/3000-8022-10289035.html?tag=lst-0-2

AdAware: Free
http://www.lavasoftusa.com/support/download/

HiJackThis: - Free

Go to
http://computercops.biz/downloads-cat-14.html ,
or
http://www.aumha.org/a/parasite.php#hjt
and download HiJackThis. Unzip to a folder other than your Desktop or the
Temp folder, doubleclick HiJackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log"
button. Press that, save the log some place you remember where it is.
Most of what it lists will be harmless or even required, so DO NOT fix
anything yet.

Open the copy of your log in NotePad and make a copy. Then you can go here
to post you log:

Jim Eshelman's site here:
AumHa Forums - HiJackThis section:
http://forum.aumha.org/

Spyware and Hijackware Removal Support, here:
http://216.180.233.162/~swicom/forums/

or Net-Integration here:
http://www.net-integration.net/cgi-...86d536d57b5f65b6e40c55365e;act=ST;f=27;t=6949

or Tom Coyote here: http://forums.tomcoyote.org/index.php?act=idx

<<DO NOT POST YOUR LOG FILE TO THIS NEWSGROUP>>

You will need to register to open a new thread to post you log. It is free,
and no one will Spam you, it is one of many that provides this service. Once
registered, go to the HiJackThis section on the forum list and click to
open. Then start a new post and post your log. The experts there will
analyze the log and report back the results. Please allow at least a few
hours or a days time for a response, depending on when you post the log

Remember, you must return to the HJT site to get your answer. It is a good
idea to click the "Notify" box so that you will get an electronic
notification by e-mail to let you know when a response has been posted.
But, you must still return to the site of your answer

HJT Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42


Hope this helps.

Jan :)

Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
I keep getting this warning from my AV prog ( Avast) each time I turn
on IE6. I delete it and then it pops up again and I delete it and
then I'm ok...for awhile.

I have run spy spy sweeper and run (and eliminated) "supposed"
virues...but I keep getting this AV warning when I use IE6.

I need some help here. I can find a virus definition for
Win32:Trojano-191 [Trj]
Which sometimes reads Win32:Trojano-180 [Trj] or Win32:Trojano-201
[Trj].

My AV prog says its in the C:/windows/system32/flmao.dll.
So I delete that and then I get another warning that says the virus
is in c:/windows/system32/crih32.exe or some other "xxxx".exe file.

The first location is always the same and (ie flmao.dll) but the
subsequent ones vary. Its like the first one must be generating the
others. I can't permanently delete that sucker!

All advise is welcomed.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top