It does to me too. From what I can find this is TROJ_AGENT.QET (and this was the most complete info I found which was on the Trend Micro Anti-Virus site so I would go with all this info and removal instructions.The one thing that sticks out is this c:\windows\Temp\startdrv.exe
It is only showing in that one scan in safe mode at 2:36. Which sort of has me puzzled...unless it was removed.
This Trojan spams email messages. Have any folks that you email tell you they have received email from you containing what I would call..."soft porn"..."make yourself feel like the king of the world" among other statements and contains an image which seems to be advertising for a product called eLite Herbal?
Was this scan you pasted the first or the last scan that you ran? If it was the first then I would think that, since this doesn't show in the other, that it has been removed. Though this thing also changes the registry and you will need to make changes to get it out of there.
Rather than post all of those instructions I am posting a link below with very simple to read instructions on how to do this. If you feel comfortable doing this then this is what I would advise.
Once you have completed that then reboot in normal mode, because the edit must be done in safe mode, and run a new HJT scan and we will see if it remains.
These steps require the disabling of System Restore and there are instructions on the link on when and how to do it and be sure to follow those instructions also. Follow the instructions exactly that you find there. I would recommend that you print them out because you must not have internet access while doing this fix.
Here is the link; TROJ_AGENT.QET removal
Now once you reboot after editing the registry you are also supposed to use the HouseCall Online Anti-Virus Scan to complete removal. I would recommend doing this for sure.
AFTER all that then run a new HJT scan and post it here.
Judy


Reply With Quote