Hi again,

As expected, both trojans ‘Trojano-169 [Trj]’ and ‘Win32:Dialui-B [Trj]’ reapeared today on my PC as if yesterday i did nothing! ;D

But thanks to our friend ‘whocares’ (#11) I know that ‘plugin1.exe’ is not a normal windows file. And since it runs at startup, I was almost sure that it has to be the cause of that glorious return of trojans above. >:( So I followed the following steps:
1- In Spybot S&D (Advanced mode) → Tools → System Startup , I unchecked any entry that has ‘C:\Windows\plugin1.exe’.
2- I reboot to safe mode.
3- I moved ‘C:\Windows\plugin1.exe’ (might be deleted). I also moved another similar one ‘C:\Windows\plugin4.exe’. :wink:
4- I deleted, as an extra precaution, the “Temporary Internet files”.
5- Then I disabled the “Virtual memory” as explained in reply #12 above.
6- I rebooted to safe mode once again.
7- I run Avast (in Simple User Interface mode) and chose ‘Schedule Boot-time Scan’ from its menu.
8- I set “Area to scan” at “Scan selected path” and the “Slected path to scan” to 'C:', and I checked “Scan archive files”.
9- Pressing “Schedule”, Avast restarted the computer and scanned 'C:' at boot-time (of the normal mode).
10- During the scan, I deleted the files having ‘Trojano-169 [Trj]’ (though this time ‘Win32:Dialui-B [Trj]’ wasn’t detected in C:\pagefile.sys)
11- Then when in normal mode, I moved ‘C:\pagefile.sys’ (might be deleted).
12- I re-enabled the virtual memory to its previous settings.

After restarting my PC many times and being on Internet for hours, it seems there is no sign of those trojans.

As you see, yesterday I missed one step… taking away ‘plugin1.exe’!

Kerim