Jump to content



  • Please log in to reply
5 replies to this topic

#1 allangi



  • Full Member
  • Pip
  • 6 posts

Posted 18 June 2004 - 11:54 AM

hi every one i am a new member to this form.

I have a file called a.exe in my system dir.It always starts when the system starts.
I noticed it in the task manager.And found the name strange.So i immeadiately deleted tht file.

Does anybody know about it or is it any custom build trojan by some one.

#2 Xena



  • Full Member
  • Pip
  • 22 posts

Posted 18 June 2004 - 12:40 PM

Did you try googling it?

Edited by Xena, 18 June 2004 - 12:41 PM.

#3 Tuxedo Jack

Tuxedo Jack

    Creator of TuxPE, a Cat5-o'-9-Tails, Etherkillers, and more

  • Expert
  • PipPipPipPipPip
  • 1,757 posts

Posted 19 June 2004 - 08:00 PM

It's a leftover from some ABetterInternet program. It'll mark itself as Systray in the O4 entries of a HJT log.

Get Ad-aware from the link in my signature. Install it, run it, and update the reference file, then scan with it and kill what it finds.

If you want, post a HijackThis log to the Malware Removal forum.
Signature file is under revision. This will be back shortly.

#4 Mike


    Dark Lord of SWI

  • Retired Staff
  • PipPipPipPipPip
  • 514 posts

Posted 20 June 2004 - 03:59 AM

It may also be IRC-Worm.Win32.Rodal.a. It's a fairly recently discovered worm.
SpywareInfo: How are you gentlemen?? All your base are belong to us!!
Spyware: What you say!!
SpywareInfo: You have no chance to survive. Make your time!

#5 allangi



  • Full Member
  • Pip
  • 6 posts

Posted 21 June 2004 - 01:52 PM

thx for the help.I ll download the adware and try to kill it.

#6 allangi



  • Full Member
  • Pip
  • 6 posts

Posted 21 June 2004 - 02:18 PM

i have downloaded adware and scanned. I found 90 new objects in which most of them were cookie tracking objects.Any way i have quarentined/removed them using adware.

Once again thx a lot for the help.

Member of

Support SpywareInfo Forum - click the button
PayPal - The safer, easier way to pay online!