Tell us where exactly Avast finds it. If you run XP disable system restore.
I have a similar to problem with a trojan form ad programs. It seems to come from IE. I am using NetScape 7.1 to avoid the pop ups.
I tried your suggestions, ie disabling ysystem restore and re-enabling it. It doesn't work. The virus keeps showing up when I reoot.
I have SpyBot and ran it. It doesn't help. Pehaps I don't know how to work it right.
Here is what Avast finds. It's a bit complicated, but I was able to copy the four trojans from the virus chest.
Scanning of selected files
Action was completed successfully!
Virus has been detected!
File Name: adbumb2.exe
FileID: 60
Virus Description: Win32:Bridge [Trj]
Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp
FileID: 0000000060 Original file name: C:\Program Files\STC\adbumb2.exe New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp\60.exe
Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp\60.exe Win32:Bridge [Trj]
------------------------------------------------------------------------------------------
Action was completed successfully!
Scanning of selected files
Action was completed successfully!
Virus has been detected!
File Name: adbumb2[1].exe
FileID: 59
Virus Description: Win32:Bridge [Trj]
Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp
FileID: 0000000059 Original file name: C:\Documents and Settings\Dean\Local Settings\Temporary Internet Files\Content.IE5\MH6XSZE5\adbumb2[1].exe New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp\59.exe
Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp\59.exe Win32:Bridge [Trj]
------------------------------------------------------------------------------------------
Action was completed successfully!
Scanning of selected files
Action was completed successfully!
Virus has been detected!
File Name: ClrSchP070.exe
FileID: 62
Virus Description: Win32:Trojan-gen. {VC}
Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp
FileID: 0000000062 Original file name: C:\Program Files\STC\ClrSchP070.exe New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp\62.exe
Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp\62.exe Win32:Trojan-gen. {VC}
------------------------------------------------------------------------------------------
Action was completed successfully!
Scanning of selected files
Action was completed successfully!
Virus has been detected!
File Name: ClrSchP070[1].exe
FileID: 61
Virus Description: Win32:Trojan-gen. {VC}
Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest
Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp
FileID: 0000000061 Original file name: C:\Documents and Settings\Dean\Local Settings\Temporary Internet Files\Content.IE5\8VY1APA3\ClrSchP070[1].exe New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp\61.exe
Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp\61.exe Win32:Trojan-gen. {VC}
------------------------------------------------------------------------------------------
Action was completed successfully!
I hope you can make sense of this, as I have about given up.
Dean