Sridhar_Rao
In the zone
Hello,
When i inserted a flash drive, the avast AV detected
VBS:Malware-gen in autorun.inf. Every attempt to delete repair and
move to chest failed. I disabled autorun feature on all drives using microsoft
TWEAK UI. Finally I used an untested application flash disinfector,
which solved the problem but left its own autorun folder on all
drives.
Whenever I try to connect to net the comodo firewall detects
an application C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe
trying to modify the memory of internet explorer and connecting to
some remote location. I am sure there is a trojan. Complete scan
(including boot time) using avast, spybot S&D, Avast adaware, windows
malicious software removal tool, rootkit revealer (all updated
versions) failed to detect anything. There are entries of spoolsv.exe
in registry too. This file exists in recycler too. What is this file doing in recycler and trying to connect internet. Should I delete all
entries in registry? what should i do now?
Any useful help is welcomed.
When i inserted a flash drive, the avast AV detected
VBS:Malware-gen in autorun.inf. Every attempt to delete repair and
move to chest failed. I disabled autorun feature on all drives using microsoft
TWEAK UI. Finally I used an untested application flash disinfector,
which solved the problem but left its own autorun folder on all
drives.
Whenever I try to connect to net the comodo firewall detects
an application C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe
trying to modify the memory of internet explorer and connecting to
some remote location. I am sure there is a trojan. Complete scan
(including boot time) using avast, spybot S&D, Avast adaware, windows
malicious software removal tool, rootkit revealer (all updated
versions) failed to detect anything. There are entries of spoolsv.exe
in registry too. This file exists in recycler too. What is this file doing in recycler and trying to connect internet. Should I delete all
entries in registry? what should i do now?
Any useful help is welcomed.