• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Malware can't find root of problem

I have a system today that seemed to be fine. I wouldn't have suspected anything except I noticed IE running as a process but this system never uses IE, they use chrome, and there was no IE window open.

I ended the process and within a few seconds it appeared again. I figured malware was running it hidden and managed to find the program that was launching it. Printspool.exe hidden in user/appdata/roaming/print spooler. Delete it and it is copied back.

I eliminated its ability to run by removing execute permissions. The last step was to remove what was putting it there. Here I am stuck.
I cannot find what is copying the file to that location.

Places I checked:
Registry - all the usual run, run once settings
Task - nothing in scheduled task
Nothing in any of the startup files.
Searched through windows system files for things that don't belong, nothing found

I can run AV and anti-malware, rootkit software and they find printspool.exe but not the task that is putting it there.
 
Back
Top