From: "Scanner" <xx.RemoveThis@xx.com>
| spoolsvr.exe / fl32.exe / loadadv.exe / Tibs -- all connected.
|
| - Location: windows\spoolsvr.exe
| - Registry Key :
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\prntspman\ > ImagePath
| c:\windows\spoolsvr.exe
|
| - AT bootup spoolsvr.exe will recreate C:\fl32.exe
| &
| - C:\Documents and Settings\LocalService\Local Settings\Temporary Internet
| Files\Content.IE5 > in one of the folder loadadv77(1).exe or other number .
|
| Note: Local Service folder is hidden, you have to enter this path in the
| address box and press enter.
|
| Anti-Virus and Spyware Killers might fail to detect and remove them.
|
| Remove them this way:
|
| SOLUTION : Delete the whole registry key
| HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\prntspman\
| If you want to be safe then save this key first using export from Registry.
|
| Reboot and delete spoolsvr.exe, fl32.exe and loadadv.exe from the respective
| directories
|
I hope you took the time to at least submit the files to Virus Total to discern who
recognizes this Trojan. All submissions sent to Virus Total are provided to participating
AV vendors.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm