Spools.dll.vbs Cleaner V1.1

February 12, 2009 at 6:56 pm 4 comments


I have developed this little program to remove away the Spools.dll.vbs aka Attas aka Solow aka VBS/IE-Title worm etc.

Symptom of this worm:

Cannot access your drive eg. C: by double clicking it.

Internet Explorer title bar changed to Xplor Team.


Before running this program, you may wish to insert your flash drive that you think it might infected with this worm.

Click Clean Now.

Followed by Check & Delete button.

If you have other partition like D drive and also your flash drive eg. F drive, simply change the value to the drive letter and hit Check & Delete button.

File size: 25 KB

Download from Download.com

Get it from CNET Download.com!

Download from Mediafire

MD5 Checksum: D429F7AE60C1D44BAF1057ECE113B560


If you are using 3rd party application like PortableApps or U3 thumbdrive that is loaded with special software, by clicking this Check & Delete button, it might disable the autorun.

That’s all for that now. Start protect your PC & Device (eg. USB Drive) from infecting with the same worm and other autorun worms by downloading this standalone Autorun Protector software.

Do comment if there is any question or bug.


Bookmark and Share

Entry filed under: Malware Removal. Tags: , , , , , , , , .

Internet Explorer Display “Careful Bhotiok is already jogging . . . saon na lang?” in the titlebar. MD5 & SHA-1 Checksum Utility

4 Comments Add your own

  • 1. Sabrina  |  February 1, 2010 at 6:26 pm

    hi, i’ve gt the worm in my thumbdrive. tried your program but it said “no signs of infection detected”. and i still cant open my file with double-click. have to right click & open or plug in my thumbdrive to autorun.

    • 2. Raymond  |  February 1, 2010 at 10:08 pm

      Perhaps you infected with other type worm. You can try download Autorun Protector @ https://raylin.wordpress.com/downloads/autorun-protector/ and do a Clear MountPoints2 Registry and restart your PC. Do let me know the outcome.

      In the event there is autorun.inf detected from one of your drives and you are unsure whether to delete it or not, you can click the Analyse and post the result here or in the Autorun Protector comment box.

  • 3. poor fella  |  January 7, 2010 at 3:09 pm

    i tried using ur program and it works! thanks alot.. but when i tried it on my fren’s computer, i says worm nt detected >.< will you be updating this program to version 1.2? ^^

    • 4. Raymond  |  January 7, 2010 at 9:09 pm

      Thanks for the comment 🙂 Perhaps your friend PC is not infected with this worm.


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Trackback this post  |  Subscribe to the comments via RSS Feed



stats for wordpress

%d bloggers like this: