I decided to turn Windows Defender on so I could check if there were too many start up programs, and saw there was still a trace of a virus I thought I had deleted, namely an unsigned csrss.exe. I kinda knew about this since it warns me every time I boot my computer that the registry needs to be updated but I never get around to it. What worried me though is that in the same group (Publisher not available) an unsigned Conhost.exe is running. Shouldn't this be signed by Windows? Is it also a remainder of a virus? I also can't seem to find a conhost.exe in the processes folder
So since I had just turned Windows Defender on anyway and my computer was still laggish, I thought 'might as well let it scan', and it found 2 infected files in the Qoobox quarantine folder. Quick Google thaught me this was the quarantine folder for Combofix, but I kinda feel uncomfortable leaving them there, last time I used combofix was a long time ago. Is it safe letting them sit there or should I clean it up somehow or uninstal combofix and reinstal? I know it's a program for experts (and read the topics about it on this site) but the few times I was hit with a serious Rootkit Combofix fixed it for me without requiring much input so I feel save having it on my desktop.
Finally, I know you guys get this question 100 times a day and will shoot me for it, but even if I resolve my 2 issues I still don't feel 100% safe, what scanner should I use to do another scan so I can assume I'm safe (never 100% sure, I know

Help

Back to top
button.
.
button.
and make sure that the option Remove found threats is 
, and save the file to your desktop as ESETScan.txt.
button, then Finish.
> Run... and in the Open dialog box, type: ComboFix /Uninstall









