spoolsv.exe Virus

spoolsv.exe found to be infected by a spoolsv.exe Trojan horse virus, how can not afford to kill all kill, kill again, finally to find the next and found that the latest variant of spoolsv.exe is still no software can kill, therefore, will be solution posted here, we want to help spoolsv.exe Trojan horse program is a slow printing, which allows the computer CPU usage to 100%, so that high-speed noisy fan to keep running. Currently available online method may be able to solve the initial problem, but the latest variant of the phenomenon of powerlessness.

Ctrl + Alt + Delete to stop spoolsv.exe Running Process

Restart your computer into Safe Mode, in the C: / windows/system32 / Remove spoolsv.exe (or the available ways to search all of the same name to delete C drive files)

Run regedit, find ways to use to find and delete all spoolsv files.

Right-click My Computer, choose manage, service, disable the print spooler service

Restart the computer into the system normal mode, you will find that your computer or in a high-speed operation, but the search has not found any spoolsv relevant documents.

Ctrl + Alt + Delete, you can find one in the process called inter background run the program, you can turn it off.

Is strongly recommended in the application of the above steps to resolve the problem, run anti-spyware program to scan and delete infected files.

spoolsv.exe is used to Windows printer tasks to a local printer.

Note

spoolsv.exe is also possible that Backdoor.Ciadoor.B Trojan. This Trojan allows an attacker to access your computer, stealing passwords and personal data. The security level of the process is recommended for immediate deletion.

Method 3:

spoolsv.exe

spoolsv.exe and the windows of the print service spoolsv.exe very similar to it will not be confused, and print service spoolsv.exe the directory is the system folder (in XP, for example) system32spoolsv.exe the path of this virus under system32spoolsvsploosv.exe Virus Information provided even get killing method: 1. System32 directory into the system to delete the folder spoolsv and miscn, as well as 11162. Start Menu Run regedit Open the Registry Editor, find

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]

"spoolsv" = "% System% spoolsvspoolsv.exe-printer" to delete the three. In the Registry Editor, open the following branch and use the key combination ctrl + f to search for the following: [HKEY_CLASSES_ROOTCLSID

[HKEY_CLASSES_ROOTwmpdrm.cfsbho

[HKEY_CLASSES_ROOTwmpdrm.cfsbho.1

[HKEY_CLASSES_ROOTTypeLib

[HKEY_CLASSES_ROOTInterface found one to delete 4. Kiyosato software to run the registry clean up registry, this step may or may not enforce system process spoolsv.exe

Method 4:

Spoolsv.exe is a slow printing Trojan program that the computer CPU usage to 100%, so that a noisy fan to maintain high speed operation; the Trojan allows an attacker to access your computer, stealing passwords and personal data.

First, determine if they are poisoned

1, point to Start - Run, type msconfig, enter, open the configuration utility program, select the "Start", after the infection was found in the Startup items is running Spoolsv.exe the boot options, each entry will be NTservice dialog windows.

2, open the system disk, assuming that C drive to see if there is C: WINDOWSsystem32spoolsv folder, which have spoolsv.exe files, the normal spoolsv.exe printer buffer pool files should be C: WINDOWSsystem32 directory.

3, open the Task Manager, you will find spoolsv.exe process, but the high CPU occupancy rate

2, clear the way

1, restart, boot press F8 to enter Safe Mode.

2, point to Start - Run, type cmd, enter the dos, the use of rd command to remove what directory (if it exists)

C: WINDOWSsystem32msibm

C: WINDOWSsystem32spoolsv

C: WINDOWSsystem32bakcfs

C: WINDOWSsystem32msicn

For example, in dos window, enter: rd (space) C: WINDOWSsystem32spoolsv / s, carriage returns, you are prompted, enter y enter, you can delete the entire directory.

Using del command to delete the following files (if it exists)

C: windowssystem32spoolsv.exe

C: WINDOWSsystem32wmpdrm.dll

For example, in dos window, enter: del (space) C: windowssystem32spoolsv.exe, carriage returns, you can delete the infected spoolsv.exe, this file can be other anti-virus after the end of normal reproduction machine normal spoolsv. exe paste it into C: windowssystem32 folder.

3, restart press F8 to enter safe mode again

(1) Desktop Right-click My Computer, select "Management", click on "Services and Applications" - "service", right-click NTservice, select "Properties", change the Startup type to "Disabled."

(2) of Start, Run, type regedit, enter to open the registry, point the menu on the editing, select Find to find items containing spoolsv.exe registry, delete the. Can use the F3 to continue to find, which will contain spoolsv.exe delete all the registry items.

Third, once again to re-start can be a normal

Clear the virus after you file, there is no SPOOLSV.EXE, and in the service where your spool print spooler can not be started, of course, the printer can not run, run inside type "services.msc" after "print spooler "service in the" General "item inside the" executable file path "has become unavailable, such as the launch will be displayed" Error 3: Can not find the system path "error, it is because your registry entries related to and deletions, and

Solution:

1: In the I386 directory on CD-ROM inside the SPOOLSV.EX_ copy files to SYSTEM32 directory changed its name to spoolsv.exe, of course, can also be in someone else's system to copy the file over, you can also use NT / XP file protection function , ie, type CMD where SFC / SCANNOW full restoration, anyway you put this file can be restored by

2: Modify the registry, the next plus one "ImagePath" = "c: windowssystem32spoolsv.exe" can be, and then open look, you can print a bar


No comments:

Post a Comment