Solved

Spoolsv.exe high memory usage

Posted on 2004-08-24
18
2,621 Views
Last Modified: 2012-05-05
I have a Windows 2000 SP4 box.  The Spoolsv.exe memory usage constatly increases. If I stop and restart the service it responds as it should.
I have deleted all printer drivers; removed any references to printers in the registry; checked for viruses; replaced the Spoolsv.exe file with a known good one.
0
Comment
Question by:RichardSimms
  • 8
  • 7
18 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11883410
Hello RichardSimms =)

Check the suggestions here to Cleanup the printer drivers and resetting the spoolsv.exe service >> http://members.shaw.ca/bsanders/CleanPrinterDrivers.htm

!! GOOD LUCK !!
0
 

Author Comment

by:RichardSimms
ID: 11884971
Thanks for this suggestion.  What is so strange is I have followed these directions and every other troubleshooting document I could find.  Yet, nothing seems to work.
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11885476
ok,,,, so u are trying to use only one printer right now..... what if u uninstall this printer, and install another printer(with updated drivers).... does the spoolsv.exe problem still exist ??
0
 

Author Comment

by:RichardSimms
ID: 11887511
Yes, I have uninstalled all the printers at this point. I also dowloaded the updated drivers and installed them without success.  At this point I do not have any printers installed and yet the Spoolsv.exe is doing the same thing....go figure.
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11887555
hmmmmmmm so how abt trying some suggestion from here >> http://www.annoyances.org/exec/forum/winxp/t1084676549
0
 

Author Comment

by:RichardSimms
ID: 11903257
Thanks:

I looked into the Microsoft image printing and it was not installed on the box.
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11904737
hmmmmmmm then what else.... can we think abt reinstalling\reapplying only SP4 :-?
0
 

Author Comment

by:RichardSimms
ID: 11907770
Are you suggesting installing overtop of the current installatiion or uninstalling and then a reinstall?
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11907801
installing overtop is enough i think..... coz it will reset all settings again as they were set when u first installed SP4 !!!!
0
 

Author Comment

by:RichardSimms
ID: 11943879
I reinstalled SP4 and no change.  Uninstalled SP4 and Reinstalled and still no change.  This is very strange.
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11948469
go here and stop the unwanted services >> http://www.blackviper.com/WIN2K/servicecfg.htm

if same issue then try this, Download HijackThis v1.98.2, run it, Save the LOG file and Post it here:
http://tools.radiosplace.com/HijackThis.exe
0
 

Author Comment

by:RichardSimms
ID: 11963569
Here it is:

Logfile of HijackThis v1.97.7
Scan saved at 9:53:05 AM, on 9/2/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
Z:\ImLua.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\PDesk\PDesk.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINNT\system32\SxgTkBar.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\WINNT\System32\dpmw32.exe
C:\WINNT\system32\NWTRAY.EXE
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\Real\RealJukebox\tsystray.exe
C:\Nemis\bin\javaw.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\WINNT\system32\NALWIN32.EXE
C:\WINNT\twain_32\Fjscan32\FJLaunch.exe
C:\Program Files\Iomega\Tools_NT\IMGICON.EXE
C:\WINNT\system32\naldesk.exe
C:\VREDISCOV\FXP.WIN\red.exe
J:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nara-at-work.gov/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://staffonly.nara.gov
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NARA
O1 - Hosts: 198.76.128.82 zenwsimport
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINNT\System32\nzdd.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [RealJukeboxSystray] "C:\Program Files\Real\RealJukebox\tsystray.exe"
O4 - HKLM\..\Run: [NEMIS] C:\Nemis\bin\javaw -cp "c:\nemis\lib\nemis.jar" -DmulticastGroup="231.1.1.128" gov.nara.nemis.NEMIS
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Mediafour Mac Volume Notifications] "C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE" /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe -r
O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Fujitsu Scanner Control Center.lnk = C:\WINNT\twain_32\Fjscan32\FJLaunch.exe
O4 - Global Startup: Getting Started with MacDrive 5.lnk = C:\Program Files\Mediafour\MacDrive5\MDGSTART.EXE
O4 - Global Startup: Iomega Icons.lnk = C:\Program Files\Iomega\Tools_NT\IMGICON.EXE
O4 - Global Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools_NT\startnt.exe
O4 - Global Startup: Logo Calibration Loader.lnk = C:\PROGRA~1\GRETAG~1\i1\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RealDownload.lnk = C:\Program Files\Real\RealDownload\Realdownload.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npswf32.dll
O12 - Plugin for .TIF: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://staffonly.nara.gov
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37959.4547685185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/en/SysWebTelecom.cab


0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11964554
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINNT\System32\nzdd.dll
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe
================================

check these lines and click on Fix Checked !!
then go here coz this line(O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe) shows that ur ur system is infected with WORM_SDBOT.NM >> http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SDBOT.NM
0
 

Author Comment

by:RichardSimms
ID: 12193403
Update:

Used the Windows 2000 disk to repair the OS. This resolved the issue.
0
 

Author Comment

by:RichardSimms
ID: 12373817
I resolved this issue by running a repair using the os disk.
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 12438883
PAQed, with points refunded (400)

Computer101
E-E Admin
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
A procedure for exporting installed hotfix details of remote computers using powershell
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now