Spoolsv.exe high memory usage

I have a Windows 2000 SP4 box.  The Spoolsv.exe memory usage constatly increases. If I stop and restart the service it responds as it should.
I have deleted all printer drivers; removed any references to printers in the registry; checked for viruses; replaced the Spoolsv.exe file with a known good one.
RichardSimmsAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

SheharyaarSaahilCommented:
Hello RichardSimms =)

Check the suggestions here to Cleanup the printer drivers and resetting the spoolsv.exe service >> http://members.shaw.ca/bsanders/CleanPrinterDrivers.htm

!! GOOD LUCK !!
0
RichardSimmsAuthor Commented:
Thanks for this suggestion.  What is so strange is I have followed these directions and every other troubleshooting document I could find.  Yet, nothing seems to work.
0
SheharyaarSaahilCommented:
ok,,,, so u are trying to use only one printer right now..... what if u uninstall this printer, and install another printer(with updated drivers).... does the spoolsv.exe problem still exist ??
0
Cloud Class® Course: C++ 11 Fundamentals

This course will introduce you to C++ 11 and teach you about syntax fundamentals.

RichardSimmsAuthor Commented:
Yes, I have uninstalled all the printers at this point. I also dowloaded the updated drivers and installed them without success.  At this point I do not have any printers installed and yet the Spoolsv.exe is doing the same thing....go figure.
0
SheharyaarSaahilCommented:
hmmmmmmm so how abt trying some suggestion from here >> http://www.annoyances.org/exec/forum/winxp/t1084676549
0
RichardSimmsAuthor Commented:
Thanks:

I looked into the Microsoft image printing and it was not installed on the box.
0
SheharyaarSaahilCommented:
hmmmmmmm then what else.... can we think abt reinstalling\reapplying only SP4 :-?
0
RichardSimmsAuthor Commented:
Are you suggesting installing overtop of the current installatiion or uninstalling and then a reinstall?
0
SheharyaarSaahilCommented:
installing overtop is enough i think..... coz it will reset all settings again as they were set when u first installed SP4 !!!!
0
RichardSimmsAuthor Commented:
I reinstalled SP4 and no change.  Uninstalled SP4 and Reinstalled and still no change.  This is very strange.
0
SheharyaarSaahilCommented:
go here and stop the unwanted services >> http://www.blackviper.com/WIN2K/servicecfg.htm

if same issue then try this, Download HijackThis v1.98.2, run it, Save the LOG file and Post it here:
http://tools.radiosplace.com/HijackThis.exe
0
RichardSimmsAuthor Commented:
Here it is:

Logfile of HijackThis v1.97.7
Scan saved at 9:53:05 AM, on 9/2/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
Z:\ImLua.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\PDesk\PDesk.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINNT\system32\SxgTkBar.exe
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\WINNT\System32\dpmw32.exe
C:\WINNT\system32\NWTRAY.EXE
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\Real\RealJukebox\tsystray.exe
C:\Nemis\bin\javaw.exe
C:\Program Files\Winamp\Winampa.exe
C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\WINNT\system32\NALWIN32.EXE
C:\WINNT\twain_32\Fjscan32\FJLaunch.exe
C:\Program Files\Iomega\Tools_NT\IMGICON.EXE
C:\WINNT\system32\naldesk.exe
C:\VREDISCOV\FXP.WIN\red.exe
J:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nara-at-work.gov/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://staffonly.nara.gov
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by NARA
O1 - Hosts: 198.76.128.82 zenwsimport
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINNT\System32\nzdd.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [RealJukeboxSystray] "C:\Program Files\Real\RealJukebox\tsystray.exe"
O4 - HKLM\..\Run: [NEMIS] C:\Nemis\bin\javaw -cp "c:\nemis\lib\nemis.jar" -DmulticastGroup="231.1.1.128" gov.nara.nemis.NEMIS
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [Mediafour Mac Volume Notifications] "C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE" /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe -r
O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Fujitsu Scanner Control Center.lnk = C:\WINNT\twain_32\Fjscan32\FJLaunch.exe
O4 - Global Startup: Getting Started with MacDrive 5.lnk = C:\Program Files\Mediafour\MacDrive5\MDGSTART.EXE
O4 - Global Startup: Iomega Icons.lnk = C:\Program Files\Iomega\Tools_NT\IMGICON.EXE
O4 - Global Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools_NT\startnt.exe
O4 - Global Startup: Logo Calibration Loader.lnk = C:\PROGRA~1\GRETAG~1\i1\CalibrationLoader\CalibrationLoader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RealDownload.lnk = C:\Program Files\Real\RealDownload\Realdownload.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npswf32.dll
O12 - Plugin for .TIF: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://staffonly.nara.gov
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37959.4547685185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EFB22865-F3BC-4309-ADFA-C8E078A7F762} (SysWebTelecomInt Class) - http://www.sponsoradulto.com/en/SysWebTelecom.cab


0
SheharyaarSaahilCommented:
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINNT\System32\nzdd.dll
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe
================================

check these lines and click on Fix Checked !!
then go here coz this line(O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe) shows that ur ur system is infected with WORM_SDBOT.NM >> http://it.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=WORM_SDBOT.NM
0
RichardSimmsAuthor Commented:
Update:

Used the Windows 2000 disk to repair the OS. This resolved the issue.
0
RichardSimmsAuthor Commented:
I resolved this issue by running a repair using the os disk.
0
Computer101Commented:
PAQed, with points refunded (400)

Computer101
E-E Admin
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.