Solved

MS Security Hotfix = "Spoolsvc32.exe" a valid registry entry or virus?

Posted on 2004-09-26
3
440 Views
Last Modified: 2013-12-04
I have an Acer Laptop, running XP Home and notice a Registry Entry that I can't find any information for.
Has anyone seen this in HKLM/Software/Microsoft/Windows/CurrentVersion/Run, and ../RunServices:
       MS Security Hotfix             "Spoolsvr32.exe"
I could not actually find the file on the C: drive.
SPOOLSV.EXE is running in processes.
Is it legit or some form of virus/trojan?
Ad-Aware SE Personal does not flag it, neither does Mcafee VirusScan.


Many thanks.
Lisa
0
Comment
Question by:carrot999
3 Comments
 
LVL 16

Accepted Solution

by:
JamesDS earned 125 total points
ID: 12158078
carrot999
MS do not issue hotfixes that operate in this way.
This is almost certainly a trojan of some description.

You have probably unwittingly downloaded something nasty.

This link (largely courtesy of COBOLDinosaur) contains everything you need to know about spyware, scumware, adware, hijacked home pages etc and the tools you need to get rid of them:

http://www.experts-exchange.com/Web/Browser_Issues/Q_20975384.html


Cheers

JamesDS
0
 
LVL 2

Expert Comment

by:Ke11ie
ID: 12158108
Hi Lisa

I checked my regedit and couldn't find anything called spoolsvr32.exe. The Print process you have called spoolsv.exe is the correct process for the Print Spooler - so that's no problem. If you do a google search for 'spoolsvr' a few sites come up - all in German though (which are all regarding printing and nothing with regards to viruses, etc.) Maybe it is just another name for the Print Spooler? If your computer isn't having any problems (like it's infected by a virus or something) I'd just ignore it!


Kellie
0
 

Author Comment

by:carrot999
ID: 12158125
Thanks Kellie,
Its reassuring to have my suspicions confirmed.  Appreciate your speedy assistance.

Cheers, Lisa
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question