spoolsv.exe - Dangerous
%windir%\temp\spoolsv\spoolsv.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
%WinDir%\Temp\spoolsv\spoolsv.exe is Trojan/Backdoor.
Kill the process %WinDir%\Temp\spoolsv\spoolsv.exe and remove %WinDir%\Temp\spoolsv\spoolsv.exe from Windows startup.
Malware: postcard.gif.exe
Removed: C:\WINDOWS\Temp\spoolsv\spoolsv.exe
Classification:Antivirus Version Last Update Result
F-Secure 9.0.15370.0 2010.01.17 -
Kaspersky 7.0.0.125 2010.01.17 Backdoor.IRC.Zapchast.zwrc
McAfee 5864 2010.01.17 Generic BackDoor
Microsoft 1.5302 2010.01.17 Backdoor:Win32/IRCFlood
NOD32 4780 2010.01.17 REG/RunKeys.NAA
Symantec 20091.2.0.41 2010.01.17 IRC.Backdoor.Trojan
Additional information
File size: 949984 bytes
MD5 : 68a521cd1d46ae3b99d18f4c4dabe1b5
SHA1 : 7939051d772a1f92b12632f0a1d8bdb8d770ec93
SHA256: 427b6250c090951c0b9f5379136834b022557b15cfbb164d0e89fbade8fcf2bd
http://greatis.com/blog/how-to-remove-ma...