Teach you how to clear Spoolsv.exe Trojan

  

First, what is Spoolsv.exe
Spoolsv.exe is a system process for sending the system's print tasks to the printer to execute, is the process of controlling the printing work in the computer . However, it is worth noting that Spoolsv.exe may also be a Backdoor.Ciadoor.B Trojan, a Trojan horse program that delays printing. The Trojan can make the CPU usage of the user reach 100%, which causes the CPU fan to run at high speed and noisy. And allow attackers to access your computer and steal personal information and passwords.

Second, to determine whether Spoolsv.exe is a Trojan

To determine whether Spoolsv.exe is a Trojan, the method is simple, as long as the path of the process can be known.

The normal system process Spoolsv.exe has the path C:windowssystems32spoolsv.exe.

The path of the Trojan Spoolsv.exe process is C:WINDOWSsystem32spoolsvspoolsv.exe

1. Open the system disk and check if there is a folder named "C:/Windowssystem32spoolsv", there is also a Spoolsv. Exe file, and display the description of "Promoting Browser Accessibility Tool".

2. Press Ctrl+Alt+Delete to open the task manager and check if the CPU usage of the Spoolsv.exe process is high. If the above two points are met, then the user's computer is likely to have been invaded by the Spoolsv.exe Trojan.

Third, clear the Spoolsv.exe Trojan method

1, first restart the computer, press F8 to enter safe mode.

2. Click the "Start - Run" command, enter CMD, open the DOS window

3. Enter cd, press Enter, and return to the C: root directory.

4. Use the rd command to delete the following directory. Use the rd command: Enter “rd c:windowssystem32spoolsv/s” and press Enter to display the prompt. Press Y to confirm the deletion, as shown in the figure.

C:WINDOWSsystem32msibm

C:WINDOWSsystem32spoolsv

C:WINDOWSsystem32?akcfs

C:WINDOWSsystem32msicn

5, use The del command deletes the following files. Use the del command: Enter "del c:windowssystem32spoolsv.exe" and press Enter to delete the infected spoolsv.exe file.

C:windowssystem32spoolsv.exe

C:WINDOWSsystem32wmpdrm.dll

6. Restart the computer and enter safe mode. Right-click on "My Computer", select "Manage" to open the "Computer Management" dialog box, select "Services and Applications - Services", and find "NTservice" on the right to set the startup type in the properties to "Disabled".

7. Click the "Start - Run" command, enter regedit, open the registry. Select "Edit - Select Find" to find the registry entry containing spoolsv.exe and delete it. You can use F3 to continue searching and delete all registry entries containing spoolsv.exe.

8. After performing the above operations, the computer still has the spoolsv.exe process running, right click on "My Computer", select "Manage", click "Services and Applications - Services", right click Print spooler, select "Properties", click the "Stop" button, and then modify the startup type to "Manual" or "Disable". Then repeat the above operation.

Copyright © Windows knowledge All Rights Reserved