spoolsv.exe is a Microsoft Windows process that handles the printing process on printers.

There are registries of malicious programs that use the same name to go unnoticed.

Some malware with the same name:
VBS.Masscal.Worm (vbs)

We have logs from other processes using the same file name:

The spoolsv.exe file and task is usually started together with Windows under the name of spoolsv and the command or file spoolsv.exe.

Detected by Symantec security program as W32.Exploz.B and also by Malwarebytes Anti-Malware as Backdoor.Bot malware.

Note: Not to be confused with the legitimate file of the same name spoolsv.exe which is always located in the %System% folder.

Instead, this malicious process/file is located in the %AppData%\Locations folder

More information: http://www.symantec.com/security_response/writeup.jsp?docid=2013-080921-5219-99


Tip: The spoolsv.exe process/program should NOT be started alongside the system. It can be a threat to system security.

