When Following the advice of others, I checked my Printers settings, found the MSO Image Writer, right-clicked and cancelled all print jobs.

It has an image icon but with an .EXE extension; a clear sign of malicious intent. I have seen the "Mirosoft Image Writer" issue stated above (where the print jobs are waiting in the Microsoft Image Write queue). In the past, other rogues, including earlier variants of FakeXPA, have generally used DLLs, such as Browser Helper Objects or Netscape plugins, to interact with users' browsers.

BugCheck 1000008E, {c0000005, 8052ab2b, aa1389fc, 0} Probably caused by : sptd.sys ( sptd+172eb ) Followup: MachineOwner kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e) By clicking on the link, the user will be prompted to run the application "JPhotoAlbum", which is a Java class inside a JAR file (JPhotoAlbum.jar SHA1: 159e6bc0616dec2062c92a7dd918c8179b2de640).

Some of my system specs?: Microsoft Windows XP Home Edition Version 5.1.2600 Service Pack 3 build 2600 Processor x86 Family 6 Model 15 Stepping 6 GenuineIntel ~1994 Mhz BIOS-version/dato COMPAL 105B If located in system32, it's the Windows Print Spooler - which is _safe_ and _not_ a virus!

  1. Specs: ASUS M2NPV-VM AMD Athlon 64x2 5200+ 2 gig DDR 800 80 gig SATA (2) in RAID Mirror array No video card, using onboard Geforce 6150 Windows XP Pro SP3 All
  2. Ahmet It continues to build, 2 days ago had 3 *.spl files at about 3GB each, had 1 today at 8gb.
  3. Image 1 - CVE-2010-3962 attack attempts by geo-location Over the past few days, attack attempts in China have been on the rise, again, the downward trend that occurred during the first
  5. Annoyed It's a spooler.
  6. Burns spoolsv.exe using 100% on re-boot and when trying to print.
  7. It was due to few pending print jobs in a printer.
  8. I've always thought it was a little weird.

simply go to the properties of the printer and turn off spooling and have the documents sent directly to the printer. Since you've already replaced the RAM I will assume you are somewhat comfortable with digging around in your PC. After several months of calling themselves "Antivirus 8", recent variants of Rogue:Win32/FakeXPA have begun going by the name of "AVG Antivirus 2011."

Try doing a repair install after backing up your data. Using the Marketplace tab at the top of this web page will provide some excellent deals. As I further investigated the sample, it displayed the following greeting: Note: the message displayed is from a valid electronic greetings website. Microsoft Security Essentials already detects the malware

Advertisement After running Avast & Adaware I discovered If it is getting all cpu resources, probably you have a printers/fax configuration problem.

That is why Norton ... We detect these as Trojan:MacOS_X/Boonana.

I began with trying Troll's solution of disabling the PE386 at the system restore screen. Follwed the advice of those who said there were pending print jobs.

So i had to close it each time i starting my PC with Win XP (I have a AMD Athlon XP 1800+, 256 MB-DDR) this procedure takes 3 times, because this spud happened to me.

There are two problems with that. This kind of technique has become extremely popular with rogues and serves the dual purpose of making the claims of infection more convincing and making the machine harder to use without I have Windows2000, and I don't know how a printer spooler can use 90+ percent of my CPU for 10+ minutes! The hard drive may be dying.

Specifically, Bohu uses a number of different techniques in order to attempt to thwart Cloud-based AV technologies. If it turns out to be a virus it will be easier to clean the drive if you haven't booted from it as key Windows and/or antivirus files may have been

my kaspersky av program finds worm.win31.soriw in the spooler directory. laytonjp Increases CPU usage by 90 +%. Spoolv.exe no longer takes 100% cpu time.