Solved! Use SPOOLSVC.EXE (Worm Mytob) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

SPOOLSVC.EXE – Worm Mytob removal

File MD5 Virus Alias
SPOOLSVC.EXE b373225ca7ba3cfc104128af9ae92e32 Worm Mytob
SPOOLSVC.EXE b373225ca7ba3cfc104128af9ae92e32 Trojan Hllw
SPOOLSVC.EXE b373225ca7ba3cfc104128af9ae92e32 Trojan Eldorado
SPOOLSVC.EXE b373225ca7ba3cfc104128af9ae92e32 Trojan Downloader
SPOOLSVC.EXE b373225ca7ba3cfc104128af9ae92e32 Trojan Crypt
SPOOLSVC.EXE b373225ca7ba3cfc104128af9ae92e32 Backdoor IRCBot

SPOOLSVC.EXE size: 118784 bytes
SPOOLSVC.EXE hash: B373225CA7BA3CFC104128AF9AE92E32

Created files:

%SysDir%\spoolsvc.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WINDOWS SYSTEM MANAGER: spoolsvc.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\WINDOWS SYSTEM MANAGER: spoolsvc.exe
HKLM\System\CurrentControlSet\Services\SharedAccess\Start: 04000000

Detected by UnHackMe:

SPOOLSVC.EXE
Default location: %SYSDIR%\SPOOLSVC.EXE

Dropper information:
MD5: c5db4b69c49eb7b8af8f8511f6fad960
File size: 118784 bytes

Leave a Reply