Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 3.88%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.06%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.19%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.02%
6.2.9200.16384 (win8_rtm.120725-1247) 2.05%
6.2.9200.16384 (win8_rtm.120725-1247) 11.99%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.02%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.06%
6.1.7600.16385 (win7_rtm.090713-1255) 1.11%
6.1.7600.16385 (win7_rtm.090713-1255) 2.26%
6.1.7600.16385 (win7_rtm.090713-1255) 3.11%
6.1.7600.16385 (win7_rtm.090713-1255) 31.04%
6.1.7600.16385 (win7_rtm.090713-1255) 4.56%
6.1.7600.16385 (win7_rtm.090713-1255) 11.42%
6.1.7600.16385 (win7_rtm.090713-1255) 1.43%
6.1.7600.16385 (win7_rtm.090713-1255) 1.64%
6.1.7600.16385 (win7_rtm.090713-1255) 0.87%
6.1.7600.16385 (win7_rtm.090713-1255) 0.81%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
View more

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegisterServiceCtrlHandlerExW, RegCloseKey, RegOpenKeyExW, RegDisablePredefinedCache, RegQueryValueExW, ConvertStringSecurityDescriptorToSecurityDescriptorW, SetServiceStatus, StartServiceCtrlDispatcherW, SetThreadToken, OpenThreadToken, OpenProcessToken
api-ms-win-core-console-l1-1-0.dll
SetConsoleCtrlHandler
api-ms-win-core-debug-l1-1-1.dll
IsDebuggerPresent, OutputDebugStringW, DebugBreak
api-ms-win-core-errorhandling-l1-1-1.dll
SetErrorMode, GetErrorMode, SetUnhandledExceptionFilter, GetLastError, RaiseException, UnhandledExceptionFilter, SetLastError
api-ms-win-core-file-l1-2-0.dll
GetTempFileNameW, DeleteFileW, CreateFileW, ReadFile
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll
HeapSetInformation, HeapDestroy, HeapCreate, GetProcessHeap
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedDecrement, InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-1.dll
DisableThreadLibraryCalls, LoadLibraryExW, GetModuleHandleW, FreeLibrary, GetModuleHandleA
api-ms-win-core-localregistry-l1-1-0.dll
RegQueryInfoKeyW, RegGetKeySecurity, RegSetKeySecurity, RegEnumValueW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegEnumKeyExW, RegDeleteKeyExW, RegOpenCurrentUser, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegGetValueW
api-ms-win-core-processthreads-l1-1-1.dll
ExitProcess, GetCurrentThread, GetCurrentProcessId, GetCurrentThreadId, SetThreadToken, TlsFree, ExitThread, TerminateProcess, OpenProcessToken, SetPriorityClass, GetCurrentProcess, TlsGetValue, OpenProcess, CreateProcessAsUserW, OpenThreadToken, TlsSetValue, TlsAlloc, CreateThread
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegDeleteTreeW, RegSetValueExW, RegGetKeySecurity, RegEnumValueW, RegSetKeySecurity, RegGetValueW, RegDeleteKeyExW, RegOpenCurrentUser, RegQueryValueExW, RegOpenKeyExW, RegDisablePredefinedCacheEx, RegQueryInfoKeyW, RegCloseKey, RegCreateKeyExW, RegDeleteValueW, RegEnumKeyExW
api-ms-win-core-string-l1-1-0.dll
CompareStringW
api-ms-win-core-synch-l1-2-0.dll
OpenEventW, AcquireSRWLockShared, ReleaseSRWLockShared, CreateMutexW, InitializeCriticalSection, WaitForSingleObject, SetEvent, EnterCriticalSection, LeaveCriticalSection, CreateEventW, ReleaseSRWLockExclusive, ReleaseMutex, InitializeSRWLock, AcquireSRWLockExclusive, InitializeCriticalSectionAndSpinCount, Sleep
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTime, GetTickCount, GetSystemWindowsDirectoryW, GetSystemTimeAsFileTime, GetVersionExW
api-ms-win-eventing-classicprovider-l1-1-0.dll
UnregisterTraceGuids, TraceEvent, RegisterTraceGuidsW, GetTraceLoggerHandle
api-ms-win-power-base-l1-1-0.dll
GetPwrCapabilities
api-ms-win-security-base-l1-2-0.dll
DuplicateToken, SetTokenInformation, IsWellKnownSid, GetSecurityDescriptorDacl, AddAccessDeniedAceEx, GetLengthSid, ImpersonateLoggedOnUser, AddAccessAllowedAceEx, CreateWellKnownSid, GetTokenInformation, GetSidSubAuthority, GetSidSubAuthorityCount, EqualSid, InitializeSecurityDescriptor, DuplicateTokenEx, SetSecurityDescriptorDacl, GetAclInformation, AddAce, CopySid, GetAce, AllocateAndInitializeSid, FreeSid, RevertToSelf, CheckTokenMembership, InitializeAcl
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW
api-ms-win-service-core-l1-1-1.dll
StartServiceCtrlDispatcherW, SetServiceStatus, RegisterServiceCtrlHandlerExW
dnsapi.dll
DnsQuery_W, DnsFree
kernel32.dll
lstrcmpiW, QueueUserWorkItem, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, AcquireSRWLockShared, ReleaseSRWLockShared, InitializeSRWLock, GetSystemTime, MoveFileExW, IsDebuggerPresent, AddVectoredExceptionHandler, DeleteFileW, GetCurrentProcessId, GetComputerNameW, WideCharToMultiByte, lstrlenW, LoadLibraryW, GetCurrentThread, LoadLibraryExW, SetErrorMode, SetPriorityClass, HeapDestroy, TlsFree, DisableThreadLibraryCalls, HeapCreate, TlsGetValue, SetConsoleCtrlHandler, InitializeCriticalSection, DuplicateHandle, ReadFile, CreateFileW, GetTempFileNameW, CompareStringW, ExitThread, GetLastError, CloseHandle, WaitForSingleObject, GetModuleHandleW, CreateEventW, CreateThread, GetTickCount, ExitProcess, Sleep, OpenEventW, HeapSetInformation, GetProcessHeap, InitializeCriticalSectionAndSpinCount, TlsAlloc, GetVersionExW, LeaveCriticalSection, EnterCriticalSection, SetEvent, SetLastError, TlsSetValue, InterlockedDecrement, OpenProcess, InterlockedIncrement, RaiseException, GetProcAddress, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, InterlockedExchange, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter, GetCurrentThreadId, DebugBreak, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetThreadpoolTimer, HeapAlloc, HeapFree, DeleteCriticalSection, ResetEvent, LocalFree, LoadLibraryA, LocalAlloc, GetModuleHandleExW, CloseThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CreateThreadpoolTimer, ResolveDelayLoadedAPI, GetTickCount64, OutputDebugStringW
msvcrt.dll
DllMain
ntdll.dll
RtlIpv6AddressToStringW, RtlIpv4AddressToStringW, NtClose, NtOpenThreadToken, NtSetInformationThread, NtOpenProcessToken, RtlReportException, EtwEventEnabled, TpReleasePool, TpAllocTimer, TpSetTimer, TpAllocWork, TpPostWork, TpSimpleTryPost, TpAllocWait, TpAllocPool, TpSetPoolMaxThreads, TpSetPoolMinThreads, TpAllocAlpcCompletion, TpAllocIoCompletion, TpStartAsyncIoOperation, RtlNtStatusToDosError, TpCallbackMayRunLong, TpWaitForAlpcCompletion, TpReleaseAlpcCompletion, TpWaitForIoCompletion, TpReleaseIoCompletion, TpWaitForTimer, TpReleaseTimer, TpSetWait, TpWaitForWait, TpReleaseWait, TpWaitForWork, TpReleaseWork, RtlValidRelativeSecurityDescriptor, EtwEventWrite, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwTraceMessage, EtwEventUnregister, EtwEventRegister, WinSqmIsOptedIn, WinSqmAddToStreamEx, WinSqmSetDWORD, WinSqmIncrementDWORD, RtlIpv4AddressToStringExW, RtlIpv4StringToAddressW, RtlIpv6AddressToStringExW, RtlIpv6StringToAddressW
powrprof.dll
PowerDeterminePlatformRole, GetPwrCapabilities
rpcrt4.dll
RpcServerInqBindings, RpcBindingToStringBindingW, RpcBindingVectorFree, RpcEpRegisterW, RpcServerRegisterIf, RpcServerRegisterIf2, RpcObjectSetType, RpcServerUseProtseqW, RpcServerUseProtseqEpA, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcBindingFree, RpcSmDestroyClientContext, I_RpcBindingInqTransportType, NdrAsyncClientCall, NdrClientCall2, RpcServerTestCancel, I_RpcExceptionFilter, RpcServerUnsubscribeForNotification, RpcServerSubscribeForNotification, RpcAsyncAbortCall, RpcSsContextLockExclusive, RpcStringFreeW, RpcRevertToSelfEx, RpcAsyncCompleteCall, RpcImpersonateClient, RpcRevertToSelf, RpcServerInqBindingHandle, I_RpcBindingIsClientLocal, I_RpcSessionStrictContextHandle, RpcRaiseException, NdrAsyncServerCall, NdrServerCall2, RpcMgmtSetServerStackSize, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcServerListen, RpcStringBindingParseW, RpcServerRegisterIf3, RpcBindingServerFromClient
slc.dll
SLGetWindowsInformationDWORD
user32.dll
SendNotifyMessageW, MsgWaitForMultipleObjects, TranslateMessage, DispatchMessageW, PeekMessageW, UnregisterDeviceNotification, RegisterDeviceNotificationW, RegisterPowerSettingNotification, UnregisterPowerSettingNotification
Export table
GetSpoolerTlsIndexes
PrvAbortPrinter
PrvAddFormW
PrvAddJobW
PrvAddMonitorW
PrvAddPerMachineConnectionW
PrvAddPortExW
PrvAddPortW
PrvAddPrinterConnectionW
PrvAddPrinterDriverExW
PrvAddPrinterDriverW
PrvAddPrinterExW
PrvAddPrinterW
PrvAddPrintProcessorW
PrvAddPrintProvidorW
PrvAdjustPointers
PrvAdjustPointersInStructuresArray
PrvAlignKMPtr
PrvAlignRpcPtr
PrvAllocSplStr
PrvAllowRemoteCalls
PrvAppendPrinterNotifyInfoData
PrvbGetDevModePerUser
PrvbSetDevModePerUser
PrvBuildOtherNamesFromMachineName
PrvCacheAddName
PrvCacheCreateAndAddNode
PrvCacheCreateAndAddNodeWithIPAddresses
PrvCacheDeleteNode
PrvCacheIsNameCluster
PrvCacheIsNameInNodeList
PrvCallDrvDevModeConversion
PrvCallRouterFindFirstPrinterChangeNotification
PrvCheckLocalCall
PrvClosePrinter
PrvClusterSplClose
PrvClusterSplIsAlive
PrvClusterSplOpen
PrvConfigurePortW
PrvCreatePrinterIC
PrvDeleteFormW
PrvDeleteMonitorW
PrvDeletePerMachineConnectionW
PrvDeletePortW
PrvDeletePrinter
PrvDeletePrinterConnectionW
PrvDeletePrinterDataExW
PrvDeletePrinterDataW
PrvDeletePrinterDriverExW
PrvDeletePrinterDriverW
PrvDeletePrinterIC
PrvDeletePrinterKeyW
PrvDeletePrintProcessorW
PrvDeletePrintProvidorW
PrvDllAllocSplMem
PrvDllAllocSplStr
PrvDllFreeSplMem
PrvDllFreeSplStr
PrvDllReallocSplMem
PrvDllReallocSplStr
PrvEndDocPrinter
PrvEndPagePrinter
PrvEnumFormsW
PrvEnumJobsW
PrvEnumMonitorsW
PrvEnumPerMachineConnectionsW
PrvEnumPortsW
PrvEnumPrinterDataExW
PrvEnumPrinterDataW
PrvEnumPrinterDriversW
PrvEnumPrinterKeyW
PrvEnumPrintersW
PrvEnumPrintProcessorDatatypesW
PrvEnumPrintProcessorsW
PrvFindClosePrinterChangeNotification
PrvFlushPrinter
PrvFormatPrinterForRegistryKey
PrvFormatRegistryKeyForPrinter
PrvFreeOtherNames
PrvGetFormW
PrvGetJobAttributes
PrvGetJobAttributesEx
PrvGetJobW
PrvGetNetworkId
PrvGetPrinterDataExW
PrvGetPrinterDataW
PrvGetPrinterDriverDirectoryW
PrvGetPrinterDriverExW
PrvGetPrinterDriverW
PrvGetPrinterW
PrvGetPrintProcessorDirectoryW
PrvGetServerPolicy
PrvGetShrinkedSize
PrvGetSpoolerTlsIndexes
PrvImpersonatePrinterClient
PrvInitializeRouter
PrvIsNamedPipeRpcCall
PrvIsNameTheLocalMachineOrAClusterSpooler
PrvMarshallDownStructure
PrvMarshallDownStructuresArray
PrvMarshallUpStructure
PrvMarshallUpStructuresArray
PrvMIDL_user_allocate
PrvMIDL_user_allocate1
PrvMIDL_user_free
PrvMIDL_user_free1
PrvOldGetPrinterDriverW
PrvOpenPrinter2W
PrvOpenPrinterExW
PrvOpenPrinterPort2W
PrvOpenPrinterW
PrvPackStrings
PrvPartialReplyPrinterChangeNotification
PrvPlayGdiScriptOnPrinterIC
PrvPrinterHandleRundown
PrvPrinterMessageBoxW
PrvProvidorFindClosePrinterChangeNotification
PrvProvidorFindFirstPrinterChangeNotification
PrvReadPrinter
PrvReallocSplMem
PrvReallocSplStr
PrvRemoteFindFirstPrinterChangeNotification
PrvReplyClosePrinter
PrvReplyOpenPrinter
PrvReplyPrinterChangeNotification
PrvReplyPrinterChangeNotificationEx
PrvReportJobProcessingProgress
PrvResetPrinterW
PrvRevertToPrinterSelf
PrvRouterAddPrinterConnection2
PrvRouterAllocBidiMem
PrvRouterAllocBidiResponseContainer
PrvRouterAllocPrinterNotifyInfo
PrvRouterBroadcastMessage
PrvRouterCorePrinterDriverInstalled
PrvRouterCreatePrintAsyncNotificationChannel
PrvRouterDeletePrinterDriverPackage
PrvRouterFindCompatibleDriver
PrvRouterFindFirstPrinterChangeNotification
PrvRouterFindNextPrinterChangeNotification
PrvRouterFreeBidiMem
PrvRouterFreeBidiResponseContainer
PrvRouterFreePrinterNotifyInfo
PrvRouterGetCorePrinterDrivers
PrvRouterGetPrintClassObject
PrvRouterGetPrinterDriverPackagePath
PrvRouterInstallPrinterDriverFromPackage
PrvRouterInternalGetPrinterDriver
PrvRouterRefreshPrinterChangeNotification
PrvRouterRegisterForPrintAsyncNotifications
PrvRouterReplyPrinter
PrvRouterSpoolerSetPolicy
PrvRouterUnregisterForPrintAsyncNotifications
PrvRouterUploadPrinterDriverPackage
PrvScheduleJob
PrvSeekPrinter
PrvSendRecvBidiData
PrvSetFormW
PrvSetJobW
PrvSetPortW
PrvSetPrinterDataExW
PrvSetPrinterDataW
PrvSetPrinterW
PrvSplCloseSpoolFileHandle
PrvSplCommitSpoolData
PrvSplDriverUnloadComplete
PrvSplGetClientUserHandle
PrvSplGetSpoolFileInfo
PrvSplGetUserSidStringFromToken
PrvSplInitializeWinSpoolDrv
PrvSplIsSessionZero
PrvSplIsUpgrade
PrvSplPowerEvent
PrvSplProcessPnPEvent
PrvSplProcessSessionEvent
PrvSplPromptUIInUsersSession
PrvSplQueryUserInfo
PrvSplReadPrinter
PrvSplRegisterForDeviceEvents
PrvSplRegisterForSessionEvents
PrvSplShutDownRouter
PrvSplUnregisterForDeviceEvents
PrvSplUnregisterForSessionEvents
PrvSpoolerFindClosePrinterChangeNotification
PrvSpoolerFindFirstPrinterChangeNotification
PrvSpoolerFindNextPrinterChangeNotification
PrvSpoolerFreePrinterNotifyInfo
PrvSpoolerHasInitialized
PrvSpoolerInit
PrvSpoolerRefreshPrinterChangeNotification
PrvStartDocPrinterW
PrvStartPagePrinter
PrvUndoAlignKMPtr
PrvUndoAlignRpcPtr
PrvUpdateBufferSize
PrvUpdatePrinterRegAll
PrvUpdatePrinterRegUser
PrvWaitForPrinterChange
PrvWaitForSpoolerInitialization
PrvWritePrinter
PrvXcvDataW
ServerGetPrintClassObject
ServerGetTlsBindingHandle
YAbortPrinter
YAddJob
YDriverUnloadComplete
YEndDocPrinter
YEndPagePrinter
YFlushPrinter
YGetPrinter
YGetPrinterDriver2
YGetPrinterDriverDirectory
YReadPrinter
YSeekPrinter
YSetJob
YSetPort
YSetPrinter
YSplReadPrinter
YStartDocPrinter
YStartPagePrinter
YWritePrinter

spoolsv.exe

Spooler SubSystem App by Microsoft

Remove spoolsv.exe
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   620b82889828fbe013ac6ad60f8e3fdb
SHA1:   cd1a07b0c3338f22fd7e9c72432fb12c01fabeb9
SHA256:   2e4f1f66b69de0a67e31294c45bcae8a7d27deb83428922270d0f856d9dea6b1
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

spoolsv.exe runs as a service under the name Spouleur d'impression (Spooler) with extensive SYSTEM privileges (full administrator access). This version is installed on Windows XP and is compiled as a 32 bit program.

DetailsDetails

File name:spoolsv.exe
Publisher:Microsoft Corporation
Product name:Spooler SubSystem App
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\spoolsv.exe
Original name:spoolsv.exe.mui
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:56.5 KB (57,856 bytes)
Build date:8/4/2004 2:14 PM
Digital DNA
Entropy:6.401537
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00534749%
0.028634%
Kernel CPU:0.00483881%
0.013761%
User CPU:0.00050868%
0.014873%
Kernel CPU time:771 ms/min
100,923,805ms/min
Memory
Private memory:3.12 MB
21.59 MB
Private (maximum):4.72 MB
Private (minimum):52 KB
Non-paged memory:3.12 MB
21.59 MB
Virtual memory:46.34 MB
140.96 MB
Virtual memory (peak):97.8 MB
169.69 MB
Working set:908 KB
18.61 MB
Working set (peak):4.76 MB
37.95 MB
Resource allocations
Threads:10
12
Handles:125
600
GUI GDI count:4
103
GUI USER count:4
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:C:\Windows\System32\spoolsv.exe
Owner:SYSTEM
Windows Service
Service name:Spooler
Display name:Spouleur d'impression
Description:“Charge les fichiers en mémoire pour une impression ultérieure”
Type:Win32OwnProcess, InteractiveProcess
Parent process:services.exe (Microsoft Windows Operating System by Microsoft)

ResourcesThreads

Averages
 
spoolsv.exe (main module)
Total CPU:0.00054071%
0.272967%
Kernel CPU:0.00044528%
0.107585%
User CPU:0.00009542%
0.165382%
Memory:64 KB
1.16 MB
localspl.dll
Total CPU:0.00025450%
Kernel CPU:0.00012725%
User CPU:0.00012725%
Memory:340 KB

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 59.50%
Windows 7 Ultimate 25.00%
Windows 7 Professional 12.00%
Windows 7 Home Basic 3.00%
Windows Vista Home Premium 0.50%

Distribution by countryDistribution by country

United States installs about 50.51% of Spooler SubSystem App.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 24.59%
Hewlett-Packard 21.31%
ASUS 14.75%
Acer 13.93%
Toshiba 13.11%
Sony 4.92%
GIGABYTE 2.46%
Alienware 1.64%
Samsung 1.64%
Lenovo 1.64%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE