What Is Spool11.exe?

It does this by creating a directory called RECYCLER in the root of the removable drive. Removable Drives Worm:Win32/Slenfbot may attempt to spread via removable drives, except drives A and B.

The worm also contains backdoor functionality that allows unauthorized access to an affected machine. The default installation location for the System folder for Windows 2000 and NT is C:\Winnt\System32; and for XP and Vista is C:\Windows\System32. The worm makes a further registry modification that

When the attacker orders the worm to spread via MSN Messenger, they must provide the following three parameters: A URL containing a list of possible messages to send, along with the

Files contained in this directory may not be reposted on other BBSs or information services without express permission from Circuit Cellar Inc. The worm chooses from this list at random.

The worm creates a ZIP archive containing a copy of itself in the temporary folder with this name.

This consists of programs that are misleading, harmful, or undesirable. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. Installation When executed, Worm:Win32/Slenfbot.KF copies itself to the as "spool11.exe" and sets the attributes for this copy to read only, hidden and system. A file name for a ZIP archive.

This file has been identified as a program that is undesirable to have running on your computer. This worm does not spread automatically upon installation, but must be ordered to spread by a remote attacker. Add comment Your details Name: Email: Receive notification emails when new replies are received on this page? The intention of this is obviously to delete the original copy of the worm that was received via Messenger.   Modifies System Settings Slenfbot deletes the following registry keys (and any

The worm also contains backdoor functionality that allows unauthorized access to an affected machine. The worm places this file in the ZIP archive, which it sends to MSN Messenger contacts, in place of itself.   Modifies Hosts File Slenfbot replaces \drivers\etc\hosts with a file What to do now Manual removal is not recommended for this threat. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL.

It modifies the registry to run this copy at each Windows start:   Adds value: "Microsoft Spool 11 Service"With data: "spool11.exe"To subkey: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run   Note - refers to a Do you have a problem with spoolsvr.exe? This code is posted as a convenience to Circuit Cellar readers. If the mutex does not exist, it assumes the worm process has been terminated and attempts to run it again.

HijackThis Category O4 Entry Note %System% is a variable that refers to the Windows System folder. After the blank lines it writes several entries to direct the following anti-virus and security related domains to localhost (   bbs.360safe.com                       blog.hispasec.com                     blog.threatfire.com                   customer.symantec.com                 discussions.virtualdr.com             download.mcafee.com                   file.ikaka.com                        forum.piriform.com                    forum.securitycadets.com              forum.tweaks.com

Top Threat behavior Worm:Win32/Slenfbot.KF is a worm that can spread via MSN Messenger, and may spread via removable drives. Add comment Your details Name: Email: Receive notification emails when new replies are received on this page? rated this process as unknownVisitorAnyone have ANY info? Top Follow:I want to...Get helpRemove difficult malwareAvoid tech support phone scamsSee and search the latest threatsFind answers to other problemsFix my softwareFix updates and solve other problemsSee common error codesDownload and

