Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 3.88%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.06%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.19%
6.3.9431.0 (winmain_bluemp.130615-1214) 0.02%
6.2.9200.16384 (win8_rtm.120725-1247) 2.05%
6.2.9200.16384 (win8_rtm.120725-1247) 11.99%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8400.0 (winmain_win8rc.120518-1423) 0.06%
6.2.8250.0 (winmain_win8beta.120217-1520) 0.02%
6.2.8102.0 (winmain_win8m3.110823-1455) 0.06%
6.1.7600.16385 (win7_rtm.090713-1255) 1.11%
6.1.7600.16385 (win7_rtm.090713-1255) 2.26%
6.1.7600.16385 (win7_rtm.090713-1255) 3.11%
6.1.7600.16385 (win7_rtm.090713-1255) 31.04%
6.1.7600.16385 (win7_rtm.090713-1255) 4.56%
6.1.7600.16385 (win7_rtm.090713-1255) 11.42%
6.1.7600.16385 (win7_rtm.090713-1255) 1.43%
6.1.7600.16385 (win7_rtm.090713-1255) 1.64%
6.1.7600.16385 (win7_rtm.090713-1255) 0.87%
6.1.7600.16385 (win7_rtm.090713-1255) 0.81%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
6.1.7600.16385 (win7_rtm.090713-1255) 0.02%
View more

Relationships

Parent process
Child processes

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegisterServiceCtrlHandlerExW, RegCloseKey, RegOpenKeyExW, RegDisablePredefinedCache, RegQueryValueExW, ConvertStringSecurityDescriptorToSecurityDescriptorW, SetServiceStatus, StartServiceCtrlDispatcherW, SetThreadToken, OpenThreadToken, OpenProcessToken
api-ms-win-core-console-l1-1-0.dll
SetConsoleCtrlHandler
api-ms-win-core-debug-l1-1-1.dll
IsDebuggerPresent, OutputDebugStringW, DebugBreak
api-ms-win-core-errorhandling-l1-1-1.dll
SetErrorMode, GetErrorMode, SetUnhandledExceptionFilter, GetLastError, RaiseException, UnhandledExceptionFilter, SetLastError
api-ms-win-core-file-l1-2-0.dll
GetTempFileNameW, DeleteFileW, CreateFileW, ReadFile
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll
HeapSetInformation, HeapDestroy, HeapCreate, GetProcessHeap
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedDecrement, InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-1.dll
DisableThreadLibraryCalls, LoadLibraryExW, GetModuleHandleW, FreeLibrary, GetModuleHandleA
api-ms-win-core-localregistry-l1-1-0.dll
RegQueryInfoKeyW, RegGetKeySecurity, RegSetKeySecurity, RegEnumValueW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegEnumKeyExW, RegDeleteKeyExW, RegOpenCurrentUser, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegGetValueW
api-ms-win-core-processthreads-l1-1-1.dll
ExitProcess, GetCurrentThread, GetCurrentProcessId, GetCurrentThreadId, SetThreadToken, TlsFree, ExitThread, TerminateProcess, OpenProcessToken, SetPriorityClass, GetCurrentProcess, TlsGetValue, OpenProcess, CreateProcessAsUserW, OpenThreadToken, TlsSetValue, TlsAlloc, CreateThread
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegDeleteTreeW, RegSetValueExW, RegGetKeySecurity, RegEnumValueW, RegSetKeySecurity, RegGetValueW, RegDeleteKeyExW, RegOpenCurrentUser, RegQueryValueExW, RegOpenKeyExW, RegDisablePredefinedCacheEx, RegQueryInfoKeyW, RegCloseKey, RegCreateKeyExW, RegDeleteValueW, RegEnumKeyExW
api-ms-win-core-string-l1-1-0.dll
CompareStringW
api-ms-win-core-synch-l1-2-0.dll
OpenEventW, AcquireSRWLockShared, ReleaseSRWLockShared, CreateMutexW, InitializeCriticalSection, WaitForSingleObject, SetEvent, EnterCriticalSection, LeaveCriticalSection, CreateEventW, ReleaseSRWLockExclusive, ReleaseMutex, InitializeSRWLock, AcquireSRWLockExclusive, InitializeCriticalSectionAndSpinCount, Sleep
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTime, GetTickCount, GetSystemWindowsDirectoryW, GetSystemTimeAsFileTime, GetVersionExW
api-ms-win-eventing-classicprovider-l1-1-0.dll
UnregisterTraceGuids, TraceEvent, RegisterTraceGuidsW, GetTraceLoggerHandle
api-ms-win-power-base-l1-1-0.dll
GetPwrCapabilities
api-ms-win-security-base-l1-2-0.dll
DuplicateToken, SetTokenInformation, IsWellKnownSid, GetSecurityDescriptorDacl, AddAccessDeniedAceEx, GetLengthSid, ImpersonateLoggedOnUser, AddAccessAllowedAceEx, CreateWellKnownSid, GetTokenInformation, GetSidSubAuthority, GetSidSubAuthorityCount, EqualSid, InitializeSecurityDescriptor, DuplicateTokenEx, SetSecurityDescriptorDacl, GetAclInformation, AddAce, CopySid, GetAce, AllocateAndInitializeSid, FreeSid, RevertToSelf, CheckTokenMembership, InitializeAcl
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW
api-ms-win-service-core-l1-1-1.dll
StartServiceCtrlDispatcherW, SetServiceStatus, RegisterServiceCtrlHandlerExW
dnsapi.dll
DnsQuery_W, DnsFree
kernel32.dll
lstrcmpiW, QueueUserWorkItem, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, AcquireSRWLockShared, ReleaseSRWLockShared, InitializeSRWLock, GetSystemTime, MoveFileExW, IsDebuggerPresent, AddVectoredExceptionHandler, DeleteFileW, GetCurrentProcessId, GetComputerNameW, WideCharToMultiByte, lstrlenW, LoadLibraryW, GetCurrentThread, LoadLibraryExW, SetErrorMode, SetPriorityClass, HeapDestroy, TlsFree, DisableThreadLibraryCalls, HeapCreate, TlsGetValue, SetConsoleCtrlHandler, InitializeCriticalSection, DuplicateHandle, ReadFile, CreateFileW, GetTempFileNameW, CompareStringW, ExitThread, GetLastError, CloseHandle, WaitForSingleObject, GetModuleHandleW, CreateEventW, CreateThread, GetTickCount, ExitProcess, Sleep, OpenEventW, HeapSetInformation, GetProcessHeap, InitializeCriticalSectionAndSpinCount, TlsAlloc, GetVersionExW, LeaveCriticalSection, EnterCriticalSection, SetEvent, SetLastError, TlsSetValue, InterlockedDecrement, OpenProcess, InterlockedIncrement, RaiseException, GetProcAddress, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, InterlockedExchange, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter, GetCurrentThreadId, DebugBreak, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetThreadpoolTimer, HeapAlloc, HeapFree, DeleteCriticalSection, ResetEvent, LocalFree, LoadLibraryA, LocalAlloc, GetModuleHandleExW, CloseThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CreateThreadpoolTimer, ResolveDelayLoadedAPI, GetTickCount64, OutputDebugStringW
msvcrt.dll
DllMain
ntdll.dll
RtlIpv6AddressToStringW, RtlIpv4AddressToStringW, NtClose, NtOpenThreadToken, NtSetInformationThread, NtOpenProcessToken, RtlReportException, EtwEventEnabled, TpReleasePool, TpAllocTimer, TpSetTimer, TpAllocWork, TpPostWork, TpSimpleTryPost, TpAllocWait, TpAllocPool, TpSetPoolMaxThreads, TpSetPoolMinThreads, TpAllocAlpcCompletion, TpAllocIoCompletion, TpStartAsyncIoOperation, RtlNtStatusToDosError, TpCallbackMayRunLong, TpWaitForAlpcCompletion, TpReleaseAlpcCompletion, TpWaitForIoCompletion, TpReleaseIoCompletion, TpWaitForTimer, TpReleaseTimer, TpSetWait, TpWaitForWait, TpReleaseWait, TpWaitForWork, TpReleaseWork, RtlValidRelativeSecurityDescriptor, EtwEventWrite, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwTraceMessage, EtwEventUnregister, EtwEventRegister, WinSqmIsOptedIn, WinSqmAddToStreamEx, WinSqmSetDWORD, WinSqmIncrementDWORD, RtlIpv4AddressToStringExW, RtlIpv4StringToAddressW, RtlIpv6AddressToStringExW, RtlIpv6StringToAddressW
powrprof.dll
PowerDeterminePlatformRole, GetPwrCapabilities
rpcrt4.dll
RpcServerInqBindings, RpcBindingToStringBindingW, RpcBindingVectorFree, RpcEpRegisterW, RpcServerRegisterIf, RpcServerRegisterIf2, RpcObjectSetType, RpcServerUseProtseqW, RpcServerUseProtseqEpA, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcBindingFree, RpcSmDestroyClientContext, I_RpcBindingInqTransportType, NdrAsyncClientCall, NdrClientCall2, RpcServerTestCancel, I_RpcExceptionFilter, RpcServerUnsubscribeForNotification, RpcServerSubscribeForNotification, RpcAsyncAbortCall, RpcSsContextLockExclusive, RpcStringFreeW, RpcRevertToSelfEx, RpcAsyncCompleteCall, RpcImpersonateClient, RpcRevertToSelf, RpcServerInqBindingHandle, I_RpcBindingIsClientLocal, I_RpcSessionStrictContextHandle, RpcRaiseException, NdrAsyncServerCall, NdrServerCall2, RpcMgmtSetServerStackSize, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcServerListen, RpcStringBindingParseW, RpcServerRegisterIf3, RpcBindingServerFromClient
slc.dll
SLGetWindowsInformationDWORD
user32.dll
SendNotifyMessageW, MsgWaitForMultipleObjects, TranslateMessage, DispatchMessageW, PeekMessageW, UnregisterDeviceNotification, RegisterDeviceNotificationW, RegisterPowerSettingNotification, UnregisterPowerSettingNotification
Export table
GetSpoolerTlsIndexes
PrvAbortPrinter
PrvAddFormW
PrvAddJobW
PrvAddMonitorW
PrvAddPerMachineConnectionW
PrvAddPortExW
PrvAddPortW
PrvAddPrinterConnectionW
PrvAddPrinterDriverExW
PrvAddPrinterDriverW
PrvAddPrinterExW
PrvAddPrinterW
PrvAddPrintProcessorW
PrvAddPrintProvidorW
PrvAdjustPointers
PrvAdjustPointersInStructuresArray
PrvAlignKMPtr
PrvAlignRpcPtr
PrvAllocSplStr
PrvAllowRemoteCalls
PrvAppendPrinterNotifyInfoData
PrvbGetDevModePerUser
PrvbSetDevModePerUser
PrvBuildOtherNamesFromMachineName
PrvCacheAddName
PrvCacheCreateAndAddNode
PrvCacheCreateAndAddNodeWithIPAddresses
PrvCacheDeleteNode
PrvCacheIsNameCluster
PrvCacheIsNameInNodeList
PrvCallDrvDevModeConversion
PrvCallRouterFindFirstPrinterChangeNotification
PrvCheckLocalCall
PrvClosePrinter
PrvClusterSplClose
PrvClusterSplIsAlive
PrvClusterSplOpen
PrvConfigurePortW
PrvCreatePrinterIC
PrvDeleteFormW
PrvDeleteMonitorW
PrvDeletePerMachineConnectionW
PrvDeletePortW
PrvDeletePrinter
PrvDeletePrinterConnectionW
PrvDeletePrinterDataExW
PrvDeletePrinterDataW
PrvDeletePrinterDriverExW
PrvDeletePrinterDriverW
PrvDeletePrinterIC
PrvDeletePrinterKeyW
PrvDeletePrintProcessorW
PrvDeletePrintProvidorW
PrvDllAllocSplMem
PrvDllAllocSplStr
PrvDllFreeSplMem
PrvDllFreeSplStr
PrvDllReallocSplMem
PrvDllReallocSplStr
PrvEndDocPrinter
PrvEndPagePrinter
PrvEnumFormsW
PrvEnumJobsW
PrvEnumMonitorsW
PrvEnumPerMachineConnectionsW
PrvEnumPortsW
PrvEnumPrinterDataExW
PrvEnumPrinterDataW
PrvEnumPrinterDriversW
PrvEnumPrinterKeyW
PrvEnumPrintersW
PrvEnumPrintProcessorDatatypesW
PrvEnumPrintProcessorsW
PrvFindClosePrinterChangeNotification
PrvFlushPrinter
PrvFormatPrinterForRegistryKey
PrvFormatRegistryKeyForPrinter
PrvFreeOtherNames
PrvGetFormW
PrvGetJobAttributes
PrvGetJobAttributesEx
PrvGetJobW
PrvGetNetworkId
PrvGetPrinterDataExW
PrvGetPrinterDataW
PrvGetPrinterDriverDirectoryW
PrvGetPrinterDriverExW
PrvGetPrinterDriverW
PrvGetPrinterW
PrvGetPrintProcessorDirectoryW
PrvGetServerPolicy
PrvGetShrinkedSize
PrvGetSpoolerTlsIndexes
PrvImpersonatePrinterClient
PrvInitializeRouter
PrvIsNamedPipeRpcCall
PrvIsNameTheLocalMachineOrAClusterSpooler
PrvMarshallDownStructure
PrvMarshallDownStructuresArray
PrvMarshallUpStructure
PrvMarshallUpStructuresArray
PrvMIDL_user_allocate
PrvMIDL_user_allocate1
PrvMIDL_user_free
PrvMIDL_user_free1
PrvOldGetPrinterDriverW
PrvOpenPrinter2W
PrvOpenPrinterExW
PrvOpenPrinterPort2W
PrvOpenPrinterW
PrvPackStrings
PrvPartialReplyPrinterChangeNotification
PrvPlayGdiScriptOnPrinterIC
PrvPrinterHandleRundown
PrvPrinterMessageBoxW
PrvProvidorFindClosePrinterChangeNotification
PrvProvidorFindFirstPrinterChangeNotification
PrvReadPrinter
PrvReallocSplMem
PrvReallocSplStr
PrvRemoteFindFirstPrinterChangeNotification
PrvReplyClosePrinter
PrvReplyOpenPrinter
PrvReplyPrinterChangeNotification
PrvReplyPrinterChangeNotificationEx
PrvReportJobProcessingProgress
PrvResetPrinterW
PrvRevertToPrinterSelf
PrvRouterAddPrinterConnection2
PrvRouterAllocBidiMem
PrvRouterAllocBidiResponseContainer
PrvRouterAllocPrinterNotifyInfo
PrvRouterBroadcastMessage
PrvRouterCorePrinterDriverInstalled
PrvRouterCreatePrintAsyncNotificationChannel
PrvRouterDeletePrinterDriverPackage
PrvRouterFindCompatibleDriver
PrvRouterFindFirstPrinterChangeNotification
PrvRouterFindNextPrinterChangeNotification
PrvRouterFreeBidiMem
PrvRouterFreeBidiResponseContainer
PrvRouterFreePrinterNotifyInfo
PrvRouterGetCorePrinterDrivers
PrvRouterGetPrintClassObject
PrvRouterGetPrinterDriverPackagePath
PrvRouterInstallPrinterDriverFromPackage
PrvRouterInternalGetPrinterDriver
PrvRouterRefreshPrinterChangeNotification
PrvRouterRegisterForPrintAsyncNotifications
PrvRouterReplyPrinter
PrvRouterSpoolerSetPolicy
PrvRouterUnregisterForPrintAsyncNotifications
PrvRouterUploadPrinterDriverPackage
PrvScheduleJob
PrvSeekPrinter
PrvSendRecvBidiData
PrvSetFormW
PrvSetJobW
PrvSetPortW
PrvSetPrinterDataExW
PrvSetPrinterDataW
PrvSetPrinterW
PrvSplCloseSpoolFileHandle
PrvSplCommitSpoolData
PrvSplDriverUnloadComplete
PrvSplGetClientUserHandle
PrvSplGetSpoolFileInfo
PrvSplGetUserSidStringFromToken
PrvSplInitializeWinSpoolDrv
PrvSplIsSessionZero
PrvSplIsUpgrade
PrvSplPowerEvent
PrvSplProcessPnPEvent
PrvSplProcessSessionEvent
PrvSplPromptUIInUsersSession
PrvSplQueryUserInfo
PrvSplReadPrinter
PrvSplRegisterForDeviceEvents
PrvSplRegisterForSessionEvents
PrvSplShutDownRouter
PrvSplUnregisterForDeviceEvents
PrvSplUnregisterForSessionEvents
PrvSpoolerFindClosePrinterChangeNotification
PrvSpoolerFindFirstPrinterChangeNotification
PrvSpoolerFindNextPrinterChangeNotification
PrvSpoolerFreePrinterNotifyInfo
PrvSpoolerHasInitialized
PrvSpoolerInit
PrvSpoolerRefreshPrinterChangeNotification
PrvStartDocPrinterW
PrvStartPagePrinter
PrvUndoAlignKMPtr
PrvUndoAlignRpcPtr
PrvUpdateBufferSize
PrvUpdatePrinterRegAll
PrvUpdatePrinterRegUser
PrvWaitForPrinterChange
PrvWaitForSpoolerInitialization
PrvWritePrinter
PrvXcvDataW
ServerGetPrintClassObject
ServerGetTlsBindingHandle
YAbortPrinter
YAddJob
YDriverUnloadComplete
YEndDocPrinter
YEndPagePrinter
YFlushPrinter
YGetPrinter
YGetPrinterDriver2
YGetPrinterDriverDirectory
YReadPrinter
YSeekPrinter
YSetJob
YSetPort
YSetPrinter
YSplReadPrinter
YStartDocPrinter
YStartPagePrinter
YWritePrinter

spoolsv.exe

Spooler SubSystem App by Microsoft

Remove spoolsv.exe
Version:   6.0.6000.16386 (vista_rtm.061101-2205)
MD5:   8554097e5136c3bf9f69fe578a1b35f4
SHA1:   1109a90367f656b75c07dd86bf7b29e3a5bb5111
SHA256:   2578545cfd647fb18f217b33c8cb4f0184a35f548659494056e455020cc15fb0
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

spoolsv.exe runs as a service under the name Spouleur d'impression (Spooler) with extensive SYSTEM privileges (full administrator access). This version is designed to run on Windows Vista and is compiled as a 32 bit program.

DetailsDetails

File name:spoolsv.exe
Publisher:Microsoft Corporation
Product name:Spooler SubSystem App
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\spoolsv.exe
Original name:spoolsv.exe.mui
File version:6.0.6000.16386 (vista_rtm.061101-2205)
Product version:6.0.6000.16386
Size:125 KB (128,000 bytes)
Digital DNA
Entropy:6.401537
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Services
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
Network connections
  • [UDP] listens on port 54394
  • [UDP] listens on port 64430
  • [UDP] listens on port 65043
  • [UDP] listens on port 65441
  • [UDP] listens on port 61475
  • [UDP] listens on port 49152
  • [UDP] listens on port 64508
  • [UDP] listens on port 49154
  • [UDP] listens on port 61386
  • [UDP] listens on port 64706
  • [UDP] listens on port 60584
  • [UDP] listens on port 50101

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00347913%
    0.028634%
    Kernel CPU:0.00249768%
    0.013761%
    User CPU:0.00098144%
    0.014873%
    Kernel CPU time:8,505,918 ms/min
    100,923,805ms/min
    User CPU time:0 ms/min
    0 ms/min
    CPU cycles:1,408,162/sec
    17,470,203/sec
    Context switches:2/sec
    284/sec
    Memory
    Private memory:7.9 MB
    21.59 MB
    Private (maximum):14.87 MB
    Private (minimum):5.9 MB
    Non-paged memory:7.9 MB
    21.59 MB
    Virtual memory:100.82 MB
    140.96 MB
    Virtual memory (peak):114.1 MB
    169.69 MB
    Working set:8.02 MB
    18.61 MB
    Working set (peak):21.7 MB
    37.95 MB
    Page faults:243,141/min
    2,039/min
    I/O
    I/O read transfer:3.92 KB/sec
    1.02 MB/min
    I/O read operations:3/sec
    343/min
    I/O write transfer:4.19 KB/sec
    274.99 KB/min
    I/O write operations:3/sec
    227/min
    I/O other transfer:1.29 KB/sec
    448.09 KB/min
    I/O other operations:112/sec
    1,671/min
    Resource allocations
    Threads:18
    12
    Handles:353
    600

    BehaviorsProcess properties

    Integrety level:System
    Platform:32-bit
    Command line:C:\Windows\System32\spoolsv.exe
    Owner:SYSTEM
    Windows Service
    Service name:Spooler
    Display name:Spouleur d'impression
    Description:“Charge les fichiers en mémoire pour une impression ultérieure”
    Type:Win32OwnProcess, InteractiveProcess
    Parent process:services.exe (Services and Controller app by Microsoft)

    ResourcesThreads

    Averages
     
    RPCRT4.dll
    Total CPU:0.38022324%
    0.272967%
    Kernel CPU:0.29083885%
    0.107585%
    User CPU:0.08938439%
    0.165382%
    CPU cycles:6,079,651/sec
    5,741,424/sec
    Memory:776 KB
    1.16 MB
    ntdll.dll
    Total CPU:0.00235444%
    Kernel CPU:0.00229479%
    User CPU:0.00005965%
    CPU cycles:28,772/sec
    Memory:1.16 MB
    spoolsv.exe (main module)
    Total CPU:0.00199741%
    Kernel CPU:0.00166154%
    User CPU:0.00033587%
    CPU cycles:37,230/sec
    Memory:132 KB
    ADVAPI32.dll
    Total CPU:0.00028329%
    Kernel CPU:0.00023783%
    User CPU:0.00004546%
    CPU cycles:4,498/sec
    Memory:792 KB
    msvcrt.dll (Windows NT CRT DLL by Microsoft)
    Total CPU:0.00020030%
    Kernel CPU:0.00010960%
    User CPU:0.00009070%
    CPU cycles:14,733/sec
    Memory:680 KB
    WSDMon.dll
    Total CPU:0.00017231%
    Kernel CPU:0.00013076%
    User CPU:0.00004155%
    CPU cycles:1,454/sec
    Memory:180 KB
    usbmon.dll
    Total CPU:0.00012354%
    Kernel CPU:0.00010432%
    User CPU:0.00001923%
    CPU cycles:1,061/sec
    Memory:44 KB
    tcpmon.dll
    Total CPU:0.00011521%
    Kernel CPU:0.00009149%
    User CPU:0.00002372%
    CPU cycles:4,092/sec
    Memory:144 KB
    FunDisc.dll
    Total CPU:0.00006608%
    Kernel CPU:0.00002691%
    User CPU:0.00003917%
    CPU cycles:932/sec
    Memory:160 KB
    localspl.dll
    Total CPU:0.00005244%
    Kernel CPU:0.00003460%
    User CPU:0.00001783%
    CPU cycles:1,323/sec
    Memory:620 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 59.50%
    Windows 7 Ultimate 25.00%
    Windows 7 Professional 12.00%
    Windows 7 Home Basic 3.00%
    Windows Vista Home Premium 0.50%

    Distribution by countryDistribution by country

    United States installs about 50.51% of Spooler SubSystem App.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 24.59%
    Hewlett-Packard 21.31%
    ASUS 14.75%
    Acer 13.93%
    Toshiba 13.11%
    Sony 4.92%
    GIGABYTE 2.46%
    Alienware 1.64%
    Samsung 1.64%
    Lenovo 1.64%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE