From: "Des"
| I verified the original file dates for spoolsv.exe in the system32 folder and
| also the changed file date. They both match every other OS system file date
| for XP mce. Defender is only issuing the warning in the event log, not
| identifying it as any type virus or malware. The file is not listed in either
| allow or quarantine and I am sure I have never been asked noe have I cleared
| the Defender history file.
| Everything works fine, Event log just records the defender warning every
| minute or so... I'm thinking it has to do with permissions, maybe?
| --
| Des
The Spooler Service can become compromised and act "differently" by such malware as the
TDSS (TDL3) RootKit.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV -
http://www.pctipp.ch/downloads/dl/35905.asp