Roman,
Printer connected via LPT1 directly.
Running Norton Antivirus and Norton Firewall.
Yes it's XP+SP2+all updates.
I think here is the info you have asked for. Firstly HijackThis log file: -
--------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:54:32, on 25/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\PROGRA~1\NETSUP~1\client32.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\gearsec.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\office.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Mick\Tmp Downloads\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.demon.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali
Internet Access
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround
Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program
Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive
Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program
Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program
Files\CyberLink\PowerBackup\PBKScheduler.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec
Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec
Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program
Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton
SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program
Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office\OSA9.EXE
O4 - Global Startup: office.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://autoreg.virgin.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) -
https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1145530952312
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143882218453
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload)
-
https://www.trueshare.com/XUpload.ocx
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common
Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. -
C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation -
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) -
Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\NETSUP~1\client32.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner -
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -
C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program
Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
O23 - Service: GhostStartService - Symantec Corporation -
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec
Corporation - C:\Program Files\Norton SystemWorks\Norton
AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec
Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec
Corporation - C:\Program Files\Norton SystemWorks\Norton
Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - Unknown owner -
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation -
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program
Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems,
Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
-----------------------------------------------------------------------------------------
Now the modules loaded by spoolsv.exe: -
_________________________________________________________________
|Name| |Base| |Size| |InMem| |MM||Version|
|Description|
|Company| |Full Path|
AcGenral.DLL 6F880000 1,875,968 118,784 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Windows Compatibility DLL
Microsoft Corporation C:\WINDOWS\AppPatch\AcGenral.DLL
ADVAPI32.dll 77DD0000 634,880 102,400 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Advanced Windows 32 Base API
Microsoft Corporation C:\WINDOWS\system32\ADVAPI32.dll
comctl32.dll 5D090000 618,496 57,344 5.82
(xpsp_sp2_rtm.040803-2158) Common Controls Library
Microsoft Corporation C:\WINDOWS\system32\comctl32.dll
comctl32.dll 773D0000 1,056,768 159,744 6.0
(xpsp_sp2_rtm.040803-2158) User Experience Controls Library
Microsoft Corporation
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
GDI32.dll 77F10000 290,816 57,344 5.1.2600.2818
(xpsp_sp2_gdr.051228-1427) GDI Client DLL
Microsoft Corporation C:\WINDOWS\system32\GDI32.dll
kernel32.dll 7C800000 999,424 167,936 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Windows NT BASE API Client DLL
Microsoft Corporation C:\WINDOWS\system32\kernel32.dll
MSACM32.dll 77BE0000 86,016 36,864 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Microsoft ACM Audio Filter
Microsoft Corporation C:\WINDOWS\system32\MSACM32.dll
msvcrt.dll 77C10000 360,448 155,648 7.0.2600.2180
(xpsp_sp2_rtm.040803-2158) Windows NT CRT DLL
Microsoft Corporation C:\WINDOWS\system32\msvcrt.dll
ntdll.dll 7C900000 720,896 212,992 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) NT Layer DLL
Microsoft Corporation C:\WINDOWS\system32\ntdll.dll
ole32.dll 774E0000 1,298,432 69,632 5.1.2600.2726
(xpsp_sp2_gdr.050725-1528) Microsoft OLE for Windows
Microsoft Corporation C:\WINDOWS\system32\ole32.dll
OLEAUT32.dll 77120000 573,440 40,960 5.1.2600.2180
Microsoft Corporation C:\WINDOWS\system32\OLEAUT32.dll
RPCRT4.dll 77E70000 593,920 159,744 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Remote Procedure Call Runtime
Microsoft Corporation C:\WINDOWS\system32\RPCRT4.dll
serwvdrv.dll 5CD70000 28,672 24,576 5.1.2600.0
(xpclient.010817-1148) Unimodem Serial Wave driver
Microsoft Corporation C:\WINDOWS\system32\serwvdrv.dll
SHELL32.dll 7C9C0000 8,474,624 118,784 6.00.2900.2869
(xpsp_sp2_gdr.060316-1512) Windows Shell Common Dll
Microsoft Corporation C:\WINDOWS\system32\SHELL32.dll
ShimEng.dll 5CB70000 155,648 77,824 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Shim Engine DLL
Microsoft Corporation C:\WINDOWS\system32\ShimEng.dll
SHLWAPI.dll 77F60000 483,328 57,344 6.00.2900.2861
(xpsp_sp2_gdr.060303-1517) Shell Light-weight Utility Library
Microsoft Corporation C:\WINDOWS\system32\SHLWAPI.dll
spoolsv.exe 01000000 65,536 36,864 5.1.2600.2696
(xpsp_sp2_gdr.050610-1519) Spooler SubSystem App
Microsoft Corporation C:\WINDOWS\system32\spoolsv.exe
umdmxfrm.dll 5B0A0000 28,672 16,384 5.1.2600.0
(xpclient.010817-1148) Unimodem Tranform Module
Microsoft Corporation C:\WINDOWS\system32\umdmxfrm.dll
USER32.dll 77D40000 589,824 77,824 5.1.2600.2622
(xpsp_sp2_gdr.050301-1519) Windows XP USER API Client DLL
Microsoft Corporation C:\WINDOWS\system32\USER32.dll
USERENV.dll 769C0000 733,184 53,248 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Userenv
Microsoft Corporation C:\WINDOWS\system32\USERENV.dll
UxTheme.dll 5AD70000 229,376 36,864 6.00.2900.2180
(xpsp_sp2_rtm.040803-2158) Microsoft UxTheme Library
Microsoft Corporation C:\WINDOWS\system32\UxTheme.dll
VERSION.dll 77C00000 32,768 24,576 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) Version Checking and File Installation
Libraries Microsoft Corporation C:\WINDOWS\system32\VERSION.dll
WINMM.dll 76B40000 184,320 61,440 5.1.2600.2180
(xpsp_sp2_rtm.040803-2158) MCI API DLL
Microsoft Corporation C:\WINDOWS\system32\WINMM.dll
__________________________________________________________________
Hope this helps and many thanks.
Mick