Spooler Sub System App jus started to dial out, forewarned by 'zone alarm', and ran 'The Cleaner', 'Pest Patrol' and 'Spy Bot' and was unable to locate anything.
Have auto update and register disabled for my printer.
Unable to locate anything related on HP web site.
Uninstalled both printer and software, then re-installed from HP site and hooked printer back on. No avail.
Nothing on MS Knowledge Base that I could find (maybe in another location).
Spoosv.exe still wants to connect at initial boot up.
Had installed 'Lime Wire' on the 23rd of Feburary and thinking this might be related. I did not install any of the 'included' adware or spy wear.
Short of doing a 'system restore', I'm at a loss of what else to do.
Here is a copy of my startup listings.
Any help would be appreciated.
Thanx.
StartupList report, 2/28/2003, 11:45:26 AM
StartupList version: 1.52
Started from : C:\unzipped\startuplist152\StartupList.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2600.0000)
* Using default options
==================================================
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\logonui.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\PestPatrol\PPControl.exe
D:\PROGRA~1\PESTPA~1\PPMemCheck.exe
D:\PROGRA~1\PESTPA~1\CookiePatrol.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\DAP\DAP.EXE
C:\unzipped\startuplist152\StartupList.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[D:\Documents and Settings\All Users\Start Menu\Programs\Startup]
ZoneAlarm.lnk = D:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = D:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
QuickTime Task = "D:\Program Files\QuickTime\qttask.exe" -atboottime
PestPatrol Control Center = D:\Program Files\PestPatrol\PPControl.exe
PPMemCheck = D:\PROGRA~1\PESTPA~1\PPMemCheck.exe
CookiePatrol = D:\PROGRA~1\PESTPA~1\CookiePatrol.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
RegisterDropHandler = D:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = D:\WINDOWS\System32\ctfmon.exe
Microsoft Works Update Detection = D:\Program Files\Microsoft Works\WkDetect.exe
--------------------------------------------------
Shell & screensaver key from D:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - D:\Program Files\DAP\DAPBHO.dll - {0000CC75-ACF3-4cac-A0A9-DD3868E06852}
(no name) - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Yahoo! Companion BHO - D:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll - {13F537F0-AF09-11d6-9029-0002B31F9E59}
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave ActiveX Control]
InProcServer32 = D:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE =
[OPUCatalog Class]
InProcServer32 = D:\WINDOWS\System32\opuc.dll
CODEBASE =
[Microsoft Office XP Professional Step by Step Interactive]
InProcServer32 = D:\WINDOWS\Downloaded Program Files\mitm0026.dll
CODEBASE = file://D:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab
[AnarkClient Class]
InProcServer32 = D:\Program Files\Anark\Client\AMClient.dll
CODEBASE =
[Update Class]
InProcServer32 = D:\WINDOWS\System32\iuctl.dll
CODEBASE =
[Shockwave Flash Object]
InProcServer32 = D:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE =
[Microsoft Office Tools on the Web Control]
InProcServer32 = D:\WINDOWS\Downloaded Program Files\OUTC.DLL
CODEBASE =
[MSN Chat Control 4.5]
InProcServer32 = D:\WINDOWS\Downloaded Program Files\MSNChat45.ocx
CODEBASE =
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: D:\WINDOWS\system32\SHELL32.dll
CDBurn: D:\WINDOWS\system32\SHELL32.dll
WebCheck: D:\WINDOWS\System32\webcheck.dll
SysTray: D:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 5,809 bytes
Report generated in 0.172 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Have auto update and register disabled for my printer.
Unable to locate anything related on HP web site.
Uninstalled both printer and software, then re-installed from HP site and hooked printer back on. No avail.
Nothing on MS Knowledge Base that I could find (maybe in another location).
Spoosv.exe still wants to connect at initial boot up.
Had installed 'Lime Wire' on the 23rd of Feburary and thinking this might be related. I did not install any of the 'included' adware or spy wear.
Short of doing a 'system restore', I'm at a loss of what else to do.
Here is a copy of my startup listings.
Any help would be appreciated.
Thanx.
StartupList report, 2/28/2003, 11:45:26 AM
StartupList version: 1.52
Started from : C:\unzipped\startuplist152\StartupList.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2600.0000)
* Using default options
==================================================
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\logonui.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\PestPatrol\PPControl.exe
D:\PROGRA~1\PESTPA~1\PPMemCheck.exe
D:\PROGRA~1\PESTPA~1\CookiePatrol.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\DAP\DAP.EXE
C:\unzipped\startuplist152\StartupList.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[D:\Documents and Settings\All Users\Start Menu\Programs\Startup]
ZoneAlarm.lnk = D:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = D:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
QuickTime Task = "D:\Program Files\QuickTime\qttask.exe" -atboottime
PestPatrol Control Center = D:\Program Files\PestPatrol\PPControl.exe
PPMemCheck = D:\PROGRA~1\PESTPA~1\PPMemCheck.exe
CookiePatrol = D:\PROGRA~1\PESTPA~1\CookiePatrol.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
RegisterDropHandler = D:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = D:\WINDOWS\System32\ctfmon.exe
Microsoft Works Update Detection = D:\Program Files\Microsoft Works\WkDetect.exe
--------------------------------------------------
Shell & screensaver key from D:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - D:\Program Files\DAP\DAPBHO.dll - {0000CC75-ACF3-4cac-A0A9-DD3868E06852}
(no name) - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Yahoo! Companion BHO - D:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll - {13F537F0-AF09-11d6-9029-0002B31F9E59}
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave ActiveX Control]
InProcServer32 = D:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE =
[OPUCatalog Class]
InProcServer32 = D:\WINDOWS\System32\opuc.dll
CODEBASE =
[Microsoft Office XP Professional Step by Step Interactive]
InProcServer32 = D:\WINDOWS\Downloaded Program Files\mitm0026.dll
CODEBASE = file://D:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab
[AnarkClient Class]
InProcServer32 = D:\Program Files\Anark\Client\AMClient.dll
CODEBASE =
[Update Class]
InProcServer32 = D:\WINDOWS\System32\iuctl.dll
CODEBASE =
[Shockwave Flash Object]
InProcServer32 = D:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE =
[Microsoft Office Tools on the Web Control]
InProcServer32 = D:\WINDOWS\Downloaded Program Files\OUTC.DLL
CODEBASE =
[MSN Chat Control 4.5]
InProcServer32 = D:\WINDOWS\Downloaded Program Files\MSNChat45.ocx
CODEBASE =
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: D:\WINDOWS\system32\SHELL32.dll
CDBurn: D:\WINDOWS\system32\SHELL32.dll
WebCheck: D:\WINDOWS\System32\webcheck.dll
SysTray: D:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 5,809 bytes
Report generated in 0.172 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only