This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Problems with Print Server

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a box running Windows Server 2003 SP2 with all the latest updates. I am using this box as a Printer Server. I have 15 printers loaded on this box. I am running Sophos Anti Virus along with regular scans with MalWareBytes. On Tuesday of this week Sophos completed its daily scan showing the W32/Magistr-B worm in a folder containing the print drivers for my Kyocera multi-functionals. Sophos reported this worm had been cleaned up. However, we have found on 3 of the Kyocera MF there is job that continues to print continuously time after time. The only we can get the printer to stop is by removing the network cable from the Kyocera. To make this clear the Kyocera's are located in three different buildings and they have 3 different jobs. One other thing, when I look in C:\windows\system32\spool\printers on the Print server I see two files in that folder. Listed as:
FP00003.SHD and FP00003.SPL. I have completed the following on these files:
1. Stopped the Printer Spooler service
2. Deleted these files
3. Rebooted the server
After rebooting the server when I look in this same folder I see those same two files there.
Please find the HijackThis scan for the Win 2K3 SP2 Print Server
I would appreicate any help I can get with this one.
Thanks in Advance.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:33 PM, on 4/3/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
C:\Program Files\Firebird\bin\ibserver.exe
C:\Program Files\Kyocera\KM-HostAgent\SoapService.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Kyocera\FileUtility\nsCatCom.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\KMNVWeb2.1\bin\kwrapper.exe
C:\Program Files\KMNVWeb2.1\jre\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KMNVWeb2.1\jre\bin\rmiregistry.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Kyocera\FileUtility\NsCatCom.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://usa.kyoceramita.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [CnwiDeviceAgent] C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: DB Assistant.lnk = ?
O4 - Global Startup: GARO Status Monitor.lnk = C:\Program Files\Canon\GAROStatusMonitor\cnwism.exe
O4 - Global Startup: Scanner File Utility.lnk = ?
O16 - DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} (PrinterHelpEtcActiveX Control) - http://www.samsungdp.com/printerhelp/ActiveX/DrPrinter.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136939872725
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136939862063
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\Software\..\Telephony: DomainName = d401.k12.id.us
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CCS\Services\Tcpip\..\{D95AEA52-A5A8-4DA0-BDC9-419CB28E78E2}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\System\CS1\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\System\CS2\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: ApacheForKMNVWeb2 - Apache Software Foundation - C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
O23 - Service: Firebird Server (InterBaseServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: KM-NET VIEWER Web Edition 2 (KMNVWeb2Service) - Unknown owner - C:\Program Files\KMNVWeb2.1\bin\kwrapper.exe
O23 - Service: KMSoapService - Unknown owner - C:\Program Files\Kyocera\KM-HostAgent\SoapService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: SFUSVC - KYOCERA MITA CORPORATION - C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe

–
End of file - 5809 bytes
johnsco55,

Your problem sounds like it is related to business computers. If you click the button at the top of the page that says Terms of Use you will see that

We offer free computer help and tech support for home and personal use. We are not here to support others that work for profit, or to support/replace your company's IT department.


W32/Magistr-B is a worm that typically sends out emails to all the addresses in outlook express, display "rude" messages on the screen at startup, and make desktop icons "run away" from your mouse cursor. I have no clue how it might effect your print server but it will attach itself to the network shares of the computers connected to the print server.

Even though we don't work on business computers, you should be aware that Sophos makes a program specifically for dealing with this worm. It can be found here: http://www.sophos.com/support/disinfection/magbremove.html

Good Luck.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI