johnsco55
Topic Starter
I have a box running Windows Server 2003 SP2 with all the latest updates. I am using this box as a Printer Server. I have 15 printers loaded on this box. I am running Sophos Anti Virus along with regular scans with MalWareBytes. On Tuesday of this week Sophos completed its daily scan showing the W32/Magistr-B worm in a folder containing the print drivers for my Kyocera multi-functionals. Sophos reported this worm had been cleaned up. However, we have found on 3 of the Kyocera MF there is job that continues to print continuously time after time. The only we can get the printer to stop is by removing the network cable from the Kyocera. To make this clear the Kyocera's are located in three different buildings and they have 3 different jobs. One other thing, when I look in C:\windows\system32\spool\printers on the Print server I see two files in that folder. Listed as:
FP00003.SHD and FP00003.SPL. I have completed the following on these files:
1. Stopped the Printer Spooler service
2. Deleted these files
3. Rebooted the server
After rebooting the server when I look in this same folder I see those same two files there.
Please find the HijackThis scan for the Win 2K3 SP2 Print Server
I would appreicate any help I can get with this one.
Thanks in Advance.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:33 PM, on 4/3/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
C:\Program Files\Firebird\bin\ibserver.exe
C:\Program Files\Kyocera\KM-HostAgent\SoapService.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Kyocera\FileUtility\nsCatCom.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\KMNVWeb2.1\bin\kwrapper.exe
C:\Program Files\KMNVWeb2.1\jre\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KMNVWeb2.1\jre\bin\rmiregistry.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Kyocera\FileUtility\NsCatCom.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://usa.kyoceramita.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [CnwiDeviceAgent] C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: DB Assistant.lnk = ?
O4 - Global Startup: GARO Status Monitor.lnk = C:\Program Files\Canon\GAROStatusMonitor\cnwism.exe
O4 - Global Startup: Scanner File Utility.lnk = ?
O16 - DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} (PrinterHelpEtcActiveX Control) - http://www.samsungdp.com/printerhelp/ActiveX/DrPrinter.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136939872725
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136939862063
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\Software\..\Telephony: DomainName = d401.k12.id.us
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CCS\Services\Tcpip\..\{D95AEA52-A5A8-4DA0-BDC9-419CB28E78E2}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\System\CS1\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\System\CS2\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: ApacheForKMNVWeb2 - Apache Software Foundation - C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
O23 - Service: Firebird Server (InterBaseServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: KM-NET VIEWER Web Edition 2 (KMNVWeb2Service) - Unknown owner - C:\Program Files\KMNVWeb2.1\bin\kwrapper.exe
O23 - Service: KMSoapService - Unknown owner - C:\Program Files\Kyocera\KM-HostAgent\SoapService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: SFUSVC - KYOCERA MITA CORPORATION - C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
–
End of file - 5809 bytes
FP00003.SHD and FP00003.SPL. I have completed the following on these files:
1. Stopped the Printer Spooler service
2. Deleted these files
3. Rebooted the server
After rebooting the server when I look in this same folder I see those same two files there.
Please find the HijackThis scan for the Win 2K3 SP2 Print Server
I would appreicate any help I can get with this one.
Thanks in Advance.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:33 PM, on 4/3/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
C:\Program Files\Firebird\bin\ibserver.exe
C:\Program Files\Kyocera\KM-HostAgent\SoapService.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Kyocera\FileUtility\nsCatCom.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\KMNVWeb2.1\bin\kwrapper.exe
C:\Program Files\KMNVWeb2.1\jre\bin\java.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\KMNVWeb2.1\jre\bin\rmiregistry.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe
C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Kyocera\FileUtility\NsCatCom.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://usa.kyoceramita.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [CnwiDeviceAgent] C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: DB Assistant.lnk = ?
O4 - Global Startup: GARO Status Monitor.lnk = C:\Program Files\Canon\GAROStatusMonitor\cnwism.exe
O4 - Global Startup: Scanner File Utility.lnk = ?
O16 - DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} (PrinterHelpEtcActiveX Control) - http://www.samsungdp.com/printerhelp/ActiveX/DrPrinter.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136939872725
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136939862063
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\Software\..\Telephony: DomainName = d401.k12.id.us
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CCS\Services\Tcpip\..\{D95AEA52-A5A8-4DA0-BDC9-419CB28E78E2}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\System\CS1\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = d401.k12.id.us
O17 - HKLM\System\CS2\Services\Tcpip\..\{3F93C630-0B3E-4353-9ED9-D80DEA540916}: NameServer = xxx.xxx.x.x
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: ApacheForKMNVWeb2 - Apache Software Foundation - C:\Program Files\KMNVWeb2.1\apache\bin\Apache.exe
O23 - Service: Firebird Server (InterBaseServer) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: KM-NET VIEWER Web Edition 2 (KMNVWeb2Service) - Unknown owner - C:\Program Files\KMNVWeb2.1\bin\kwrapper.exe
O23 - Service: KMSoapService - Unknown owner - C:\Program Files\Kyocera\KM-HostAgent\SoapService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: SFUSVC - KYOCERA MITA CORPORATION - C:\Program Files\Kyocera\FileUtility\SFUSVC.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
–
End of file - 5809 bytes