The following is a log I got from HiJackThis. Can someone tell me if they see something here. This workstation's print spooler service is halting the var file. Yes it uses an lpr port for printers.
Logfile of HijackThis v1.97.7
Scan saved at 9:49:34 AM, on 6/2/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINNT\System32\nfsclnt.
exe
C:\WINNT\SYSTEM32\DWRCS.EX
E
C:\WINNT\System32\svchost.
exe
C:\Program Files\Dell\OpenManage\Clie
nt\Iap.exe
C:\ePOAgent\FrameworkServi
ce.exe
C:\Program Files\Network Associates\VirusScan\Mcshi
eld.exe
C:\Program Files\Network Associates\VirusScan\VsTsk
Mgr.exe
C:\WINNT\system32\regsvc.e
xe
C:\WINNT\system32\MSTask.e
xe
C:\WINNT\system32\svchost.
exe
C:\WINNT\System32\PSXRUN.E
XE
C:\WINNT\system32\psxss.ex
e
C:\SFU\Mapper\mapsvc.exe
C:\SFU\usr\sbin\zzInterix
C:\SFU\usr\sbin\init
C:\SFU\usr\sbin\syslogd
C:\SFU\usr\sbin\inetd
C:\SFU\usr\sbin\cron
C:\WINNT\System32\svchost.
exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.ex
e
C:\ePOAgent\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTA
T.EXE
C:\WINNT\kdx\KHost.exe
C:\WINNT\sysupd.exe
C:\WINNT\system32\internat
.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\DataViz\DvzIncMsgr.e
xe
C:\Program Files\Palm\HOTSYNC.EXE
E:\Spyware Utilities\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.excite.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://government.dellnet.com/R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3
DBE0391097
2} - (no file)
R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1
C38C7065C3
B} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - c:\program files\adobe\acrobat 5.0\Acrobat\ActiveX\AcroIE
Helper.ocx
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radi
o - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINNT\System32\msdxm.oc
x
O3 - Toolbar: (no name) - {6A85D97D-665D-4825-8341-9
501AD9F56A
3} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray
.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.ex
e
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\ePOAgent\UpdaterUI.exe
" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTA
T.EXE" /STANDALONE
O4 - HKLM\..\Run: [kdx] C:\WINNT\kdx\KHost.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT4
0.EXE
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.e
xe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {02BCC737-B171-4746-94C9-0
D8A0B2C008
9} (Microsoft Office Template and Media Control) -
http://office.microsoft.com/templates/ieawsdc.cabO16 - DPF: {03F998B2-0E00-11D3-A498-0
0104B6EB52
E} (MetaStreamCtl Class) -
https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/beta/vet_install_popup.pl?1&4&04.00.07.02&http://www.bhg.com/bhg/category.jhtml?categoryid=/templatedata/bhg/category/data/coloraroom_livingroom4.xmlO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {17D72920-7A15-11D4-921E-0
080C8DA7A5
E} (AimSp32 Class) -
http://makeover.substance.com/save/makeover.cabO16 - DPF: {18AE3ABF-725D-4623-91DD-F
D9293D5686
4} (printQuick Browser Add In (Ver5)) -
http://www.pqprint.com/plugin/axversion/1512/printquick1512.cabO16 - DPF: {1B9935E4-8A50-4DD8-BD09-A
7518723BF9
7} (eAssist NetAgent Customer ActiveX Control version 3) -
http://agent.celebrateexpress.com/netagent/objects/custappx3.CABO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://software-dl.real.com/23520fc492bf3e3b7718/netzip/RdxIE601.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37881.848287037O16 - DPF: {C1BAC744-8F0B-11D0-89E7-0
0C0A829519
7} (Cameractl Class) -
http://www.parentwatch.com/centers/video/push.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {DF6A0F17-0B1E-11D4-829D-0
0C04F6843F
E} (Microsoft Office Tools on the Web Control) -
http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-B
A56D4D8D74
3} (Secure Delivery) -
http://content.kontiki.com/kdx/v2.11/kontiki/kontiki/current/kdx.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = farmcredit-ffcb.com
O17 - HKLM\System\CCS\Services\T
cpip\..\{5
AA11716-21
12-46FE-B0
75-2800FD5
5AE46}: NameServer = 198.10.20.4,198.10.20.5
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = farmcredit-ffcb.com
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: SearchList = farmcredit-ffcb.com
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = farmcredit-ffcb.com
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: SearchList = farmcredit-ffcb.com
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: SearchList = farmcredit-ffcb.com