HP Printer Malfunction (Virus?)

driversmalwareprinting

i'm having serious problems with several HP Printers.

The issue is the following: my printer (different models) prints random ASCII character on the first line of a paper ( image sample: http://tinyurl.com/d2744sk ) and prints several papers ( 50+ )

And here another screenshot of the print queue: http://tinyurl.com/cvxeo6n the first 2 are the ascii "print".

The problem is presenting himself on different printer models (but only HP) and in different organization with some personal in common but no connection between the two. The building are miles away. I suspect some user spread the virus via USB keys.

I run a full system scan with several antivirus with no result. I'm updating printers firmware, if avaiable, as we speak.

Consider that:

- All models seems to be vulnerable: Laser and InkJet
- Antivirus can't find anything
- Driver and firmware are updated to the latest version
- The printer function properly but every 1 or 2 prints starts printing ascii character
- The client are Windows XP 32Bit and Windows 7 64Bit
- Printers are all in the same Subnet and VLAN there's direct connectivity from clients to printer with stable ping. I ruled out network issues

Some of printer models affected HP P2055dn, HP2015dn

My organization has 15+ Printers and 80+ Client i need a deployable solution if applicable.

What could i do?

Thank you in advance!

Best Answer

So far I found these reports, in addition to the SANS ISC Diary post:

http://community.spiceworks.com/topic/232157-printer-prints-virus-string-until-out-of-paper?page=2

  • See post from "kinggeorge" on Jun 08, 2012 at 07:01 AM page 2: " ... Only on the Windows 7, we found a (hidden) scheduled task, that used rundll32.exe with a randomly generated dll-file in c:\windows\system32 ..."

https://community.mcafee.com/thread/45989?start=10&tstart=0

  • Post #14 from "mrussell77" on Jun 8, 2012 8:02 AM confirms registry keys reported in the SANS diary comments.
  • Post #15 from "scorpy" on Jun 8, 2012 7:58 AM mentions the scheduled task.