Wierd and Annoying Infection, help!

Tordek

[H]ard|Gawd
Joined
Dec 9, 2003
Messages
1,765
It seems there something, a virus, that makes my xp sp2 install to print complete black pages in my hp 840c printer... I have no idea what this could be.
Sometimes the documents show in the printer queue, sometimes not,

I have done these:

1. Ran Antivir with latest defs in normal mode and safe mode.
2. I was sharing the printer on the network, that has stopped too.
3. Ran Adaware and Spybot and Spysweeper.
4. Run Highjack This!

Heres the log:
****************************************************
Logfile of HijackThis v1.98.2
Scan saved at 11:24:04 AM, on 11/4/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Downloads\Apps\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2004\\Parser.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1099206923125

************************************

5. Google for it..

Nothing has come up that resembles my problem, so

HELP!
 
Nope not it...

HP hasnt updated this printer's driver for a while now...
 
Have you completely removed the printer and reinstalled? This does not sound like a viral problem at all to me. There's no evidence of propagation in the form of system slowdown and the issue is not one that I've ever heard of a virus causing.

I would uninstall the printer, delete all the HP software, restart, and install again.


BTW, your hijackthis log is squeaky clean, assuming that leechget is your p2p of choice
 
well if it was actually an infection, the first thing it likely would do is circumvent any AV and likely the firewall as well, so a remote scan or a fresh install of a different trial version to a non-default directory can often uncover that

however I agree it doesnt sound like an infection





PS
Some MOD edited my location, this is my comeback!. The ComeBack of the "Custom Location" !!!!!!!!!!

mods dont do such things
but Admins do :p
 
Yeah, u guys were right on target...

It was a driver thing. Reinstalled the driver and everything is good now.

Thx
 
Back
Top