Suspect Network Printer Infected by Virus

We have a stand alone network printer running TCP/IP that is connected to our network via CAT-5 to our switch.  Our broadband internet bandwidth has been running at 25kbps but when we unplug the printer from the switch, our bandwidth increases to 1.2mbps (normal speed).  The activity light on our switch also goes crazy when the printer is plugged in.

The printer is a Xerox Phaser 860.

Could this possibly be a virus that has infected the printer itself or some other problem (ie. printer is simply malfunctioning)?  

Tks.
jeffmsasAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

LucFEMEA Server EngineerCommented:
Hi jeffmsas,

As far as I know there are no virusses for printers, but maybe your internetrouter let's it send outside the LAN, try blocking access to the internet for the printer.

Greetings,

LucF
0
jeffmsasAuthor Commented:
The printer itself doesn't have a username on the network so how can we block access to the internet for the printer?
0
LucFEMEA Server EngineerCommented:
You can block the IP adres wich your printer uses.
0
Powerful Yet Easy-to-Use Network Monitoring

Identify excessive bandwidth utilization or unexpected application traffic with SolarWinds Bandwidth Analyzer Pack.

PsiCopCommented:
Viruses are OS- or application-specific. Unless the Phaser 860 runs something vulnerable like Windoze, its highly unlikely that some virus has magically installed itself in the printer.

Your problem could be something as simple as a malfunctioning NIC in the printer that's sending out a lot of garbage frames or packets, overloading your router interface. If you can swap NICs in the printer, try that.

Also verify that the UTP cable plugged into the printer is good (try swapping it with another known-good cable).

Perhaps the switch port is bad - try a different switch port.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
The--CaptainCommented:
Have you tried using a sniffer to watch exactly what sort of crazy traffic the printer is generating?  That would go a long way towards solving your problem.

Cheers,
-Jon

0
wyliecoyoteukIT directorCommented:
I would login to the printer`s webserver and disable:
1) all protocols which are not needed(e.g. appletalk, IPX/spx etc.)
2)ensure that NO gateway is set (some printer utilities will search for ever for an smtp management server for instance)
3)disable IPP (internet printing protocol)
4)remove the printer's mac address or IP address from the allowed hosts on your router.
review what ports and utilities  you use to connect to this printer.Some software will only work satisfactorily on a self containred LAN, and will cause havoc on a WAN
0
ThePowderedToastManCommented:
These types of problems usually indcate a bad NIC.
0
PsiCopCommented:
I thot I said that. :-)
0
wyliecoyoteukIT directorCommented:
Also, a lot of printers and MFPs these days actually run winnt, win2k, NetBSD and Linux as operating systems!
(Ricoh MFPs= NetBSD, early Ricoh colour = Windows Atwork, Konica = NT4 or win2K, Toshiba MFPs = Linux, etc.)

These days , network connected printers and MFPs are PCs connected to a scanner and printer in one box, often running a specialized version of an established OS.

The biggest mistake you can make is to set a gateway in the printer`s settings.

We have had hackers attack network printers  via SNMP, thinking that they are a router or other network device.
0
jeffmsasAuthor Commented:
I just wanted to let everyone know that we are still having the problem.  I've tried filtering the printers IP address and port in the broadband router config.  I've removed the gateway from the printer's network settings and any other protocol that I thought would help, I've reset the router and printer, I've moved the printer to a different port on the switch, nothing seems to help.  We talked to a Xerox lead support tech and he said he's never experienced this before.  I also called our internet service provider and they don't see a problem either.  

The only way we can kill the traffic between the printer and internet is to unplug the printer from the switch.

I'm still working on the issue.  I'll post again when we get a fix for it.  Tks.

0
ThePowderedToastManCommented:
PSIcop - a simple concurrence, no point stealing intended old chap-

Jeff, PULL THE NIC AND PUT A NEW ONE IN!

TOPTM
0
PsiCopCommented:
Remind me not to buy any Konica network printers...

TPTM - No problem
0
wyliecoyoteukIT directorCommented:
If you are still having problems,  PSIcop is probably right.
0
jeffmsasAuthor Commented:
Replaced defective switch.  Tks PsiCop.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Network Analysis

From novice to tech pro — start learning today.