Congratulations to AcaCandy on her 100,000th post!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer avg backup black screen boot bsod computer connection crash css dell display drive driver drivers email error ethernet excel firefox firefox 3 game hard drive internet internet explorer itunes laptop linux malware monitor network networking outlook outlook 2003 outlook 2007 outlook express partition problem router slow software spyware trojan usb video virus vista windows windows xp wireless
General Security
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > General Security >
Original trigger of task in Task Scheduler


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
DonDodge's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Dec 2007
Experience: Intermediate
03-Mar-2008, 08:32 PM #1
Original trigger of task in Task Scheduler
I found a malicious task planted in the Task Scheduler of Vista Home Premium. This task is designed to create an illusion the computer is infected with a virus.

Is there any way I can determine the exact event that was originally programmed into the task that activated the trigger and set the task in motion?

Edit: I should add this is a reverse engineered OEM version of Vista.

Last edited by DonDodge : 03-Mar-2008 08:52 PM.
lunarlander's Avatar
Computer Specs
Senior Member with 815 posts.
 
Join Date: Sep 2007
04-Mar-2008, 09:08 PM #2
I wouldn't trust any pirated OS version. They can insert all sorts of keyloggers, botnet clients into it and you wouldn't know. Think about it, you do email, business and private stuff on it and all the while this guy is reading everything through a backdoor.
DonDodge's Avatar
Computer Specs
Member with 39 posts.
 
Join Date: Dec 2007
Experience: Intermediate
05-Mar-2008, 09:40 AM #3
This is not a pirated operating system lunarlander. It's fully licensed by Microsoft and is the OS provided in the recovery partition of a laptop computer purchased from a major brick & mortar office supply company. The computer came in factory packaging with all seals intact. What you state above is exactly what I'm concerned about since the computer was purchased for business use and must be secure.

As I said, I've found a malicious task. It was programmed into the image provided by the manufacturer.

I know all the parameters for the task as well as the settings and conditions that control how it runs. I also have all the info on the trigger that makes it run NOW. What I can't find is the particular piece of programming that activated the task BEFORE the trigger took over. It wasn't installation of the software from the recovery partition to the C: drive.

I have the complete history of the task from the log. This dates back to the first time the task was executed. I have a very good idea what originally set the task in motion but I can't prove it until I find the programming that did it.
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 01:31 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.