Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus batch bios bsod crash desktop driver drivers error ethernet excel freeze gaming gpu hard drive hardware hdmi internet laptop malware memory monitor motherboard netgear network printer problem ram registry router server slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Original trigger of task in Task Scheduler

Reply  
Thread Tools
DonDodge's Avatar
Computer Specs
Member with 46 posts.
 
Join Date: Dec 2007
Experience: Intermediate
03-Mar-2008, 09:32 PM #1
Original trigger of task in Task Scheduler
I found a malicious task planted in the Task Scheduler of Vista Home Premium. This task is designed to create an illusion the computer is infected with a virus.

Is there any way I can determine the exact event that was originally programmed into the task that activated the trigger and set the task in motion?

Edit: I should add this is a reverse engineered OEM version of Vista.

Last edited by DonDodge; 03-Mar-2008 at 09:52 PM..
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
04-Mar-2008, 10:08 PM #2
I wouldn't trust any pirated OS version. They can insert all sorts of keyloggers, botnet clients into it and you wouldn't know. Think about it, you do email, business and private stuff on it and all the while this guy is reading everything through a backdoor.
DonDodge's Avatar
Computer Specs
Member with 46 posts.
 
Join Date: Dec 2007
Experience: Intermediate
05-Mar-2008, 10:40 AM #3
This is not a pirated operating system lunarlander. It's fully licensed by Microsoft and is the OS provided in the recovery partition of a laptop computer purchased from a major brick & mortar office supply company. The computer came in factory packaging with all seals intact. What you state above is exactly what I'm concerned about since the computer was purchased for business use and must be secure.

As I said, I've found a malicious task. It was programmed into the image provided by the manufacturer.

I know all the parameters for the task as well as the settings and conditions that control how it runs. I also have all the info on the trigger that makes it run NOW. What I can't find is the particular piece of programming that activated the task BEFORE the trigger took over. It wasn't installation of the software from the recovery partition to the C: drive.

I have the complete history of the task from the log. This dates back to the first time the task was executed. I have a very good idea what originally set the task in motion but I can't prove it until I find the programming that did it.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 02:52 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.