mcloum Posted September 8, 2009 Posted September 8, 2009 Hi all, Just noticed this is the scheduled tasks on my new 2008 server.. rundll32.exe zazld.obk,vhcxpfb Runs everyday at 17:00 Anyone seen this before? googled it but nothing comes up. Mike
azrael78 Posted September 8, 2009 Posted September 8, 2009 Not seen that one before but for the sake of security, disable the task (don't delete it) and then run a full AV scan over the server. It doesn't look like something legitimate but with so much software in use everywhere, it's hard to tell sometimes. At the very least, run Malwarebytes Anti-Malware over it. Just to make sure you don't have anything nasty lurking. Az
leco Posted September 8, 2009 Posted September 8, 2009 Isn't that an Outlook backup file type (.obk) ? Though I don't know what the switches are.
MrEprise Posted September 8, 2009 Posted September 8, 2009 I believe Conficker inserts scheduled tasks much like this - we ended up with similar tasks of most of our PCs when we became infected (VirusScan 8.0i which we had installed stops updating after Feb09 - nice of County to let us know...) I can't confirm that it's Conficker (i'd assume most malware/spyware/viruses leave something like this) but it does seem very similar.
FN-GM Posted September 8, 2009 Posted September 8, 2009 Check to see if your automatic update service is running....
Michael Posted September 8, 2009 Posted September 8, 2009 I would definitely disable it. Seems very odd and I've no idea what it's for. The fact it's mostly random letters and no hits in Google, it doesn't look positive.
powdarrmonkey Posted September 9, 2009 Posted September 9, 2009 (edited) Blatantly a worm... Edit: almost certainly Conficker, too. Sorry. Edited September 9, 2009 by powdarrmonkey
6Foot2 Posted September 12, 2009 Posted September 12, 2009 Not sure if this will help but one of the searches I did while looking for info on this turned up a web page called: "You've been bitten by Matt's Anti-Spam harvester script" It is located at: http : // www . camerashed . co . uk / biteme . asp ? Page No = 2453 [Address broken up so that it does not act as a click able link after posting] What is weird is that the page has text with the letters arranged apparently at random with a few E-Mail links scattered down the page and a link to a similar page at the bottom [see attached picture] Any idea what purpose this web page might serve? [i ask only for the sake of interest] From the title of the website it seems obvious what the function is but the site looks so chaotic I wondered if the web pages are corrupt?
Sylv3r Posted September 13, 2009 Posted September 13, 2009 I have seen something similar to that for conficker also, although I would have expected a lot more than the one scheduled task. Have you tried to run the Microsoft removal tool? Download details: Windows Malicious Software Removal Tool
xathros Posted September 13, 2009 Posted September 13, 2009 Certainly looks like Conficker to me. Having had dealings with that on a few hundred machines and it's a pain in the ass.
mcloum Posted September 13, 2009 Author Posted September 13, 2009 Its most likely going to be conficker, we had a outbreak of it before i replaced the servers (no anti-virus yet...my own fault ) I wouldnt mind but firewall is on, servers and workstations are totally patched so how the hell is it still getting infected?!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now