NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Virus alerts

Virus alerts


Windows Task Scheduler under Worm Attacks

One more report concerning the Windows functions

By Bogdan Popa, Security and Search Engines Editor

3rd of January 2008, 10:58 GMT

Adjust text size:


Windows Task Scheduler might be easily used in worm attacks
Enlarge picture
Earlier this day, security company Trend Micro has published an advisory concerning a malicious JavaScript that attempts to open Internet Explorer in order to download additional infections on an affected computer. Now, another Microsoft Windows component is affected by a pretty dangerous infection: Windows Task Scheduler. According to
a report signed by the same security company, WORM_SOHANAD.FM affects Windows 98, ME, NT, 2000, XP and Server 2003 and has a low overall risk rating. However, its damage potential is medium, while the distribution potential has the same risk rating. I guess we've all understood that this worm is pretty dangerous for a vulnerable computer.

Now, let's get to some serious matters. It seems like WORM_SOHANAD.FM can reach your computer once you visit a malicious website equipped with the infection. In addition, it may be dropped by another malware already installed on your computer. Moreover, it attempts to use the Windows Task Scheduler to be sure it is executed at a later time.

"It then uses the Windows Task Scheduler to create a scheduled task that executes the dropped copy. This worm also creates a registry entry to enable its automatic execution at every system startup", Trend Micro noted in the notification.

Task Manager may become unavailable as the worm creates new registry entries to disable this Windows function. "This worm drops copies of itself in all physical and removable drives. It also drops an AUTORUN.INF file to automatically execute its dropped copies when the said drives are accessed", the security company continued.

Just like any other recent worm, it tries to connect to the web in order to download and deploy additional infections on an affected computer, but the URLs are unavailable according to Trend Micro. So, don't forget to update your antivirus solution and avoid using suspicious pages that may drop the infection on your computer.

TAGS:

security | worm | windows | task scheduler | infection
Read by 3,174 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 5 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


BitDefender Reports on Threats

Malware Author Apologizes for Windows Worm

Windows Vista Immune to Skype Worm by Default

Windows Infection Affecting All Drives, All Networks, All Removable Devices!

How About A Virus That Restarts Your Computer?

Yet Another Windows Infection Targeting Removable Drives

User opinions:


Comment #1 by: Miko on 17 Mar 2009, 09:14 GMT reply to this comment

Hi. I have "TROJ_DOWNLOADJOB.A" on my Vista at work, which creates the file "WindowsTasksAt1.Job". As a result, task scheduler downloading "WORM_DOWNLOAD.AD". This result in openning many connection, which of course, slowing my PC connectivity.

Trend found and removed that. HOWEVER, I understood from the system person at my work this virus is spreading via the PCs sharing file system, and after day or two it infect my PC again!!

I've tried to disable Task Scheduler as it seems everything start from it, however this CANNOT be done in Vista (the "stop" or "disable" key in services window is gray). I've read that task scheduler cannot be disabled or it not recommended doing so in Vista because it run some hidden tasks crucial for Vista functioning.

So? what's is next step?

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM