{"id":420,"date":"2008-07-16T15:01:16","date_gmt":"2008-07-16T13:01:16","guid":{"rendered":"https:\/\/alax.info\/blog\/?p=420"},"modified":"2008-07-17T16:25:55","modified_gmt":"2008-07-17T14:25:55","slug":"viral-netschedulejobadd","status":"publish","type":"post","link":"https:\/\/alax.info\/blog\/420","title":{"rendered":"Viral NetScheduleJobAdd"},"content":{"rendered":"<p>Something unrecognized started showing Internet Explorer based popups&#8230; Obviously it is of a viral source, there is an executable with arbitrary eight character name created in %WINDIR%\\system32 which also uses <a href=\"http:\/\/msdn.microsoft.com\/en-us\/library\/aa370614(VS.85).aspx\">NetScheduleJobAdd<\/a> to add a number of delayed start job to launch Internet Explorer and navigate to free lotto, diversity visa and other advertised websites. Google search on <a href=\"http:\/\/www.google.com\/search?q=NetScheduleJobAdd\">NetScheduleJobAdd<\/a>, however, did not give any matching description for a known virus, trojan or malware. Fresh <a href=\"http:\/\/lavasoft.com\/\">AdAware<\/a> is also not yet aware&#8230;<\/p>\n<p><strong>Update 1<\/strong>: Similar symptoms described <a href=\"http:\/\/www.trojaner-board.de\/55665-virus-will-nicht-vom-pc-verschwinden.html\">here in German<\/a>.<\/p>\n<p><strong>Update 2<\/strong>: I started <a href=\"http:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb896645.aspx\">Process Monitor<\/a> to record creation of a new file in<em> %WINDIR%\\system32<\/em> to find out where it comes from on next re-spawning of the popup. It took some time to wait and here it goes. There was again an IE popup and new AT\/Scheduled Task entries. A new process <em>%WINDIR%\\dnQS28v6.exe<\/em> was started. The image was created by another process <em>gC5AHp1a.exe<\/em> from user&#8217;s Temp which was already terminated and the file was deleted to the moment. Still logs are here.<\/p>\n<p>The process <em>gC5AHp1a.exe<\/em> was created by&#8230; Mozilla Firefox 3! None of the DLLs loaded into Firefox process look suspicious.<\/p>\n<p><a href=\"https:\/\/alax.info\/blog\/wp-content\/uploads\/2008\/07\/virus-image001.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-428\" title=\"virus-image001\" src=\"https:\/\/alax.info\/blog\/wp-content\/uploads\/2008\/07\/virus-image001-300x143.png\" alt=\"\" width=\"300\" height=\"143\" srcset=\"https:\/\/alax.info\/blog\/wp-content\/uploads\/2008\/07\/virus-image001-300x143.png 300w, https:\/\/alax.info\/blog\/wp-content\/uploads\/2008\/07\/virus-image001.png 816w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p><strong>Update 3<\/strong>: Firefox 3.0.1 available, <a href=\"http:\/\/www.mozilla.org\/security\/known-vulnerabilities\/firefox30.html#firefox3.0.1\">fixed security issues<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Something unrecognized started showing Internet Explorer based popups&#8230; Obviously it is of a viral source, there is an executable with arbitrary eight character name created in %WINDIR%\\system32 which also uses NetScheduleJobAdd to add a number of delayed start job to launch Internet Explorer and navigate to free lotto, diversity visa and other advertised websites. Google&hellip; <\/p>\n<p><a class=\"moretag\" href=\"https:\/\/alax.info\/blog\/420\">Read the full article<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[87],"class_list":["post-420","post","type-post","status-publish","format-standard","hentry","category-off-topic","tag-virus"],"_links":{"self":[{"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/posts\/420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/comments?post=420"}],"version-history":[{"count":0,"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/posts\/420\/revisions"}],"wp:attachment":[{"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/media?parent=420"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/categories?post=420"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/alax.info\/blog\/wp-json\/wp\/v2\/tags?post=420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}