Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Can I trace or audit Remote Scheduled Task (at.exe) Commands?

Posted on 2009-03-30
5
Medium Priority
?
374 Views
Last Modified: 2012-05-06
I have some virus that remotely schedules tasks on other computers and that made me think:

On the machine that the task is created on, is it possible to see from which machine that task was actually created? I assume using auditing it should be possible to trace this?

Any ideas?
0
Comment
Question by:GSLBermuda
  • 3
  • 2
5 Comments
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24022054
0
 

Author Comment

by:GSLBermuda
ID: 24022197
We already found out which virus we are dealing with (and yes, it was that one), that wasn't my question (I didn't post the question in the antii virus section ;-) ) My question is more in general, if someone remotely schedules a task on another computer, it is possible to trace such an attempt (succes or not) on the remote machine and how would I identify that in the event viewer or something like that.
0
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 2000 total points
ID: 24022247
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 24022266
Also some people have posted in other sections unknowing that they had said virus, so better safe than sorry :-)

Hope the above helps you
0
 

Author Comment

by:GSLBermuda
ID: 24022637
No Worries! And thanks, that article was very helpful.

0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

INTRODUCTION The purpose of this document is to demonstrate the Installation and configuration of the Data Protection Manager product. Note that this demonstration was prepared on the basis of Windows OS is 2008 R2 and DPM 2010. DATA PROTECTI…
Citrix XenApp, Internet Explorer 11 set to Enterprise Mode and using central hosted sites.xml file.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question