Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Weird Default WBDService

Posted on 2010-09-17
6
Medium Priority
?
506 Views
Last Modified: 2012-05-10
Ok guys, I'm a tech and network admin, and have come across something that has me stumped.  I have a Windows 2003 server running IIS that hosts multiple web sites.  About every 2-3 nights the system stops serving web sites completely.  I have done some digging and have found a service installed called Default WBDService.  This goes to a file called upsvr.exe.  Description of the service is "Support Windows File Search Servers Databases.".  When I kill that running process and disable the service everything works fine again.  I have found nothing on this file name, service name, or description on the web.  

Anyone have any thoughts?  This has all the makings of a virus type file, or a backdoor, rootkit, something, but virus scanners say the file is clean.  Have I been hacked?
0
Comment
Question by:mozarks
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
6 Comments
 
LVL 9

Accepted Solution

by:
Michael Knight earned 2000 total points
ID: 33701917
Well, if you can't find that service anywhere online, it would lead me to believe that it's a rouge application. My first thought is that upsvr is taking over port 80 periodically as you say and confusing the server into not serving pages at all. Hence when you kill the service, IIS is once again able to serve over 80.
I just checked a couple 2k3/II6 machines that are actively serving pages and see no sign of this service. There's no harm in disabling it obviously, so why not do a search in regedit for upsvr.exe and just delete the keys (backup first if you are uncomfortable) see if they stay deleted/disabled.
what does uploading the file to http://www.virustotal.com/ have to say about it?
0
 
LVL 2

Author Comment

by:mozarks
ID: 33702623
I've removed the service before and it comes back, leading me to further believe that, as you way, it's a rogue app.  Any idea of a .Net application that another user has done could possibly be causing this?  Nobody else has access to this server to install anything, at least not that I know of.  I have one web app on that is a .Net app that the coder who did it is not very experienced.  I've been blaming my locking up issues on that app until I found this not too long ago.  

I think your assessment of the situation is accurate - was just hoping someone would recognize what this service and / or file might be doing.  

Not familiar with VirusTotal.  Thanks for that info!
0
 
LVL 2

Author Comment

by:mozarks
ID: 33703102
I have tracked down some more info.  From VirusTotal.com I get a response of BDS/Backdoor.Gen from Avira.  There's another file that is suspicious that I've found that resembles something important that may be related as well - labeled as "Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\Windows\System32\msdtcsvc.exe.  I upload this one to virutotal.com and I get the BDS/Backdoor.Gen as well.  I know that MSDTC is a valid service so I compared this to some of my other servers and on those the service goes to the file msdtc.exe instead of msdtcsvc.exe.  So, it's looking more and more like this server has been hacked.  

0
What Is Blockchain Technology?

Blockchain is a technology that underpins the success of Bitcoin and other digital currencies, but it has uses far beyond finance. Learn how blockchain works and why it is proving disruptive to other areas of IT.

 
LVL 9

Expert Comment

by:Michael Knight
ID: 33704912
yeah, msdtc is a valid service, msdtcsvc is definately malware. Since Avira seems to at least recognize it, you could use Avira's portable boot CD to clean the files: http://thepcsecurity.com/virus-scan-boot-disk-from-avira/ you'd have to bring the box down for an hour or so, but better that than a day down the line.
0
 
LVL 2

Author Comment

by:mozarks
ID: 33705059
I think I'm going to one even better and move the sites I have on here to another server and just reload this one.  Thanks for the comments back and forth.  Always helps to have a second opinion on these things.  
0
 
LVL 2

Author Closing Comment

by:mozarks
ID: 33705071
Good response.  Appreciate the time taken to help out.  
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question