[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Weird Default WBDService

Posted on 2010-09-17
6
Medium Priority
?
508 Views
Last Modified: 2012-05-10
Ok guys, I'm a tech and network admin, and have come across something that has me stumped.  I have a Windows 2003 server running IIS that hosts multiple web sites.  About every 2-3 nights the system stops serving web sites completely.  I have done some digging and have found a service installed called Default WBDService.  This goes to a file called upsvr.exe.  Description of the service is "Support Windows File Search Servers Databases.".  When I kill that running process and disable the service everything works fine again.  I have found nothing on this file name, service name, or description on the web.  

Anyone have any thoughts?  This has all the makings of a virus type file, or a backdoor, rootkit, something, but virus scanners say the file is clean.  Have I been hacked?
0
Comment
Question by:mozarks
  • 4
  • 2
6 Comments
 
LVL 9

Accepted Solution

by:
Michael Knight earned 2000 total points
ID: 33701917
Well, if you can't find that service anywhere online, it would lead me to believe that it's a rouge application. My first thought is that upsvr is taking over port 80 periodically as you say and confusing the server into not serving pages at all. Hence when you kill the service, IIS is once again able to serve over 80.
I just checked a couple 2k3/II6 machines that are actively serving pages and see no sign of this service. There's no harm in disabling it obviously, so why not do a search in regedit for upsvr.exe and just delete the keys (backup first if you are uncomfortable) see if they stay deleted/disabled.
what does uploading the file to http://www.virustotal.com/ have to say about it?
0
 
LVL 2

Author Comment

by:mozarks
ID: 33702623
I've removed the service before and it comes back, leading me to further believe that, as you way, it's a rogue app.  Any idea of a .Net application that another user has done could possibly be causing this?  Nobody else has access to this server to install anything, at least not that I know of.  I have one web app on that is a .Net app that the coder who did it is not very experienced.  I've been blaming my locking up issues on that app until I found this not too long ago.  

I think your assessment of the situation is accurate - was just hoping someone would recognize what this service and / or file might be doing.  

Not familiar with VirusTotal.  Thanks for that info!
0
 
LVL 2

Author Comment

by:mozarks
ID: 33703102
I have tracked down some more info.  From VirusTotal.com I get a response of BDS/Backdoor.Gen from Avira.  There's another file that is suspicious that I've found that resembles something important that may be related as well - labeled as "Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\Windows\System32\msdtcsvc.exe.  I upload this one to virutotal.com and I get the BDS/Backdoor.Gen as well.  I know that MSDTC is a valid service so I compared this to some of my other servers and on those the service goes to the file msdtc.exe instead of msdtcsvc.exe.  So, it's looking more and more like this server has been hacked.  

0
Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
LVL 9

Expert Comment

by:Michael Knight
ID: 33704912
yeah, msdtc is a valid service, msdtcsvc is definately malware. Since Avira seems to at least recognize it, you could use Avira's portable boot CD to clean the files: http://thepcsecurity.com/virus-scan-boot-disk-from-avira/ you'd have to bring the box down for an hour or so, but better that than a day down the line.
0
 
LVL 2

Author Comment

by:mozarks
ID: 33705059
I think I'm going to one even better and move the sites I have on here to another server and just reload this one.  Thanks for the comments back and forth.  Always helps to have a second opinion on these things.  
0
 
LVL 2

Author Closing Comment

by:mozarks
ID: 33705071
Good response.  Appreciate the time taken to help out.  
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Preparing an email is something we should all take special care with – especially when the email is for somebody you may not know very well. The pressures of everyday working life stacked with a hectic office environment can make this a real challen…
This installment of Make It Better gives Media Temple customers the latest news, plugins, and tutorials to make their VPS hosting experience that much smoother.
SQL Database Recovery Software repairs the MDF & NDF Files, corrupted due to hardware related issues or software related errors. Provides preview of recovered database objects and allows saving in either MSSQL, CSV, HTML or XLS format. Ensures recov…
The video provides a quick and easy steps to migrate MBOX file to well known Outlook PST and Office 365. Besides this, it also supports and migrates more than 20 email clients of MBOX which include AppleMail, Opera, Thunderbird and SeaMonkey effortl…

591 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question