Solved

Task Scheduler service stops and auto configures itself to disabled

Posted on 2011-03-13
15
1,040 Views
Last Modified: 2012-05-11
Windows Server 2003 SP2. I have a batch file configured to shutdown all the PCs on the LAN every night at 10.30. Lately, I come in in the morning and they are all still running. When I interrogated the server, I find that the task scheduler service has stopped and is set to disabled. Obviously, I then set it back to started and automatic but every day at some stage it resets itself back to stopped and disabled. Weird what? I'm thinking virus but not sure really how to tackle this. I have Symantec Client Security running and it reports that the Conficker virus is active but every instance it encounters it, it manages to delete it successfuly. I have also scanned with the W32. downadup removal tool from Symantec but it doesn't find it. It's the same file that is identified every time (nowfeee.wi) in the system32 folder but I can never find the file. It's a bit of a phantom.
0
Comment
Question by:Paulduberry
  • 8
  • 3
  • 3
  • +1
15 Comments
 
LVL 12

Expert Comment

by:jmlamb
ID: 35124683
The Task Scheduler service must be running and properly configured to run tasks. If you had stopped scheduled tasks manually from the Scheduled Tasks window, the service stops and does not initialize the next time you start the computer. If the service is not configured to log on as the local system account, it may not start.

To check the settings for the service:

1. Click Start, click Control Panel, and then double-click Administrative Tools.
2. Click Computer Management.
3. Expand Services and Applications, and then click Services.
4. Right-click the Task Scheduler service, and then click Properties.
5. On the General tab, make sure that the startup type is set to automatic, and that the service status is Started. If the service is not running, click Start.
6. On the Log On tab, make sure that the local system account is selected, and that the Allow service to interact with desktop check box has a check mark.
7. Click OK, and then quit Computer Management.

http://support.microsoft.com/kb/308558
0
 
LVL 42

Assisted Solution

by:Davis McCarn
Davis McCarn earned 400 total points
ID: 35128104
That guy is probably all over your network and, once it got in, has hidden its root process so Symantec can't see it.
According to this the Malicious Software Removal Tool can get it; but, read the article: http://support.microsoft.com/kb/962007
0
 

Author Comment

by:Paulduberry
ID: 35188283
DavisMcCarn, I read the KB from MS and went through it all step-by-step. According to the KB, the Malicious Software Removal Tool is automatically downloaded from Windows Update. If that is the case, then there is nothing to do except hope that it finds and removes the bug. At least, that's my understanding of it. It clearly isn't doing it's job. I have followed the other steps in the article also including the manual removal procedure but it hasn't made any difference.
0
 

Author Comment

by:Paulduberry
ID: 35188349
jmlamb,

My post states that I have to manually start the task scheduler service every day despite the fact it is configured to start automatically. The other settings are configured also as mentioned in your post.
0
 
LVL 68

Assisted Solution

by:Qlemo
Qlemo earned 100 total points
ID: 35188409
MRT might be downloaded automatically, but if there is suspicion, always start Windows Update manually. Some Updates only come optionally. I would not trust in MRT to be downloaded.

Nevertheless, it seems not to help. The usual recommendations made by the Virus and Malicious Tools Experts is to use MBAM (http://www.malwarebytes.org/mbam.php) and ComboFix (http://www.bleepingcomputer.com/download/anti-virus/combofix). The latter is a very sophisticated tool, and should only be used with extreme care (regarding applying changes) - the analysis can be run without concerns. I would start with MBAM, and see if that helps.
0
 
LVL 42

Accepted Solution

by:
Davis McCarn earned 400 total points
ID: 35188911
If the MRT was downloaded and run, the most recent copy will be in your C:\Windows\System32 folder as MRT.EXE and the most recent version is from 3/10/2011.  I often check for it as it lets me know the last time a system got it (meaning, if they thought they got infected in March; but the last MRT is from December lets me know something happened in January)
You should specifically download and run the MRT manually.
0
 

Author Comment

by:Paulduberry
ID: 35189163
I attempted to download and run MRT manually but couldn't find any option to do so. Would you be able to send me a link please?
0
Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

 

Author Comment

by:Paulduberry
ID: 35191238
Never mind. I found MRT.exe in the system32 folder as described. Thanks. It's dated 9-3-2011. I am currently scanning.
0
 

Author Comment

by:Paulduberry
ID: 35191434
Question, Is it advisable to run ComboFix on Windows Server 2003 considering this computer is central to our organization and has a lot of critical data that needs to be available 24-7?
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 35191606
That's one of many reasons I suggested using MBAM first. ComboFix will isolate the server machine, and the author does not "support" it running on a server. Most probably there will be no issue, but if, then it is severe. I don't know if I would take the risk.
0
 

Author Comment

by:Paulduberry
ID: 35193656
MRT didn't find any bugs. Running MBAM now.
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 35194185
When I asked for advice regarding your case, a much more versed Expert than me advised against using ComboFix on Servers and 64bit OS. Sorry I mentioned it, but I forgot you are talking about a Server when I did.

Let's hope MBAM finds something.
0
 
LVL 42

Expert Comment

by:Davis McCarn
ID: 35194271
0
 

Author Comment

by:Paulduberry
ID: 35202824
DavisMcCarn, Running that download  at the moment. This is my last hope. I'll close the ticket tomorrow regardless of the outcome.
0
 

Author Closing Comment

by:Paulduberry
ID: 35208817
Guys, I still have the problem. I will probably have to wipe the server to make this bugger disappear but thanks anyway to all who contributed.
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
Find out what Office 365 Transport Rules are, how they work and their limitations managing Office 365 signatures.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now