Need to track down Infection in a Server 2008 domain user profile

Posted on 2016-11-15
Last Modified: 2016-11-15
One of my customers remoted onto her server a couple of days ago and ran her Outlook email there. She received an infected email with an "Invoice attached" message, and, amazingly, attempted to open the attachment, which was a .jar file.

Don't recall her permission level on the server, but it was enough to run the .jar, but it stopped, prompting her to accept a command which is trying to insert a .reg file into the registry.  She did not permit the .reg file, thankfully.

I reduced her user account privileges to basic user, but whenever she logs on, Regedit is constantly requesting permission to run a .reg file. If she cancels, the prompt comes back one second later. I can stop it all by killing javaw.exe in the task manager.  However, when she logs back on, it starts up again.

Hers is the only user account affected, yet I cannot find anything anywhere that tells javaw.exe (or anything else) to start up when she, and only she, logs on. There are no suspicious extensions or add-ons in her Chrome or IE browsers. I've scanned her user profile for visues, and run a rootkit detector, etc.  All clean.

Can someone advise?
Question by:DaveWWW
  • 3
  • 2
  • 2
LVL 37

Expert Comment

ID: 41887920
run MSCONFIG as an administrator on the server and review all Startup Items and remove or disable anything suspicious. better also review services as well.

you may also right-click the taskbar and choose Task Manager to check Startup items.

Author Comment

ID: 41887936
Thanks.  I've been been through MSCONFIG and the Task Manager. I see javaw.exe in the Task Manager, which I can shut down, but it comes back when this user logs back on.  What I'm not clear on is how to find the source of this autostarting of javaw.exe when only a single user is having the issue.  No other users autostart the program javaw.exe.

I've checked the logon script for this user and it is no different than anyone else's.

That's the confusing part in this: Where is this single user receiving an instruction to run javaw.exe that attempts to run a .reg file?
LVL 37

Accepted Solution

bbao earned 500 total points
ID: 41887954
javaw.exe itself is not the issue or trouble maker, the process calls Java runtime is the one to go.

you may check the Java runtime's parent process ID, it should be pointing the target process or at least providing a clue.
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Author Closing Comment

ID: 41888002
Thank you! That worked. I found the info using Process Explorer and then searched the registry for it, and deleted it out of the Run area for that user.
LVL 86

Expert Comment

ID: 41888004
msconfig is good, but much better is Sysinternals'  'autoruns' - try that
LVL 86

Expert Comment

ID: 41888009
Too late - but it might have got you there right away ;)
LVL 37

Expert Comment

ID: 41888121
> Sysinternals'  'autoruns' - try that

yes, AUTORUNS can be handy to list ALL auto-start items from both startup folders, registr items and services, but you have to review them one by pen to guess if it is related or not.

the given method of tracking back to parent process can directly determine the related process or even thread (a virus way) and finally catch the source image file on file system.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Outlook 2010 not responding when sending email. 4 43
MS Endpoint Protection 2 25
Google email problem 3 28
How to find computer SID in windows server 2008 r2 3 40
Large Outlook files lead to various unwanted errors and corruption issues. Furthermore, large outlook files can also make Outlook take longer to start-up, search, navigate, and shut-down. So, In this article, i will discuss a method to make your Out…
Read this checklist to learn more about the 15 things you should never include in an email signature.
This Experts Exchange video Micro Tutorial shows how to tell Microsoft Office that a word is NOT spelled correctly. Microsoft Office has a built-in, main dictionary that is shared by Office apps, including Excel, Outlook, PowerPoint, and Word. When …
CodeTwo Sync for iCloud ( automatically synchronizes your Outlook 2016, 2013, 2010 or 2007 folders with iCloud folders available via iCloud Control Panel. This lets you automatically sync them with…

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question