Malware/Virus - Server 2008R2

Soldato
Joined
16 May 2008
Posts
2,561
Location
Bristol
One of my VMs (Server 2008 R2 fully updated) is constantly trying to connect to port 25 'smtp.hot.glbdns.microsoft.com' from the process 'taskeng.exe'.

I'm not too worried as it's only allowed access to DNS and HTTP through the firewall but I would like to get it clean.

I've tried the following:
Replaced with known clean version of 'taskeng.exe' - no joy
"SFC /scannow" - System files all checked and verified
GMER rootkit scanner - clean
RUBotted - clean
Kaspersky for servers - clean
MBAM - clean
Uploaded taskeng.exe to VirusTotal.com - clean
HiJackThis - brings back nothing untoward
RootkitBuster - incompatible with X64
Combofix - incompatible with server OS

Apart from wiping the box I'm not sure what else I can do? Unless this is actually a legit SMTP connection for Microsoft usage statistics or something?
 
idea.

run wireshark - let it through and see how data is transfered & info.

it it doesnt repeat it could be just sending statics if it does look more into wireshark & find out where its going?
 
Thank you.. problem solved and I'm totally kicking myself now..

I saw it was trying to authenticate using my personal email and the server was saying "TLS required go away". Then I remembered I set up a scheduled task to email myself whenever an account is changed but never set any authentication on it :o

One good thing has come out of though! My GFs laptop is doing netbios lookups for random strings so I'd better go sort that out :\
 
Back
Top Bottom