Wierd Processes Running on Windows 2003 Servers

Wierd Processes Running on Windows 2003 Servers

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Wierd Processes Running on Windows 2003 Servers Amanda 07-16-2006
Posted by Amanda on July 16, 2006, 9:42 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I was troubleshooting an unrelated problem and came across a process that is
running on my 3 servers. The executable was located in the C:\Windows\Temp
directory and had the following names. It was different on each computer.

IPFB78.EXE
LDEFBA.EXE
CVE3A0.EXE

If I end the process the file disappears out of the C:\Windows\Temp
directory. I am running up to date Trend Micro and the scan comes clean. I
also ran an Ad-Aware scan and everything looked good too.

Has anyone seen anything like this. It doesn't seem to be affescting the
performance of my servers but leaves an uneasy feeling for me.



Posted by karl levinson, mvp on July 16, 2006, 1:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sounds very suspicious. I suggest going to www.virustotal.com and
submitting the files there. You should get an answer in a few seconds as to
whether this is something known or not. If it is not known, that site
supposedly shares samples with other AV companies, though you may want to
submit it to your AV company directly via the instructions on their web
site.


>I was troubleshooting an unrelated problem and came across a process that
>is running on my 3 servers. The executable was located in the
>C:\Windows\Temp directory and had the following names. It was different on
>each computer.
>
> IPFB78.EXE
> LDEFBA.EXE
> CVE3A0.EXE
>
> If I end the process the file disappears out of the C:\Windows\Temp
> directory. I am running up to date Trend Micro and the scan comes clean. I
> also ran an Ad-Aware scan and everything looked good too.
>
> Has anyone seen anything like this. It doesn't seem to be affescting the
> performance of my servers but leaves an uneasy feeling for me.
>
>



Posted by =?Utf-8?B?TWlsbyAoIE1TUFNTKQ== on July 16, 2006, 6:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
All exe file you've listed are unknown and being generated randomly every
startup by an unknown dll file. since when did this started to appear?
Anything else wierd or uncanny happening in the server or the workstations
attached to the domain or the forest which this servers controls?

--
Milo
MSPSS - ESCA


"Amanda" wrote:

> I was troubleshooting an unrelated problem and came across a process that is
> running on my 3 servers. The executable was located in the C:\Windows\Temp
> directory and had the following names. It was different on each computer.
>
> IPFB78.EXE
> LDEFBA.EXE
> CVE3A0.EXE
>
> If I end the process the file disappears out of the C:\Windows\Temp
> directory. I am running up to date Trend Micro and the scan comes clean. I
> also ran an Ad-Aware scan and everything looked good too.
>
> Has anyone seen anything like this. It doesn't seem to be affescting the
> performance of my servers but leaves an uneasy feeling for me.
>
>
>

Posted by =?Utf-8?B?TWlsbyAoIE1TUFNTKQ== on July 16, 2006, 6:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Also if you have an ISA server running among this 3 server ( can you have
this file monitored and pretty much the bandwidth it is using and if its
trying to communicate outside Intranet )
--
Milo
MSPSS - ESCA


"Amanda" wrote:

> I was troubleshooting an unrelated problem and came across a process that is
> running on my 3 servers. The executable was located in the C:\Windows\Temp
> directory and had the following names. It was different on each computer.
>
> IPFB78.EXE
> LDEFBA.EXE
> CVE3A0.EXE
>
> If I end the process the file disappears out of the C:\Windows\Temp
> directory. I am running up to date Trend Micro and the scan comes clean. I
> also ran an Ad-Aware scan and everything looked good too.
>
> Has anyone seen anything like this. It doesn't seem to be affescting the
> performance of my servers but leaves an uneasy feeling for me.
>
>
>

Posted by =?Utf-8?B?TWlsbyAoIE1TUFNTKQ== on July 17, 2006, 3:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Defender 2 is in its beta form ( currently we're still on the scenario of
development ) its not hit or miss - its more of signature based scanner and
we're currently updating it with the most current anti-spyware and
anti-malware.
--
Milo
MSPSS - ESCA


"Amanda" wrote:

> I was troubleshooting an unrelated problem and came across a process that is
> running on my 3 servers. The executable was located in the C:\Windows\Temp
> directory and had the following names. It was different on each computer.
>
> IPFB78.EXE
> LDEFBA.EXE
> CVE3A0.EXE
>
> If I end the process the file disappears out of the C:\Windows\Temp
> directory. I am running up to date Trend Micro and the scan comes clean. I
> also ran an Ad-Aware scan and everything looked good too.
>
> Has anyone seen anything like this. It doesn't seem to be affescting the
> performance of my servers but leaves an uneasy feeling for me.
>
>
>

Similar ThreadsPosted
Anti Virus software for Windows 2003 August 13, 2007, 9:57 am
Security issue with MS Exchange and Windows 2003 Server November 28, 2005, 5:05 pm
Windows 2003 server - firewall / virus protection March 7, 2006, 7:06 pm
Needing an enterprise product installable on Windows XP or 2003 that can scan Apple Mac's July 17, 2008, 7:21 pm
Is anybody using Eset NOD32 on their servers? November 28, 2005, 10:22 am
Which processes are legitimate? June 25, 2008, 5:09 pm
Wierd... McAfee Antivirus' On-Access Scan gets disabled by itself July 14, 2005, 9:20 am
ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router June 13, 2008, 5:05 pm
ZLob/DNSChanger Trojan now can modify DNS Servers in your SOHO Router June 13, 2008, 5:50 pm
Does anyone know how to see if NTLM is running on a web site? December 16, 2005, 10:04 am

The site map in XML format XML site map

Contact Us | Privacy Policy