Re: Hiding scheduled tasks in 2K/XP

From: H Carvey (keydet89at_private)
Date: Tue Jun 03 2003 - 12:15:05 PDT

  • Next message: Dan Perez: "RE: Hiding scheduled tasks in 2K/XP"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <000301c328d6$15c4d780$1202020a@hey>
    
    Winter,
    
    I've verified this on Win2K SP2.  Interesting. 
    
    I use Perl for system programming on Windows platforms,
    particularly for IR and forensics.  The
    Win32::TaskScheduler module will completely enumerate
    even the hidden (attrib +h) tasks...
    
    I mention this, as I'm putting together a full-blown IR
    application that is made up of my scripts, and can be
    run from a CD.  This will be included in my upcoming book.
    
    Harlan
    
    >Ive found that you can use attrib.exe on files in
    %windir%\tasks,
    >particularly with the +h attribute. "Attrib.exe +h *"
    will hide all
    >scheduled tasks from AT, Scheduled Tasks (both Control
    Panel + explorer) =
    >and
    >"dir %windir%\tasks" (unless you use dir /a or have it
    set as such in
    >%dircmd%).  Browsing %windir%\tasks on the cmd line
    with "dir /a" is the
    >only way ive been able to detect jobs that have been
    hidden this way. =
    >They
    >run as scheduled. Tested on 2000 SP3 & XP SP1.
    
    
    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue Jun 03 2003 - 13:23:21 PDT