Korean
<< Back
VID 27081
Severity 10
Port 135
Protocol TCP
Class WMI
Detailed Description scheduled job for running pre-configured program for each time may use suitable route for attacking by hacking and installing the trojan horse, backdoor with start program. So we recommend to check reserved job every time.

* Platforms Affected:
Microsoft Windows Any version
Recommendation < GUI Check £¾
1. Start> Settings> Control Panel> Check up registered reserved job
2. Check up detail information of registered reserved job
3. Remove unnecessary files

£¼ CLI Check £¾
1. Start> Run> cmd
2. Execute C:\>at

[Windows Server 2012, 2016, 2019]
< GUI Check £¾
1. Start> Settings> Control Panel> Administrative Tools> Task Scheduler
2. Select the registered schedule task to check the details
3. Delete unnecessary files

£¼ CLI Check £¾
1. Start> Run> cmd
2. Execute C:\>schtasks
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)