SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


weird avserve.exe file !!!

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 05-01-2004, 08:03 AM
az0000000 Offline
Registered User
 
Join Date: May 2004
Location: Moldova, Chisinau
Posts: 87
Exclamation weird avserve.exe file !!!

a weird file was somehow created in windows folder and at startup it starts and takes 60% of my RAM
i checked creation day and it looked like it was created at the same hour I noticed the problem, i guess through some internet site navigation
first, i stopped that service manually by task manager, than i deleted it from windows folder, and now i am up to clean up the registry from that file completely, but i am not sure if it is a needed file and what is it.
did it happen to any of you ever? did anyone hear of such file? i browsed the internet and did not find even such file name.
i want to delete any reference to that file in the registry/run section, but not sure is is good to do that


Weird!!!
I decided to restart computer without cleaning the registry from this strange file and again!!!
Even I’ve deleted the file and cleaned the recycle bin it was created again in C:\WINDOWS folder!!! And it stilled 60-70% of my RAM again!!! Now I delete it again, and will definitely clean the registry/run section from it!!! May be that will help…


can anyone tell me what ig going on?
tanx a lot in advance!
__________________
The beat never fades!

Last edited by az0000000 : 05-01-2004 at 08:44 AM.
Reply With Quote

  #2  
Old 05-01-2004, 08:54 AM
Azn_tweaker's Avatar
Azn_tweaker Offline
w1nD0w5 xP Tw3aK3r GuRu
 
Join Date: Feb 2004
Location: Toronto, Canada
Posts: 811
do u have Spybot and ad-aware 6.0 installed? if not download and install them. Remember to update both references.
this is for ad-aware do an "Full Scan" and post ur ad-aware log.

heres how to do an "full scan"
http://www.lavahelp.com/howto/fullscan/index.html
__________________
joined my friends forum.
www.osdevil.com
Pentium 4 1.5GHz, 128RDRAM, 40GB HD, WinXP Pro w/SP1, NOD32, XP ICF, SpywareBlaster 3.1, SBS&D 1.3, Ad-Aware 6.0 Professional, CWshredder 1.57
Reply With Quote

  #3  
Old 05-01-2004, 12:25 PM
braindead's Avatar
braindead Offline
Registered User
 
Join Date: Oct 2003
Location: upstate New York
Posts: 149
I looked around and found that avsev.exe is a file associated with NT 4.0 in a file name avwsntfr.exe. It is a IBM token ring. Do you have a IBM computer or NT 4.o on your computer?
Reply With Quote

  #4  
Old 05-01-2004, 01:45 PM
az0000000 Offline
Registered User
 
Join Date: May 2004
Location: Moldova, Chisinau
Posts: 87
Thumbs up reason found!

tanx a lot everyone!

i found the reason
it is all about W32/Sasser.worm!!!
anyone that got infected with it consider visiting this links and follow instructions:

http://securityresponse.symantec.com...sser.worm.html

and

http://vil.nai.com/vil/content/v_125007.htm

as instructions are provided by strongest antivirus soft providers

good luck!
__________________
The beat never fades!
Reply With Quote

  #5  
Old 05-01-2004, 02:14 PM
Azn_tweaker's Avatar
Azn_tweaker Offline
w1nD0w5 xP Tw3aK3r GuRu
 
Join Date: Feb 2004
Location: Toronto, Canada
Posts: 811
did u get it removed?
__________________
joined my friends forum.
www.osdevil.com
Pentium 4 1.5GHz, 128RDRAM, 40GB HD, WinXP Pro w/SP1, NOD32, XP ICF, SpywareBlaster 3.1, SBS&D 1.3, Ad-Aware 6.0 Professional, CWshredder 1.57
Reply With Quote

  #6  
Old 05-02-2004, 03:39 AM
az0000000 Offline
Registered User
 
Join Date: May 2004
Location: Moldova, Chisinau
Posts: 87
yes i did

Yes I did.
Actually most important part is installing that Microsoft patch that will simply stop virus from influencing your computer in any way.
Also now I know very clear where virus files are and can quarantine them with my antiviral prog even manually.
__________________
The beat never fades!
Reply With Quote

  #7  
Old 05-02-2004, 09:19 AM
Azn_tweaker's Avatar
Azn_tweaker Offline
w1nD0w5 xP Tw3aK3r GuRu
 
Join Date: Feb 2004
Location: Toronto, Canada
Posts: 811
ok Good.
__________________
joined my friends forum.
www.osdevil.com
Pentium 4 1.5GHz, 128RDRAM, 40GB HD, WinXP Pro w/SP1, NOD32, XP ICF, SpywareBlaster 3.1, SBS&D 1.3, Ad-Aware 6.0 Professional, CWshredder 1.57
Reply With Quote

  #8  
Old 05-02-2004, 09:52 AM
ESALADUANE's Avatar
ESALADUANE Offline
Senior Member
 
Join Date: Nov 2002
Location: Minneapolis, Minnesota, USA
Posts: 2,003
For others with the same problem, Symantec has added a removal tool for Sasser to its Security Response page. See here:
http://securityresponse.symantec.com...oval.tool.html

The patch from Microsoft is one of the Security Updates for April (MS04-011).
http://www.microsoft.com/technet/sec.../MS04-011.mspx
Reply With Quote

  #9  
Old 05-02-2004, 11:42 AM
Vincent9V Offline
Registered User
 
Join Date: May 2004
Location: Vancouver BC Canada
Posts: 12
I had the same problem here, http://www.softwaretipsandtricks.com...threadid=10799.

Here is another way to delete
http://uk.trendmicro-europe.com/ente...=WORM_SASSER.A
Reply With Quote

  #10  
Old 05-03-2004, 06:18 AM
az0000000 Offline
Registered User
 
Join Date: May 2004
Location: Moldova, Chisinau
Posts: 87
tanx for that link

tanx for this link http://securityresponse.symantec.co...moval.tool.html
since i use Norton Antivirus
__________________
The beat never fades!
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Drag & Drop stops file access mklass Windows XP 4 05-06-2008 03:56 AM
rewriter not working! skoundrel Windows XP 6 05-29-2005 02:31 PM
weird file giggy Windows XP 2 02-06-2004 08:34 PM
XP repair installation zenyanz Windows XP 6 05-14-2003 02:20 PM
msconfig.exe gone?? azanoncello Windows XP 2 12-26-2002 07:00 PM



All times are GMT -5. The time now is 04:17 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.