Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

avserve.exe, avserve2.exe, avservesetup.pf. HELP!!! this virus is shutting me downloa

Thread Tools
 
Search this Thread
 
Old 02 May 2004, 11:01 PM
  #1  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default avserve.exe, avserve2.exe, avservesetup.pf. HELP!!! this virus is shutting me downloa

got these files on my PC. seems to have happened to friends in area on btbroadband too.

delete files in title and they some back and keep closing my computer


now ive got a NT/AUTHORITY/SYSTEM shutdown im being shutdown



help
Old 02 May 2004, 11:05 PM
  #2  
mark_h
Scooby Regular
 
mark_h's Avatar
 
Join Date: Mar 2001
Location: Just passing through...
Posts: 17,497
Likes: 0
Received 0 Likes on 0 Posts
Default

W32.Sasser.Worm
There's removal instructions, and a link to a removal tool there.
Old 02 May 2004, 11:06 PM
  #3  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default

page expired
Old 02 May 2004, 11:08 PM
  #4  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default

help. Before im shut down again
Old 02 May 2004, 11:08 PM
  #5  
milo
Scooby Regular
 
milo's Avatar
 
Join Date: Nov 2001
Posts: 2,043
Likes: 0
Received 0 Likes on 0 Posts
Default

like most good(!) viruses, they'll have modified a registry setting to re-establish themselves at start-up.

look in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run in your registry and REMOVE any reference to these, and indeed anything that you DONT want to run at start-up.

it's good practice to back-up your registry just incase of course

specifically for said virus, look on anti-virus software websites as they'll say how to remove this one exactly.

and do the following:
* get anti-virus software
* get a decent firewall
* look on microsoft's site for security updates as often as possible - REGULARLY check windowsupdate.
Old 02 May 2004, 11:09 PM
  #6  
mark_h
Scooby Regular
 
mark_h's Avatar
 
Join Date: Mar 2001
Location: Just passing through...
Posts: 17,497
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Poor Guy
page expired
Still works for me
Old 02 May 2004, 11:16 PM
  #7  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default

http://msn.mcafee.com/virusInfo/defa...virus_k=125007

This is the Stinger and has detected and deleted the worm.
http://vil.nai.com/vil/stinger/

must say im impressed with it.

CHEERS GUYS!!!!

PS. have BLACKICE firewall

Trending Topics

Old 02 May 2004, 11:29 PM
  #8  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default

its bloody back
Old 02 May 2004, 11:31 PM
  #9  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default

System Idle Process is taking 85+% CPU usage which looks very shifty

whats happening?!
Old 02 May 2004, 11:58 PM
  #10  
dba
Scooby Regular
 
dba's Avatar
 
Join Date: May 2001
Posts: 2,214
Likes: 0
Received 0 Likes on 0 Posts
Default

sounds like your firewall is letting another one in everytime you go online? get another firewall,on cd,load it,and run a full virus scan,assuming you have an antivirus programme? if you have port open,they will find it everytime i think
Old 03 May 2004, 12:24 AM
  #11  
mark_h
Scooby Regular
 
mark_h's Avatar
 
Join Date: Mar 2001
Location: Just passing through...
Posts: 17,497
Likes: 0
Received 0 Likes on 0 Posts
Default

And run Windows Update and get all the critical patches.
Old 03 May 2004, 07:43 AM
  #12  
ajm
Scooby Regular
 
ajm's Avatar
 
Join Date: Sep 2002
Location: The biosphere
Posts: 7,824
Likes: 0
Received 0 Likes on 0 Posts
Default

look in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run in your registry and REMOVE any reference to these, and indeed anything that you DONT want to run at start-up.
Reboot in safe mode (hold down F8 as the computer starts to boot). This will make sure the virus won't run at startup. If it is running then it will just undo any changes you make.

Next either do what milo suggested, or run "msconfig" and under the "Startup" tab untick any suspicous looking files. E.g. anything to do with avserve*.exe

Reboot

Then, as Mark suggested, update windows.
Old 03 May 2004, 08:14 AM
  #13  
dowser
Scooby Senior
 
dowser's Avatar
 
Join Date: Oct 2000
Location: Zurich, Switzerland
Posts: 3,105
Likes: 0
Received 0 Likes on 0 Posts
Default

Stinger is the best tool to completely remove the worm. But unless you've patched against MS04-011, or have updated your virus definition files, you'll quickly get re-infected.....very quickly

Imagine a world where everyone patched against latest vulnerabilities and ran auto-update on their AV software. Interent access would be much faster for everyone

Richard
Old 03 May 2004, 09:25 AM
  #14  
Poor Guy
Scooby Regular
Thread Starter
 
Poor Guy's Avatar
 
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes on 0 Posts
Default

for gods sake. Its like putting on riot gear to go to the shops!
Old 03 May 2004, 11:11 AM
  #15  
dowser
Scooby Senior
 
dowser's Avatar
 
Join Date: Oct 2000
Location: Zurich, Switzerland
Posts: 3,105
Likes: 0
Received 0 Likes on 0 Posts
Default

Correct, but most of it can (indeed, should) be automated.

Richard
Old 03 May 2004, 12:23 PM
  #16  
R1916v
Scooby Regular
 
R1916v's Avatar
 
Join Date: May 2002
Posts: 1,002
Likes: 0
Received 0 Likes on 0 Posts
Default

I'm afraid I find blackice useless, get something like outpost firewall.

And gods sake get some AV software (!) and make sure windows is update ok.
Old 04 May 2004, 12:04 AM
  #17  
giblet
Scooby Regular
 
giblet's Avatar
 
Join Date: Aug 2003
Posts: 56
Likes: 0
Received 0 Likes on 0 Posts
Default XP tip

just a small part of the problem is the autoreboot caused by the LSASS crashing. On XP at least you can give yourself time - when you get notification of an impending reboot got to Start-Run and enter "shutdown /a" and hit return. This will at least abort the scheduled reboot and give you a chance...
Old 04 May 2004, 08:40 AM
  #18  
Muffleman
Scooby Regular
 
Muffleman's Avatar
 
Join Date: May 2003
Location: West Sussex
Posts: 912
Likes: 0
Received 0 Likes on 0 Posts
Default

I spent most of yesterday afternoon pi**ing around with this little virus, it's a right pain !

Does wind me up that some people have the time, inclination and ability to create such viruses.

Matt
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
aaron_ions
General Technical
14
25 September 2015 02:33 PM
jobegold@hotmail.co.uk
ScoobyNet General
43
24 September 2015 02:16 PM
alcazar
Non Scooby Related
25
11 September 2015 08:45 PM
longun
ScoobyNet General
1
19 September 2001 09:37 AM
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: avserve.exe, avserve2.exe, avservesetup.pf. HELP!!! this virus is shutting me downloa



All times are GMT +1. The time now is 09:18 AM.