avserve.exe, avserve2.exe, avservesetup.pf. HELP!!! this virus is shutting me downloa
#1
Scooby Regular
Thread Starter
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes
on
0 Posts
avserve.exe, avserve2.exe, avservesetup.pf. HELP!!! this virus is shutting me downloa
got these files on my PC. seems to have happened to friends in area on btbroadband too.
delete files in title and they some back and keep closing my computer
now ive got a NT/AUTHORITY/SYSTEM shutdown im being shutdown
help
delete files in title and they some back and keep closing my computer
now ive got a NT/AUTHORITY/SYSTEM shutdown im being shutdown
help
#2
Scooby Regular
Join Date: Mar 2001
Location: Just passing through...
Posts: 17,497
Likes: 0
Received 0 Likes
on
0 Posts
#5
like most good(!) viruses, they'll have modified a registry setting to re-establish themselves at start-up.
look in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run in your registry and REMOVE any reference to these, and indeed anything that you DONT want to run at start-up.
it's good practice to back-up your registry just incase of course
specifically for said virus, look on anti-virus software websites as they'll say how to remove this one exactly.
and do the following:
* get anti-virus software
* get a decent firewall
* look on microsoft's site for security updates as often as possible - REGULARLY check windowsupdate.
look in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run in your registry and REMOVE any reference to these, and indeed anything that you DONT want to run at start-up.
it's good practice to back-up your registry just incase of course
specifically for said virus, look on anti-virus software websites as they'll say how to remove this one exactly.
and do the following:
* get anti-virus software
* get a decent firewall
* look on microsoft's site for security updates as often as possible - REGULARLY check windowsupdate.
#7
Scooby Regular
Thread Starter
Join Date: Apr 2003
Location: A galaxy far far away.
Posts: 3,310
Likes: 0
Received 0 Likes
on
0 Posts
http://msn.mcafee.com/virusInfo/defa...virus_k=125007
This is the Stinger and has detected and deleted the worm.
http://vil.nai.com/vil/stinger/
must say im impressed with it.
CHEERS GUYS!!!!
PS. have BLACKICE firewall
This is the Stinger and has detected and deleted the worm.
http://vil.nai.com/vil/stinger/
must say im impressed with it.
CHEERS GUYS!!!!
PS. have BLACKICE firewall
Trending Topics
#10
sounds like your firewall is letting another one in everytime you go online? get another firewall,on cd,load it,and run a full virus scan,assuming you have an antivirus programme? if you have port open,they will find it everytime i think
#12
Scooby Regular
Join Date: Sep 2002
Location: The biosphere
Posts: 7,824
Likes: 0
Received 0 Likes
on
0 Posts
look in:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run in your registry and REMOVE any reference to these, and indeed anything that you DONT want to run at start-up.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run in your registry and REMOVE any reference to these, and indeed anything that you DONT want to run at start-up.
Next either do what milo suggested, or run "msconfig" and under the "Startup" tab untick any suspicous looking files. E.g. anything to do with avserve*.exe
Reboot
Then, as Mark suggested, update windows.
#13
Scooby Senior
Join Date: Oct 2000
Location: Zurich, Switzerland
Posts: 3,105
Likes: 0
Received 0 Likes
on
0 Posts
Stinger is the best tool to completely remove the worm. But unless you've patched against MS04-011, or have updated your virus definition files, you'll quickly get re-infected.....very quickly
Imagine a world where everyone patched against latest vulnerabilities and ran auto-update on their AV software. Interent access would be much faster for everyone
Richard
Imagine a world where everyone patched against latest vulnerabilities and ran auto-update on their AV software. Interent access would be much faster for everyone
Richard
#17
XP tip
just a small part of the problem is the autoreboot caused by the LSASS crashing. On XP at least you can give yourself time - when you get notification of an impending reboot got to Start-Run and enter "shutdown /a" and hit return. This will at least abort the scheduled reboot and give you a chance...
#18
Scooby Regular
Join Date: May 2003
Location: West Sussex
Posts: 912
Likes: 0
Received 0 Likes
on
0 Posts
I spent most of yesterday afternoon pi**ing around with this little virus, it's a right pain !
Does wind me up that some people have the time, inclination and ability to create such viruses.
Matt
Does wind me up that some people have the time, inclination and ability to create such viruses.
Matt
Thread
Thread Starter
Forum
Replies
Last Post
aaron_ions
General Technical
14
25 September 2015 02:33 PM
jobegold@hotmail.co.uk
ScoobyNet General
43
24 September 2015 02:16 PM
alcazar
Non Scooby Related
25
11 September 2015 08:45 PM