Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 25th January 2005   #1
Inactive
 
Profile:
Join Date: Jan 2005
Posts: 38
Computer Experience:
Experienced
coop Reputation Level


Advapi [please help understand Sucurity Event logged]

Advapi seems to by accessing my computer - a search shows it is a virus - but McAffee is not catching it and a search for advapi.exe turns up nothing (even search system folders and hidden files). Also advapi.exe does not show up in running processes or boot processes.

I'm not sure what it is, but it generates events 528 and 576 like crazy. Usually these events happen in bursts - several times per hour.

From what I can tell, advapi is a legit WIN opperation. I cannot find any specific reference to this event as a virus or trojan, but I am not sure what else it could be.

This is a typical event:
[quote][size=1]Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 1/25/2005
Time: 7:04:00 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: HAL2000
Description:
Successful Logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Logon Type: 5
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name:
Logon GUID: {00000000-0000-0000-0000-000000000000}

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

-------

Quote:
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 1/25/2005
Time: 7:04:00 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: HAL2000
Description:
Special privileges assigned to new logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Privileges: SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



Is there a step-by-step available to getting rid of this thing? Below is a bit of my Event Viewer log and a summary of the typical entries.

Quote:
Type Date Time Source Category Event User Computer
Success Audit 1/25/2005 7:04:00 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 7:04:00 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 7:00:22 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 7:00:22 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 7:00:22 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 7:00:22 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:30:22 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:30:22 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:30:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:30:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:00:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:00:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:00:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 6:00:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:30:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:30:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:30:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:30:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:00:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:00:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:00:21 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 5:00:21 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:30:20 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:30:20 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:30:20 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:30:20 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:00:20 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:00:20 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:00:20 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 4:00:20 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:46:36 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:46:36 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:30:20 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:30:20 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:30:20 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:30:20 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:00:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:00:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:00:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 3:00:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:30:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:30:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:30:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:30:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:00:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:00:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:00:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 2:00:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:30:19 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:30:19 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:30:18 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:30:18 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:00:17 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:00:17 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:00:17 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 1:00:17 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:39:16 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:39:16 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:30:17 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:30:17 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:30:17 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:30:17 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:00:16 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:00:16 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:00:16 AM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/25/2005 12:00:16 AM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:30:16 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:30:16 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:30:16 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:30:16 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:00:16 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:00:16 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:00:16 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 11:00:16 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:30:16 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:30:16 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:30:15 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:30:15 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:00:15 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:00:15 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:00:15 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 10:00:15 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:30:15 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:30:15 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:30:15 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:30:15 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:00:14 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:00:14 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:00:14 PM Security Privilege Use 576 NETWORK SERVICE HAL2000
Success Audit 1/24/2005 9:00:14 PM Security Logon/Logoff 528 NETWORK SERVICE HAL2000


Suggestions? Thank you in advance.


Last edited by coop; 25th January 2005 at 20:18.
coop is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 25th January 2005   #2
Staff
 
Christer's Avatar
 
Profile:
Join Date: Dec 2002
Location: Sweden
Posts: 5,162
Computer Experience:
I'm trying!
Christer Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation Level


coop,
maybe I sent You on a wild goose chase but better safe than sorry!

I found the Microsoft articles below which describes the events:

Security Event Descriptions

Privilege Use Events

Search results id 576

Search results id 528

Christer

Christer is offline  
Old 25th January 2005   #3
Inactive
 
Profile:
Join Date: Jan 2005
Posts: 38
Computer Experience:
Experienced
coop Reputation Level


Quote:
Originally Posted by Christer
coop,
maybe I sent You on a wild goose chase but better safe than sorry!

I found the Microsoft articles below which describes the events:

Security Event Descriptions

Privilege Use Events

Search results id 576

Search results id 528

Christer

Yeah - it appears to be legit proceses - but I do not understand why there are so many. Maybe, as suggested by the one article, I have settings that are too sensative and record various innocuous events?

coop is offline  
Old 25th January 2005   #4
Administrator
Microsoft MVP
 
Arie's Avatar
 
Profile:
Join Date: Dec 2001
Location: Birkirkara, Malta
Posts: 9,815
Computer Experience:
***
Arie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation Level

My System

Please follow Posting Rules (#3 - Meaningful Subject) when posting.

I have adjusted your subject.

Arie is offline  
Old 19th February 2005   #5
Inactive
 
Profile:
Join Date: Feb 2005
Posts: 2
Computer Experience:
Experienced
jirobert Reputation Level


ADVAPI Problem

I have the same ADVAPI problem on my XP loads. Does anyone know if this is a legit process? The ADVAPI process runs immediately after installing XP. I did a low level format on the drive before loading it. The computer is not connected to the internet. All security prone services were disabled during the installation.

I have a Maxtor SATA/150 PIC Card installed because my system board is 100 and the drive is ATA/133. The card has a 10 MB bios. If I have a trojan, the only place it can be living is in the card bios.

If ADVAPI is a Trojan, it's a tough one to kill....

jirobert is offline  
Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
winupd.dll and Norton problems tanman General Security 31 29th September 2004 17:26
Out of memory error unexpected Keith2 General Internet 13 17th June 2004 19:38
New problems Jeane Windows 2000 9 22nd May 2004 03:59
Windows XP, applications break albatros Windows XP 8 20th April 2004 17:08
Event Viewer System Error martinr121 Windows XP 26 9th March 2004 16:46


All times are GMT +1. The time now is 05:21.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]