1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Advapi [please help understand Sucurity Event logged]

Discussion in 'Malware and Virus Removal Archive' started by coop, 2005/01/25.

Thread Status:
Not open for further replies.
  1. 2005/01/25
    coop

    coop Inactive Thread Starter

    Joined:
    2005/01/24
    Messages:
    38
    Likes Received:
    0
    Advapi seems to by accessing my computer - a search shows it is a virus - but McAffee is not catching it and a search for advapi.exe turns up nothing (even search system folders and hidden files). Also advapi.exe does not show up in running processes or boot processes.

    I'm not sure what it is, but it generates events 528 and 576 like crazy. Usually these events happen in bursts - several times per hour.

    From what I can tell, advapi is a legit WIN opperation. I cannot find any specific reference to this event as a virus or trojan, but I am not sure what else it could be.

    This is a typical event:
     
    Last edited: 2005/01/25
    coop,
    #1
  2. 2005/01/25
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73

  3. to hide this advert.

  4. 2005/01/25
    coop

    coop Inactive Thread Starter

    Joined:
    2005/01/24
    Messages:
    38
    Likes Received:
    0

    Yeah - it appears to be legit proceses - but I do not understand why there are so many. Maybe, as suggested by the one article, I have settings that are too sensative and record various innocuous events?
     
    coop,
    #3
  5. 2005/01/25
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Please follow Posting Rules (#3 - Meaningful Subject) when posting.

    I have adjusted your subject.
     
    Arie,
    #4
  6. 2005/02/19
    jirobert

    jirobert Inactive

    Joined:
    2005/02/19
    Messages:
    2
    Likes Received:
    0
    ADVAPI Problem

    I have the same ADVAPI problem on my XP loads. Does anyone know if this is a legit process? The ADVAPI process runs immediately after installing XP. I did a low level format on the drive before loading it. The computer is not connected to the internet. All security prone services were disabled during the installation.

    I have a Maxtor SATA/150 PIC Card installed because my system board is 100 and the drive is ATA/133. The card has a 10 MB bios. If I have a trojan, the only place it can be living is in the card bios.

    If ADVAPI is a Trojan, it's a tough one to kill....
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.