View Full Version : avserve.exe
racerboybmw
05-17-2004, 09:11 PM
Has anyone heard of this file? avserve.exe It has taken control of my processor and won't let go. I would like to know what program installed it and the best way to get rid of it, if it is an unnecessary file. Windows XP 2.66 processor, 256 MB RAM. If I go into task manager and turn it off my PC runs fine. Any help is greatly appreciated.
Fruss Tray Ted
05-17-2004, 09:38 PM
It's a part of the Sasser worm.
Get up to snuff with your security scans and removal tools.
Spybot S&W
AdAware
Antivirus updates and scans (tell us which ones)
Couple online scans
Do MS critical updates
Download and run Stinger
Then post a HiJackThis log back here to see if all traces are removed.
ErnieK
05-17-2004, 11:09 PM
Link to MS's sasser removal tool.
http://www.microsoft.com/downloads/details.aspx?FamilyID=76c6de7e-1b6b-4fc3-90d4-9fa42d14cc17&displaylang=en
racerboybmw
05-20-2004, 12:02 PM
Thanks guys- I was thinking that was it but wanted EXPERTS opinions and i feel that you guys qualify!!
Budfred
05-21-2004, 12:42 AM
You still need to run the other security programs and post a HijackThis log... If you have Sasser, you probably have a whole pile of other garbage...
To run HJT, extract it to a permanent folder such as C:\Documents or one you create like C:\HJT. Close all programs you have opened and make sure that all programs are enabled if you use msconfig. Run it and Scan, then Save the log. When the log window appears, Right click to Copy it, open your browser and come here to Paste the log. Do not make any changes until it is checked since most items are either benign or essential to the computer.
racerboybmw
05-21-2004, 01:16 AM
I am going to fdisk -format and reinstall- it needs a good cleaning
Budfred
05-21-2004, 01:35 AM
Well that is one way to do it...:p
Keep in mind that you restore backup files, they could be infected. Also, the reason you got infected is that your protections are not solid enough... In particular, you need to update Windoze as soon as possible when you reinstall... Sasser and others are blocked by a number of MS patches....
racerboybmw
05-21-2004, 10:23 PM
I did download the patch and saved it to disk.I regularly backup files and i will intall after I "patch" things up.Again thanks for th ehelp and offer to read my hijack file but it was getting due for a good scrubbing anyway.
vBulletin v3.6.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.