Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 898
  • Last Modified:

Is advapi spyware or a hacking tool?


Does anyone know how to get rid of this error in my SBS server seceurity log ?

Logon Failure:Reason:Unknown user name or bad password User Name:anonymous Domain:Logon Type:3Logon Process:Advapi Athentication Package:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 
0
cap7
Asked:
cap7
  • 2
2 Solutions
 
PowerITCommented:
Advapi is known as part of the Netdevil trojan/backdoor.
See: http://www.processlibrary.com/directory/files/advapi/
Scan all your workstations and servers with a good antivirus.
These are the manual removal instructions: http://www.exterminate-it.com/malpedia/remove-net-devil
Also, to be absolutely sure: if you find the advapi.exe or shellapi32.exe you can also have it scanned at virustotal. They use all virusscanners known to mankind at once;-)

kr, J.
0
 
jakosysadminCommented:
It's prolly not what you fear. But to get rid of these messages you need to track this access attempt to its source process and fix it there - use the tools from Sysinternals Suite (http://google.com/search?q=sysinternals+suite). Apply logic: if it were malware trying to brute force its way in, it wouldn't be wise to start with anonymous but rather an Administrator, right?
maybe you unnecessarily run a ftp server (where anonymous is often used for public access).
0
 
jakosysadminCommented:
and please, search the experts-exchange before asking questions: http://www.experts-exchange.com/Software/Server_Software/Web_Servers/Microsoft_IIS/Q_24550402.html ;)
0
 
cap7Author Commented:
I search the registy and removed a software key search assistant with the advapi.exe , this resolved my login errors.
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now