Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

n3vasap23.exe is kicking up a storm 1

Status
Not open for further replies.

doior

IS-IT--Management
Aug 8, 2000
47
0
0
US
Anyone infected with this n3vasap23.exe? It appears to be W32.Spybot.worm but it will come back a few hours later after it has been attacked.

Symantec version 9 with rapid release files is not helping us.

Any info is appreciated.

Thank you.
 
Start->Run->services.msc

ssearch for a service looking like 'MSNPluginSrIvcs', right click and select Disable .

If this file exists here delete it(if you cant boot in safe mode, or with recovery console)
C:\WINDOWS\System32\n3vasap23.exe

search this registry keys and delete these entries
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] [MSNPluginSrIvcs] n3vasap23.exe

HKEY_LOCAL_MACHINE\System\ControlSet001\Services] [MSNPluginSrIvcs] n3vasap23.exe

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [MSNPluginSrIvcs] n3vasap23.exe

and also make a search in the registry for that file(it might be somewhere else too)

Then install a good firewall and a good Antivirus (excluding Norton) This is my opinion, You can do as you wish.

Good Luck
 
perluserpengo,

This is realtively new malware, and unfortunately it is polymorphic it seeems.

HijackThis! would make the registry edits above less tedious. See: faq608-4650

I suspect this is one of those new ones we have to wait on a bit for the Security community to get a good grip on the problem.
 
Thank you for the reply. This is exactly what we are finding after removal. We are using the rapid release defs from Symantec that will seem to catch the virus but the PC will crash in a few hours.

At this stage, we have found that something else is with us or the PCs are just damaged! There is no visual porcess running but the PC will still crash after it has been up for a while.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top