Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 06-13-2005, 03:48 PM   #1
Member (5 bit)
 
Join Date: Dec 2004
Posts: 20
WMIPRVSE-Application error

I've been gettting this message intermittently after booting up on a number of computers:

Wmiprvse.exe-Application error
The instruction at "0x7c911e58" reference memory at "0x000000000"

I know that wmiprvse.exe belongs to the WMI however, I cannot determine what is causing the errors. The error does not seem to stop anything you just click ok and the computer works flawlessly.

Does anybody have ideas about what could be causing this issue.
frizzy is offline   Reply With Quote
Old 06-13-2005, 04:31 PM   #2
Member (10 bit)
 
macko72's Avatar
 
Join Date: Feb 2005
Location: London, England, United Kingdom
Posts: 979
Send a message via MSN to macko72
Exclamation

If a process named wmiprvse.exe is running on your computer, you may have been infected with a strain of the Sonebot-B worm.

http://www.auditmypc.com/process/wmiprvse.asp

W32/Sonebot-B is a network worm which includes IRC bot and backdoor functionality that allows unauthorised remote access to the infected computer.
This worm copies itself to network shares with weak passwords, initiates a remote background process, connects to a remote IRC server and joins a specific channel.
W32/Sonebot-B drops a copy of itself to the Windows System32 folder with the filename WMIPRVSE.EXE and sets the following registry entries to run the copy on system restart:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Kernel_check = wmiprvse.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Kernel_check = wmiprvse.exe
W32/Sonebot-B also attempts to terminate a number of processes and delete a number of files from the infected computer.
This worm may also set the following registry entries:
HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\
AutoShareServer =
AutoShareWks =
HKLM\System\CurrentControlSet\Control\lsa\
RestrictAnonymous =
RestrictAnonymousSam =

http://www.neuber.com/taskmanager/pr...prvse.exe.html
__________________
I am always doing that which I can not do, in order that I may learn how to do it.

Last edited by macko72; 06-13-2005 at 04:35 PM.
macko72 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 10:38 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2