|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (5 bit)
Join Date: Dec 2004
Posts: 20
|
WMIPRVSE-Application error
I've been gettting this message intermittently after booting up on a number of computers:
Wmiprvse.exe-Application error The instruction at "0x7c911e58" reference memory at "0x000000000" I know that wmiprvse.exe belongs to the WMI however, I cannot determine what is causing the errors. The error does not seem to stop anything you just click ok and the computer works flawlessly. Does anybody have ideas about what could be causing this issue. |
|
|
|
|
|
#2 |
|
Member (10 bit)
|
If a process named wmiprvse.exe is running on your computer, you may have been infected with a strain of the Sonebot-B worm.
http://www.auditmypc.com/process/wmiprvse.asp W32/Sonebot-B is a network worm which includes IRC bot and backdoor functionality that allows unauthorised remote access to the infected computer. This worm copies itself to network shares with weak passwords, initiates a remote background process, connects to a remote IRC server and joins a specific channel. W32/Sonebot-B drops a copy of itself to the Windows System32 folder with the filename WMIPRVSE.EXE and sets the following registry entries to run the copy on system restart: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Kernel_check = wmiprvse.exe HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ Kernel_check = wmiprvse.exe W32/Sonebot-B also attempts to terminate a number of processes and delete a number of files from the infected computer. This worm may also set the following registry entries: HKLM\System\CurrentControlSet\Services\lanmanserver\parameters\ AutoShareServer = AutoShareWks = HKLM\System\CurrentControlSet\Control\lsa\ RestrictAnonymous = RestrictAnonymousSam = http://www.neuber.com/taskmanager/pr...prvse.exe.html
__________________
I am always doing that which I can not do, in order that I may learn how to do it. Last edited by macko72; 06-13-2005 at 04:35 PM. |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|