Help - Search - Members - Calendar
Full Version: How Do I Get Rid Of Advapi
BleepingComputer.com > Security > Am I infected? What do I do?
   
bluesjunior
I have had a couple of Audit failures on Start-up where the report mentions Advapi. I googled it and found it to be Malware. My question is how do I get rid of it.
I am running the following security programmes on my Pc but none of them picks it up. Comodo Firewall, Avast Anti-virus, Spybot S&D, Adaware, Spyware Blaster, AVG Antispyware.

I have also recently installed Start-up Inspector which is where I found Advapi while checking the security logs.

Can anyone tell me how to get rid of it or is it a Windows programme that should be left alone?.
Grinler
Are you sure you are not receiving Advapi32 errors? The 32 after advapi is important in determining the right solution.
bluesjunior
Thanks for your reply Grinler,

I was checking the security tag on the events log on my Startup Inspector Application. I share this computer with my daughter and noticed that every time we logged on to our respective accounts two Audit failures were reported.

The First One reads:

Date:
Source: Security
Time:
Failure Audit properties
Category: Logon/Logoff
Type: Failure Aud
Event id: 529
User: NT AUTHORITY \ SYSTEM
Logon Failure
Reason: Unknown user name or bad password
Username: George
Domain: BLUESJUNIOR
Logon Type: 2
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: BLUESJUNIOR

For more Information see help and support centre at http://go.microsoft.com/fwlink/events.asp


The Second One Says:

Date:
Source: Security
Time:
Category: Account Logon
Type: Failure Aud
Event id: 680
User: NT AUTHORITY \ SYSTEM
Computer: BLUESJUNIOR

Description:

Logon Attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon Account: George
Source Work Station: BLUESJUNIOR
Error Code: 0xC000006A

For more Information see help and support centre at http://go.microsoft.com/fwlink/events.asp

The same failures are reported each time my daughter logs in and out, the only change being the account names.


I have been to the Microsoft help and support centre but although it is a known issue I don't really understand the reply. I am using Windows XP Home with the SP2 update installed and I am signed up to automatic updates and up to date with that side of it.I have also googled these events and found a lot of info but no solution.

I would appreciate any advice/help offered in this matter and let me know if you need to know anything else.
Grinler
See if this matches your scenario:

http://support.microsoft.com/default.aspx?...kb;en-us;811082

Are you configured for a Windows domain?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.