Support Forum Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Submit a log and you will receive ALL the information we have in our DB's on everything on your system INSTANTLY!

Avserve.exe


Click here to Run a Free Scan for Avserve.exe Related Errors

What is it?
WORM_SASSER.A - AVSERVE.EXE

What does it do?
This worm exploits the Windows LSASS vulnerability , which is a buffer overrun that allows remote code execution and enables an attacker to gain full control of affected systems.This vulnerability is discussed in detail in the following pages:

To propagate, it scans the network for vulnerable systems. When it finds a vulnerable system, this malware sends a specially crafted packet to produce a buffer overflow on LSASS.EXE.

It creates the script file CMD.FTP, which contains instructions for the vulnerable system to download and execute a copy of this malware from a remote infected system using FTP on TCP port 5554.

Removal:
Trend Micro has the full dirt ( HERE )


Fix Avserve.exe Errors: Free Scan

Recommended: Free PC Speed Test - what is slowing down your PC?


Avserve.exe is Spyware!

Startup DB Entries:
[avserve.exe]"Added by the SASSER WORM!" b

Service DB Entries:
Nothing Found

Disclaimer

Every attempt has been made to ensure the information about Avserve.exe is accurate but alot of malware applications try to pose as valid applications. If it is something other than what was posted above please leave some feedback in the forum.
Printer Friendly

User Comments
Security Risks - Adware Spyware
sndconfg16.exe | salm.exe | isass.exe | se.dll | kazza.exe | backweb-7288971.exe | bridge.dll | wtoolsa.exe | tkbellexe.exe | dl.exe | newdot~1.dll | wupdt.exe | mwsoemon.exe | saie.exe | webrebates0.exe | bxxs5.dll | funny.exe | 180ax.exe | randreco.exe | mssearchnet.exe | service.exe | webrebates1.exe | saap.exe | sais.exe | wsup.exe | backweb-137903.exe | sed.exe | alcmtr.exe | wo.exe | ffisearch.exe | optimize.exe | iadhide4.dll | backweb-8876480.exe | cdaengine0400.dll | istsvc.exe | newdotnet6_38.dll | Fvprotect.exe | Winupdate.exe | java.exe | cmesys.exe |