LiveWire Network Peer Answers Peer Support Teen Forums Tech Forums College Forums 585 users online 179029 members 1644 active today Advertise Here Sign In
TeenCollegeTechPhotos | Quizzes | LiveSecret | Video | Dictionary | News | FAQ
You have 1 new message.
Emergency Help
Until you sign up you can't do much. Yes, it's free.

Sign Up Now
Membername:
Password:
Already have an account?
Invite Friends
Active Members
Groups
Contests
Moderators
4 online / 48 MPM
Fresh Topics
  LiveWire / Technical Forums / General Tech Discussion / Viewing Topic

For the love of fuck plz help. :|
Replies: 17Last Post July 2 10:39am by Khadgar
Pages: 1 2  Next » Email Print Favorite
( Dead Eyes )


Personal Assistant
Reply
1. Open up your Server Mgmt Console, and drill down as follows:
-Advanced Management
  -Group Policy Management
     -Forest (your server)
        -Domains
           -(Your Server)
              -Domain Controllers

I got that from a website, I want to do the following instructions but I have NO fucking clue what a Server Mgmt Console is, this asshole couldn't just fucking say "open cmd prompt and type" no he had to make it frickin difficult.
And I searched google and cant find out what the fuck a server mgmt  console is!


9:20 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
Khadgar


Novice

Patron
Support Leader
Reply
Do you have a server? y/n
If n, then you don't have a server management console.


-------
╔╬╝ -- 1000 needles!
_╠╗
-------

9:22 am on July 2, 2008 | Joined Feb. 2006 | 532 Days Active
Join to learn more about Khadgar California, United States | Asexual Male | 12914 Posts | -310 Points
Scoobydoo24


Dairy Product Addict
Reply
IDK too. so your not alone.

-------
always give second chances you never know when you'll need one.

9:22 am on July 2, 2008 | Joined April 2008 | 63 Days Active
Join to learn more about Scoobydoo24 Arizona, United States | Straight Female | 189 Posts | 1192 Points
( Dead Eyes )


Personal Assistant
Reply
I don't but the reason why I'm trying to turn it off is because I keep getting thousands of "success" audit entries.
That means that somebody hacked into my computer 1000 times if it says a random user made an audit right?

9:24 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
Khadgar


Novice

Patron
Support Leader
Reply
Quote: from Dead Eyes at 9:24 am on July 2, 2008

I don't but the reason why I'm trying to turn it off is because I keep getting thousands of "success" audit entries.
That means that somebody hacked into my computer 1000 times if it says a random user made an audit right?

Visit this website:

https://www.grc.com/x/ne.dll?bh0bkyd2

It will attempt to access your computer and report back to you the findings. If it reports back as secure, then it's probably not a 'hack' attempt. If it says one thing or another is insecure, I suggest you fix what it says.

-------
╔╬╝ -- 1000 needles!
_╠╗
-------


9:27 am on July 2, 2008 | Joined Feb. 2006 | 532 Days Active
Join to learn more about Khadgar California, United States | Asexual Male | 12914 Posts | -310 Points
( Dead Eyes )


Personal Assistant
Reply
Quote: from Khadgar at 9:27 am on July 2, 2008

Quote: from Dead Eyes at 9:24 am on July 2, 2008

I don't but the reason why I'm trying to turn it off is because I keep getting thousands of "success" audit entries.  
 That means that somebody hacked into my computer 1000 times if it says a random user made an audit right?

 Visit this website:

https://www.grc.com/x/ne.dll?bh0bkyd2

It will attempt to access your computer and report back to you the findings. If it reports back as secure, then it's probably not a 'hack' attempt. If it says one thing or another is insecure, I suggest you fix what it says.


I'm familiar with that site and I have done all the tests and it says my comp is good but why the hell do I keep getting "success audit" entries?
Are they normal??


9:29 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
Khadgar


Novice

Patron
Support Leader
Reply
Quote: from Dead Eyes at 9:29 am on July 2, 2008

I'm familiar with that site and I have done all the tests and it says my comp is good but why the hell do I keep getting "success audit" entries?  
Are they normal??

TBH, I'm not quite sure what a success audit is. Give me a minute.

Okay... success audit. Where is this term coming to you from? An antivirus program? Popup messages?

Post edited at 9:32 am on July 2, 2008 by Khadgar

-------
╔╬╝ -- 1000 needles!
_╠╗
-------


9:31 am on July 2, 2008 | Joined Feb. 2006 | 532 Days Active
Join to learn more about Khadgar California, United States | Asexual Male | 12914 Posts | -310 Points
( Dead Eyes )


Personal Assistant
Reply
Quote: from Khadgar at 9:31 am on July 2, 2008

Quote: from Dead Eyes at 9:29 am on July 2, 2008

I'm familiar with that site and I have done all the tests and it says my comp is good but why the hell do I keep getting "success audit" entries?  
 Are they normal??

 TBH, I'm not quite sure what a success audit is. Give me a minute.


Click Start
Control Panel
Performance&Maintenance
Administrative tools
Event viewer

I am getting success audit entries in my security tab.


9:33 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
Khadgar


Novice

Patron
Support Leader
Reply
So, judging from this Microsoft article:

Success Audit (Security log)

An event that describes the successful completion of an audited security event. For example, a Success Audit event is logged when a user logs on to the computer.

That doesn't exactly sound too promising. Are these rapidly coming in? If so, I would suggest disconnecting your computer from all networks temporarily and see if they continue. If they do continue, that it's something internal on your computer acting funny. If it stops, then it was something involving the network and further research is required.

Maybe some program attempting to connect to a server for automatic updates?

I'm not sure, I'm looking in to it.

-------
╔╬╝ -- 1000 needles!
_╠╗
-------


9:39 am on July 2, 2008 | Joined Feb. 2006 | 532 Days Active
Join to learn more about Khadgar California, United States | Asexual Male | 12914 Posts | -310 Points
Khadgar


Novice

Patron
Support Leader
Reply
Okay: what is the source of the success audits? I just induced a few on my computer, they don't seem as bad as it read from the article.

For example, the one I just induced reads:


Success Audit | 7/2/2008 | 9:44:22 AM | Security | System | 517 | SYSTEM | <computername>

So it was an audit under the authority of SYSTEM on <computername>.

Post edited at 9:47 am on July 2, 2008 by Khadgar

-------
╔╬╝ -- 1000 needles!
_╠╗
-------


9:46 am on July 2, 2008 | Joined Feb. 2006 | 532 Days Active
Join to learn more about Khadgar California, United States | Asexual Male | 12914 Posts | -310 Points
( Dead Eyes )


Personal Assistant
Reply
Quote: from Khadgar at 9:39 am on July 2, 2008

So, judging from this Microsoft article:

Success Audit (Security log)

An event that describes the successful completion of an audited security event. For example, a Success Audit event is logged when a user logs on to the computer.

That doesn't exactly sound too promising. Are these rapidly coming in? If so, I would suggest disconnecting your computer from all networks temporarily and see if they continue. If they do continue, that it's something internal on your computer acting funny. If it stops, then it was something involving the network and further research is required.

Maybe some program attempting to connect to a server for automatic updates?

I'm not sure, I'm looking in to it.


It cant be a program looking for updates, I turn off automatic update on everything I download, I prefer to do the updates manually.
I wouldn't say "rapidly" but there coming though, I'm looking at the times now and it looks like who ever is connecting is connecting every (5-10 mins 2-3 hours).
I will disconnect from the internet and see if I keep getting events coming in.
Be back in an hour.
Thanks for help.


9:49 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
( Dead Eyes )


Personal Assistant
Reply
Quote: from Khadgar at 9:46 am on July 2, 2008

Okay: what is the source of the success audits? I just induced a few on my computer, they don't seem as bad as it read from the article.

For example, the one I just induced reads:

 
Success Audit  |  7/2/2008  |  9:44:22 AM  |  Security  |  System  |  517  |  SYSTEM  |  <computername>

So it was an audit under the authority of SYSTEM on <computername>.


Here is one of the audits.
Date:7/3/2008
Source: Security
Time 10:16:56AM
Category:Privilege Use
Type: Success A
Event ID: 576
User:NT AUTHORITY\NETWORK SERVICE
Computer: HAULT0ACCESS


9:52 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
( Dead Eyes )


Personal Assistant
Reply
What ever is going on is going on through the process called "Advapi".
According to the audit that was the process this user logged in on.

9:57 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
Khadgar


Novice

Patron
Support Leader
Reply
BZZT

advapi.exe (AdvApi) - Details

The process known as Advapi.exe is installed and started by a variant of the Netdevil virus (also known as netdevil12 and netdevil1.2). It should not be confused with the 'Advapi32' process (notice the '32').

advapi.exe is considered to be a security risk, not only because antivirus programs flag AdvApi as a virus, but also because a number of users have complained about its performance.


-------
╔╬╝ -- 1000 needles!
_╠╗
-------


9:59 am on July 2, 2008 | Joined Feb. 2006 | 532 Days Active
Join to learn more about Khadgar California, United States | Asexual Male | 12914 Posts | -310 Points
( Dead Eyes )


Personal Assistant
Reply
Quote: from Khadgar at 9:59 am on July 2, 2008

BZZT

advapi.exe (AdvApi) - Details

The process known as Advapi.exe is installed and started by a variant of the Netdevil virus (also known as netdevil12 and netdevil1.2). It should not be confused with the 'Advapi32' process (notice the '32').

advapi.exe is considered to be a security risk, not only because antivirus programs flag AdvApi as a virus, but also because a number of users have complained about its performance.


I searched my computer and found 3 results related to "advapi".
1.
Name
advapi32.dll  
In Folder  
C:\WINDOWS\System32

2.
Name
advapi32.dll
In Folder
C:\WINDOWS\System32\dllcache

Then there is one I'm suspicious of...
This file is just called "ADVAPI32" no .dll extension was at the end of it. Its in the folder C:\WINDOWS\I386 its registered as a "DL_File", this file is 325kb the first to up above are both 603kb.


10:07 am on July 2, 2008 | Joined June 2008 | 12 Days Active
Join to learn more about Dead Eyes United States | 67 Posts | 187 Points
Pages: 1 2  Next » Email Print Favorite

Quick Reply

You are signed in as our guest.

Looking for something else?
 

  LiveWire / Technical Forums / General Tech Discussion / Viewing Topic