advapi32.dll and type 5 logons in event viewer...

G

gavin

Hi all,

Just a quick question - is it normal to see logon events for a proces
called "Advapi" in the event viewer? they appear to be type 5 logins
(service) so I think its OK - I read alot about a virus that installs
as a file called "advapi.exe" but I am pretty sure there is a
legitimate dll called "advapi32.dll".

Can anyone confirm?

cheers!

Gav
 
W

Wesley Vogel

advapi32.dll = Win32 ADVAPI32 core component. Advanced Windows 32 Base API

advapi32.dll is a part of an advanced API services library supporting
numerous APIs including many security and registry calls.

Events and Errors Message Center
Results 1 - 9 of 9 for: Advapi32
http://www.microsoft.com/technet/support/ee/SearchResults.aspx?Type=0&Message=Advapi32

Event ID & the Event Source are very important.

To open the Event Viewer...
Start | Run | Type: eventvwr | Click OK

For any Events that seem related to the problem...

Double click the event in Event Viewer | Click: the button below the second
arrow (looks like two pages) [[Copies the details of the event to the
Clipboard.]] | Paste into Notepad | Also click on:
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Read all info | Copy and paste to Notepad | Click the [+] Related Knowledge
Base articles | Follow any links that might be useful

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427

Event Viewer overview
http://www.microsoft.com/resources/.../xp/all/proddocs/en-us/event_overview_01.mspx

This can also be very useful.

You need to have the Event ID & the Event Source. Microsoft product: --All
Products-- is usually good enough. Be careful when scrolling down in the
page so that Microsoft product: doesn't change on you.

To view Windows XP Events and Errors, type the Source (for example, Print)
and/or the Event code (for example, 20) into the ID field, then click the Go
button. Source and Event codes may be found in the Event Viewer logs.

Events And Errors Message Center: Advanced Search
http://www.microsoft.com/technet/support/ee/ee_advanced.aspx

Events And Errors Message Center: Basic Search
http://www.microsoft.com/technet/support/ee/ee_basic.aspx

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top