A service was installed in the system seAWeaVP.sys

Discussion in 'Prevx Betas' started by zerotox, Jan 19, 2013.

Thread Status:
Not open for further replies.
  1. zerotox

    zerotox Registered Member

    Joined:
    Jul 16, 2009
    Posts:
    417
    Hello,

    All of a sudden I got this entry in my Eventviewer log and checking the driver seAWeaVP.sys it's signed by Webroot. Any info on what it is for?
     
  2. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,012
    Location:
    Ontario, Canada
    I did a search on my Win 7 x64 and found nothing? And are you still on .46?

    TH

    19-01-2013 2-21-52 PM.png
     
  3. zerotox

    zerotox Registered Member

    Joined:
    Jul 16, 2009
    Posts:
    417
  4. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,012
    Location:
    Ontario, Canada
  5. Ibrad

    Ibrad Registered Member

    Joined:
    Dec 8, 2009
    Posts:
    1,949
    Just giving a random guess but I have a feeling its most likely for the rootkit scanner. A lot of rootkit scanners use randomly names .sys files. However why you have more then one on your machine and they are not deleting themselves I do not know
     
  6. Techfox1976

    Techfox1976 Registered Member

    Joined:
    Jul 22, 2010
    Posts:
    749
    Most likely the normal WRKrn.sys driver randomly renamed because an attempt to install it to the normal name was interfered with or the option to install with a random name was selected.
     
  7. zerotox

    zerotox Registered Member

    Joined:
    Jul 16, 2009
    Posts:
    417
    No, the normal WRKrn.sys driver was present there as well. Actually after reboot those 2 drivers disappeared.
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    This is normal - during malware cleanup, WSA creates a randomized copy of its driver to provide additional cleanup functionality.
     
  9. Triple Helix

    Triple Helix Webroot Product Advisor

    Joined:
    Nov 20, 2004
    Posts:
    12,012
    Location:
    Ontario, Canada
    Good to know thanks! ;)

    TH
     
  10. Techfox1976

    Techfox1976 Registered Member

    Joined:
    Jul 22, 2010
    Posts:
    749
    Also could be a pending rename op if there were two updates since the last reboot of the system.
     
Thread Status:
Not open for further replies.