Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


I am targeted by a computer virus [RESOLVED]
Goto page Previous  1, 2
 
Post new topic   This topic is locked: you cannot edit posts or make replies.    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
Burningmace
Grandmaster Cheater
Reputation: 5

Joined: 17 Feb 2008
Posts: 520
Location: Inside the Intel CET shadow stack

PostPosted: Mon Aug 10, 2009 7:24 pm    Post subject: Reply with quote

Could you launch Process Explorer and view the info on dllhost.exe, then paste the parameters that it was called with here?

e.g: dllhost.exe /load something.dll

_________________
It's not fun unless every exploit mitigation is enabled.
Back to top
View user's profile Send private message
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Mon Aug 10, 2009 7:36 pm    Post subject: Reply with quote

Quote:
C:\WINDOWS\system32\dllhost.exe /Processid:{791EBD64-8021-490D-BE13-6A78FBDB092F}
Back to top
View user's profile Send private message
Thanitos
Grandmaster Cheater Supreme
Reputation: 0

Joined: 02 Mar 2007
Posts: 1588

PostPosted: Mon Aug 10, 2009 7:52 pm    Post subject: Reply with quote

System restore to BEFORE you got the virus or your last resort of reformating, I found with the temp folder viruses they were just easier to system restore or reformat
_________________



Back to top
View user's profile Send private message Send e-mail
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Mon Aug 10, 2009 7:58 pm    Post subject: Reply with quote

Not that I intend to keep the virus within my PC, but I could really learn something from its source code and the 'keepalive' process.
Back to top
View user's profile Send private message
Thanitos
Grandmaster Cheater Supreme
Reputation: 0

Joined: 02 Mar 2007
Posts: 1588

PostPosted: Mon Aug 10, 2009 8:03 pm    Post subject: Reply with quote

Alright, those are just the ways I used, but good luck
_________________



Back to top
View user's profile Send private message Send e-mail
Hero
I'm a spammer
Reputation: 79

Joined: 16 Sep 2006
Posts: 7154

PostPosted: Mon Aug 10, 2009 8:31 pm    Post subject: Reply with quote

Delete cookies, temp folders, and system volumes back dating to when it started. if its backing up in any of these places it wont go away. It may also be locating in system folders.
Back to top
View user's profile Send private message
WhiteByte
Master Cheater
Reputation: 0

Joined: 29 Mar 2009
Posts: 404
Location: Visual Studio

PostPosted: Mon Aug 10, 2009 11:07 pm    Post subject: Reply with quote

Record Packets with wpe pro or any efficent packet editor. Turn on all av's and firewall protections. When you find the ip use whois to discover more info about the originating location. I may be wrong but this might help.
_________________
Back to top
View user's profile Send private message Send e-mail
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 12:15 am    Post subject: Reply with quote

WPE Pro records packets within a specific process, and I still don't know how the virus got in. AV and firewall is on and running.

Still waiting for the virus to pop up again so I can root the rest out.
Back to top
View user's profile Send private message
Thanitos
Grandmaster Cheater Supreme
Reputation: 0

Joined: 02 Mar 2007
Posts: 1588

PostPosted: Tue Aug 11, 2009 12:27 am    Post subject: Reply with quote

Whats your OS, fire wall, and virus software?
_________________



Back to top
View user's profile Send private message Send e-mail
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 12:45 am    Post subject: Reply with quote

XP Home Edition SP3, Outpost Firewall, AVG 8.5 Free.
Back to top
View user's profile Send private message
Luigi
Grandmaster Cheater Supreme
Reputation: 1

Joined: 24 Mar 2008
Posts: 1082

PostPosted: Tue Aug 11, 2009 12:50 am    Post subject: Reply with quote

~Freelancer~ wrote:
XP Home Edition SP3, Outpost Firewall, AVG 8.5 Free.
I've tried AVG 8.0 (long time ago). It was pretty bad, and did not have any on-access scanning. I recommend the Avira Free Edition.

That's really all I can say, since people stronger in this particular area are already helping you.
Back to top
View user's profile Send private message
Thanitos
Grandmaster Cheater Supreme
Reputation: 0

Joined: 02 Mar 2007
Posts: 1588

PostPosted: Tue Aug 11, 2009 5:15 am    Post subject: Reply with quote

Ugh AVG should be considered a virus it self, you should look for a torrented version of Avast! or, my favorite, Eset nod32. I used a fire wall called ZoneAlarm, that is a good firewall.
_________________



Back to top
View user's profile Send private message Send e-mail
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 5:18 am    Post subject: Reply with quote

No warez. (hint hint)

I tried ZoneAlarm once. For every process I try to run it keeps asking me for permission. Based on this inconvenience, I uninstalled it.

1.5 hours to go until the anticipated time of the virus launch.
Back to top
View user's profile Send private message
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 7:58 am    Post subject: Reply with quote

20:30 passed without a hitch. I guess either the attacker quit, or he used an exploit in uTorrent, which I didn't run today.

Problem solved, requesting lock.
Back to top
View user's profile Send private message
Burningmace
Grandmaster Cheater
Reputation: 5

Joined: 17 Feb 2008
Posts: 520
Location: Inside the Intel CET shadow stack

PostPosted: Tue Aug 11, 2009 9:23 am    Post subject: Reply with quote

Glad to see you solved it Smile
_________________
It's not fun unless every exploit mitigation is enabled.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites