View previous topic :: View next topic |
Author |
Message |
Burningmace Grandmaster Cheater
Reputation: 5
Joined: 17 Feb 2008 Posts: 520 Location: Inside the Intel CET shadow stack
|
Posted: Mon Aug 10, 2009 7:24 pm Post subject: |
|
|
Could you launch Process Explorer and view the info on dllhost.exe, then paste the parameters that it was called with here?
e.g: dllhost.exe /load something.dll
_________________
It's not fun unless every exploit mitigation is enabled. |
|
Back to top |
|
 |
Haswell Grandmaster Cheater
Reputation: 10
Joined: 24 Nov 2007 Posts: 703
|
Posted: Mon Aug 10, 2009 7:36 pm Post subject: |
|
|
Quote: | C:\WINDOWS\system32\dllhost.exe /Processid:{791EBD64-8021-490D-BE13-6A78FBDB092F} |
|
|
Back to top |
|
 |
Thanitos Grandmaster Cheater Supreme
Reputation: 0
Joined: 02 Mar 2007 Posts: 1588
|
Posted: Mon Aug 10, 2009 7:52 pm Post subject: |
|
|
System restore to BEFORE you got the virus or your last resort of reformating, I found with the temp folder viruses they were just easier to system restore or reformat
_________________
|
|
Back to top |
|
 |
Haswell Grandmaster Cheater
Reputation: 10
Joined: 24 Nov 2007 Posts: 703
|
Posted: Mon Aug 10, 2009 7:58 pm Post subject: |
|
|
Not that I intend to keep the virus within my PC, but I could really learn something from its source code and the 'keepalive' process.
|
|
Back to top |
|
 |
Thanitos Grandmaster Cheater Supreme
Reputation: 0
Joined: 02 Mar 2007 Posts: 1588
|
Posted: Mon Aug 10, 2009 8:03 pm Post subject: |
|
|
Alright, those are just the ways I used, but good luck
_________________
|
|
Back to top |
|
 |
Hero I'm a spammer
Reputation: 79
Joined: 16 Sep 2006 Posts: 7154
|
Posted: Mon Aug 10, 2009 8:31 pm Post subject: |
|
|
Delete cookies, temp folders, and system volumes back dating to when it started. if its backing up in any of these places it wont go away. It may also be locating in system folders.
|
|
Back to top |
|
 |
WhiteByte Master Cheater
Reputation: 0
Joined: 29 Mar 2009 Posts: 404 Location: Visual Studio
|
Posted: Mon Aug 10, 2009 11:07 pm Post subject: |
|
|
Record Packets with wpe pro or any efficent packet editor. Turn on all av's and firewall protections. When you find the ip use whois to discover more info about the originating location. I may be wrong but this might help.
_________________
|
|
Back to top |
|
 |
Haswell Grandmaster Cheater
Reputation: 10
Joined: 24 Nov 2007 Posts: 703
|
Posted: Tue Aug 11, 2009 12:15 am Post subject: |
|
|
WPE Pro records packets within a specific process, and I still don't know how the virus got in. AV and firewall is on and running.
Still waiting for the virus to pop up again so I can root the rest out.
|
|
Back to top |
|
 |
Thanitos Grandmaster Cheater Supreme
Reputation: 0
Joined: 02 Mar 2007 Posts: 1588
|
Posted: Tue Aug 11, 2009 12:27 am Post subject: |
|
|
Whats your OS, fire wall, and virus software?
_________________
|
|
Back to top |
|
 |
Haswell Grandmaster Cheater
Reputation: 10
Joined: 24 Nov 2007 Posts: 703
|
Posted: Tue Aug 11, 2009 12:45 am Post subject: |
|
|
XP Home Edition SP3, Outpost Firewall, AVG 8.5 Free.
|
|
Back to top |
|
 |
Luigi Grandmaster Cheater Supreme
Reputation: 1
Joined: 24 Mar 2008 Posts: 1082
|
Posted: Tue Aug 11, 2009 12:50 am Post subject: |
|
|
~Freelancer~ wrote: | XP Home Edition SP3, Outpost Firewall, AVG 8.5 Free. | I've tried AVG 8.0 (long time ago). It was pretty bad, and did not have any on-access scanning. I recommend the Avira Free Edition.
That's really all I can say, since people stronger in this particular area are already helping you.
|
|
Back to top |
|
 |
Thanitos Grandmaster Cheater Supreme
Reputation: 0
Joined: 02 Mar 2007 Posts: 1588
|
Posted: Tue Aug 11, 2009 5:15 am Post subject: |
|
|
Ugh AVG should be considered a virus it self, you should look for a torrented version of Avast! or, my favorite, Eset nod32. I used a fire wall called ZoneAlarm, that is a good firewall.
_________________
|
|
Back to top |
|
 |
Haswell Grandmaster Cheater
Reputation: 10
Joined: 24 Nov 2007 Posts: 703
|
Posted: Tue Aug 11, 2009 5:18 am Post subject: |
|
|
No warez. (hint hint)
I tried ZoneAlarm once. For every process I try to run it keeps asking me for permission. Based on this inconvenience, I uninstalled it.
1.5 hours to go until the anticipated time of the virus launch.
|
|
Back to top |
|
 |
Haswell Grandmaster Cheater
Reputation: 10
Joined: 24 Nov 2007 Posts: 703
|
Posted: Tue Aug 11, 2009 7:58 am Post subject: |
|
|
20:30 passed without a hitch. I guess either the attacker quit, or he used an exploit in uTorrent, which I didn't run today.
Problem solved, requesting lock.
|
|
Back to top |
|
 |
Burningmace Grandmaster Cheater
Reputation: 5
Joined: 17 Feb 2008 Posts: 520 Location: Inside the Intel CET shadow stack
|
|
Back to top |
|
 |
|