Twokinds ARCHIVE Forums

This forum is for the preservation of old threads from before the forum pruning.
It is currently Tue Apr 15, 2025 4:53 pm

All times are UTC - 5 hours




Post new topic Reply to topic  [ 41 posts ]  Go to page Previous  1, 2, 3
Author Message
 Post subject:
PostPosted: Sun Oct 05, 2008 2:54 am 
Offline
Templar Inner Circle

Joined: Tue Jul 15, 2008 1:37 am
Posts: 3264
Location: Washington
Oh, dear o.o;;
I dun wanna' overload you D:


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 12:39 am 
Offline
Citizen
User avatar

Joined: Wed Jul 30, 2008 5:13 am
Posts: 96
KitWiz4687 wrote:
Sigh...
I think I'm stretching myself a little far all over the place.
...


What the heck. My exams are over, I'll see what I can do...

Keldoth: Let's see... you're probably running Windows XP Media Center Edition on a laptop with an ATI video card. If it is a laptop, it's probably a Centrino platform (or at least uses an Intel wireless card)? You also have a Canon scanner, a HP printer, an iPod (or you use iTunes to play your music) as well as a PDA (Probably a Palm PDA). Chances are you also have a microsoft mouse and keyboard. You have installed an EA game, probably Battlefield 2142 or similar game with an online component, as well as Steam. You're also running WampServer.

Yes, that entire list was derived from your process listing. There's no obvious malicious process though, except for dllhost (which can act as a host for malicious programs) and whatever it's doing.

Other than looking at the ProcMon listing, do you know what message and links the virus sends out, and is it still happening even though you changed your password?


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 1:21 am 
Offline
Citizen

Joined: Tue Sep 16, 2008 10:27 pm
Posts: 99
Sorry AJ, ProcMon will put out thousands of lines of events so it is not possible to post the logs here...>.>


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 1:30 am 
Offline
Citizen
User avatar

Joined: Wed Jul 30, 2008 5:13 am
Posts: 96
Good point. I assumed dllhost.exe wouldn't do a lot. Which could be true, but probably is false where he'd leave it running for about a minute. Out of curiosity, how many events did it log?

Edit: I fail at reading. The log file he'll save would contain all events, which would probably reach about 100,000 events in a minute. So, yes, too much to post. Gah. *resolves to be more careful next time*


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 1:49 am 
Offline
Citizen
User avatar

Joined: Wed Apr 04, 2007 1:29 am
Posts: 64
Location: In the mysterious land of Nowheresville
KitWiz4687 wrote:
Sorry AJ, ProcMon will put out thousands of lines of events so it is not possible to post the logs here...>.>


nopaste.org


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 2:19 am 
Offline
Citizen
User avatar

Joined: Wed Jul 30, 2008 5:13 am
Posts: 96
Neybulot wrote:
KitWiz4687 wrote:
Sorry AJ, ProcMon will put out thousands of lines of events so it is not possible to post the logs here...>.>


nopaste.org


Which, considering that Keldoth has ~60 processes (+- a few), would kill it, because a 10 second capture with ~45 processes and active use produced ~40,000 events, which nopaste seems to be choking on right now...

Yep, it choked:
nopaste.org wrote:
Error

content too big (max 512KB)


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 10:53 pm 
Offline
Templar Inner Circle
User avatar

Joined: Sun Mar 30, 2008 10:05 pm
Posts: 2906
Location: Five miles into nothing, sitting in a Dennies
Yeah, me and Kit are currently wrestling with how to exchange a file of that size.

As for the messages, really, the only way to answer that would be to ask the people on my friends list.

Plus, to help avoid it, I've been constantly signing in as ghost, so I dunno, let's see if I can get the people on my contacts list here.


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 11:54 pm 
Offline
Templar Inner Circle

Joined: Tue Jul 15, 2008 1:37 am
Posts: 3264
Location: Washington
My friend did a system restore (or something to that affect) and it's seemed to go away for now, so...


Top
 Profile  
 
 Post subject:
PostPosted: Mon Oct 06, 2008 11:54 pm 
Offline
Council Member
User avatar

Joined: Fri Dec 08, 2006 2:06 am
Posts: 544
Location: Behind my computer.
Keldoth Wolfram Dekel wrote:
Yeah, me and Kit are currently wrestling with how to exchange a file of that size.

As for the messages, really, the only way to answer that would be to ask the people on my friends list.

Plus, to help avoid it, I've been constantly signing in as ghost, so I dunno, let's see if I can get the people on my contacts list here.

Take the text file, zip it up, and upload it to some file-hosting site.
Simple.


-RobbieThe1st


Top
 Profile  
 
 Post subject:
PostPosted: Tue Oct 07, 2008 12:56 am 
Offline
Citizen

Joined: Tue Sep 16, 2008 10:27 pm
Posts: 99
I may as well make my upload manager since it'll work kinda like ThinSlice Upload when I'm done.


Top
 Profile  
 
 Post subject:
PostPosted: Thu Oct 09, 2008 9:59 pm 
Offline
Grand Templar
User avatar

Joined: Mon Jul 04, 2005 2:24 am
Posts: 1135
Location: In a tea shop, arguing about politics
If the file is under 5 gigs just use this site hurr:

http://www.filedropper.com/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 41 posts ]  Go to page Previous  1, 2, 3

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group