• Home
  • Index
  • Search
  • Download
  • Server Rules
  • House Roleplay Laws
  • Player Utilities
  • Player Help
  • Forum Utilities
  • Returning Player?
  • Toggle Sidebar
Interactive Nav-Map
Interactive DarkMap
Tutorials
New Wiki
ID reference
Restart reference
Players Online
Player Activity
Faction Activity
Player Base Status
Discord Help Channel
DarkStat
Server public configs
POB Administration
Missing Powerplant
Stuck in Connecticut
Account Banned
Lost Ship/Account
POB Restoration
Disconnected
Member List
Forum Stats
Show Team
View New Posts
View Today's Posts
Calendar
Help
Archive Mode




Hi there Guest,  
Existing user?   Sign in    Create account
Login
Username:
Password: Lost Password?
 
  Discovery Gaming Community The Community Real Life Discussion Software & Hardware
« Previous 1 … 78 79 80 81 82 … 91 Next »
Virus Help

Server Time (24h)

Players Online

Active Events - Scoreboard

Latest activity

Virus Help
Offline Magoo!
05-10-2008, 07:00 PM, (This post was last modified: 05-10-2008, 07:01 PM by Magoo!.)
#1
Member
Posts: 1,875
Threads: 63
Joined: Sep 2007

Well, please move this if it isn't in the right spot. Anyways...

I've got a totally pain in the dewlap Virus that appeared out of nowhere. The only places I've been have been the Disco forums, Wikipedia, the JG forums, and *cough* Facebook. Same routine.

It attatches itself to an 'svchost' process and takes up 100% of my system memory usage. If you end the process, all of your sound gets shot, internet explorer is missing a few taskbars (like the tabs) but the computer runs smoothly. I've run Stinger, CA Security checks, and Trend Online House Call thing and haven't found anything.

Oh, and I had to transfer a hard copy of Stinger because when I tried to get it from download.com it stopped mid-download and gave me a:

"Download interrupted - Connection to server has been reestablished, closing application"

Any ideas, please? This is really annoying because I like my sound... And my bars... And everything else that gets killed when you end svchost.
  Reply  
Offline DBoy1612
05-10-2008, 07:46 PM,
#2
Member
Posts: 2,067
Threads: 96
Joined: Oct 2006

Ummm...

Get Avast?
http://avast.com

Retired Admin
What Dustin now spends his free time doing... Don't hurt me... Though EVEMail me if you play. ^_^
[Image: DBoy-Blue-Copy3.png]
  Reply  
Offline Mere_Mortal
05-10-2008, 08:09 PM, (This post was last modified: 05-10-2008, 08:18 PM by Mere_Mortal.)
#3
Member
Posts: 574
Threads: 54
Joined: May 2008

If you already know the module that is being loaded into the Service Host, you can use any decent process viewer to terminate such, Process Explorer is a good example. This means that you can remove the injection without having to close the process itself. Naturally, it depends on the malware itself as to what can or can't be done, for example it may simply reinject as soon as you remove it and will most likely be present upon every reboot.

I recommend you take some time to review CastleCops' Malware Removal Procedure in order to remedy your problem.

Quote:The file has been renamed to circumvent anti-stinger tactics used by Sober.r
I wouldn't be at all surprised if Sober.r is your foe. Try downloading Stinger from here.
  Reply  
Offline Magoo!
05-10-2008, 10:24 PM, (This post was last modified: 05-11-2008, 01:38 AM by Magoo!.)
#4
Member
Posts: 1,875
Threads: 63
Joined: Sep 2007

-Edit- It's all fixed! Thanks guys!
  Reply  


  • View a Printable Version
  • Subscribe to this thread


Users browsing this thread:
1 Guest(s)



Powered By MyBB, © 2002-2026 MyBB Group. Theme © 2014 iAndrew & DiscoveryGC
  • Contact Us
  •  Lite mode
Linear Mode
Threaded Mode