Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
5/2/2004 11:29:13 AM EDT
suddently got an error message today. computer said my virual memory was low. bullshit. i've got 896 mb RAM. No way am i using it all. i run a few checks, and found out the svchost.exe is killing my box. at one time it sucked up to 1.5 GB of RAM!!! I don't have any viruses...defs are up to date and no viruses found. i ran a blaster tool, and no blaster found. my hard drive light is constandly flashing, and my memory is being sucked up. ideas/help/anything????

I do know computers pretty well, but this has me puzzled. originally posted in computer networkign area, but doesnt 'appear to have gotten any traffic. I'm pulling my hair out here.
5/2/2004 11:31:13 AM EDT
[#1]
leech this
and this
and this
5/2/2004 11:40:59 AM EDT
[#2]
securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html



Due to the random nature of how the worm constructs the exploit data, this may cause the RPC service to crash if it receives incorrect data. This may manifest as svchost.exe, generating errors as a result of the incorrect data.



It might be that.
5/2/2004 11:42:18 AM EDT
[#3]
NTMSIDX


that mean anytihng to you? it's being hammered as shown by filemon.
5/2/2004 11:46:56 AM EDT
[#4]

Quoted:
securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.html



Due to the random nature of how the worm constructs the exploit data, this may cause the RPC service to crash if it receives incorrect data. This may manifest as svchost.exe, generating errors as a result of the incorrect data.



It might be that.



i ran a blaster tool, and no blaster found. but i appreciate the help!

5/2/2004 11:49:14 AM EDT
[#5]
you have a trojan, delete it or move it out of your system directory
5/2/2004 11:54:38 AM EDT
[#6]
i did a search and it appears that's some sort of keylogger. hmm...

Norton did not find it. i'm not that suprised though.

now im jsut trying to figure out where the hell it came from....(tinfoil hat on!)
5/2/2004 11:59:00 AM EDT
[#7]

Quoted:
leech this
and this
and this

Good site, Peekay!
5/2/2004 12:07:43 PM EDT
[#8]
i use a spy sweeper. dont remember the mfr. but it was downloaded free IIRC. you wouldnt believe how many things of spyware i find almost every sweep. on the other hand norton always says my machine is fine.
5/2/2004 12:20:25 PM EDT
[#9]
norton says my machine is fine, and so did adaware.

I removed the directory, and all seems good. However, none of the registry keys are present that sould be. apparently that directory belongs to "Specter" keylogger. But, like stated, i found no other telltale signs(registry, DLL's, etc).

hmm....interesting to say the least.

Thanks for the help! If i can ever return the favor, let me know.


Fellas, drinks are on me!  
5/2/2004 3:56:16 PM EDT
[#11]
Now who is dumb enough to click on a link to the software that this guy originaly had a problem with....


Quoted:
www.specter-software.com/

5/2/2004 4:06:49 PM EDT
[#12]

Quoted:
i did a search and it appears that's some sort of keylogger. hmm...

Norton did not find it. i'm not that suprised though.

now im jsut trying to figure out where the hell it came from....(tinfoil hat on!)



Norton couldn't find its a$$ with both hands.