05-27-2007, 02:45 PM
Does anyone here use IP blocking software such as protowall or pear gaurdian?

I recently started using this ip blocking/monitoring software which blocks many known malicious IP's

To cut to the chase here When I log into HL It is trying to reach out to a sight This is the name:
AtrivoHell.CWS.BS.Hijackers|Malware Network

Doesnt sound very friendly eh?

I could give you the IP but not going to do that just yet, what Im wondering is if anyone knows what this is & how its related to HL

Also Ive noted just recently that when I log onto HL my cpu usage is going through the roof HL is using up to 50% of a duel core processor to run? Its not constant but it spikes like every 3, 5 8 12 seconds randomly.

It is HL doing this or something that has attached itself to HL somehow because once I close HL the CPU access stops

Anyone else notice this?? or willing to test?

Photo shop uses 50% of my CPU

Converting Files uses 60% of my cpu cycles

HL shouldn't be using 50% cpu cycles to run in the background should it?

05-27-2007, 02:56 PM
OMG grab a tin hat, and someone call Galen Thurber.


For the AtrivoHell.CWS.BS.Hijackers|Malware Network.. I don't think it is directly connected to HL.. or atleast, it is not Jiri trying to h4x you up.

As for the CPU usage.. I've noticed this heartbeat CPU usage for years... I put it down to innefficient coding or something.
But I don't know.

05-27-2007, 02:56 PM
Locust have tried contacting Jiri with this?
IF not i'll try and got through Squadron Channels and get his attention.

05-27-2007, 03:47 PM
Originally posted by Megile:
As for the CPU usage.. I've noticed this heartbeat CPU usage for years... I put it down to innefficient coding or something.
But I don't know.

Well, put it down to coding in Visual Basic. Easy for programmers, heavy for CPU http://forums.ubi.com/groupee_common/emoticons/icon_smile.gif
The good thing is that it doesn't affect gameplay, because when IL-2 starts, HL stops refresing the server & player lists and I think the CPU spikes should be gone while playing.

05-27-2007, 03:56 PM
Hmmm - It's not hyperlobby client related.
Since you're posting here on UBI I guess you made an exception rule for protowall/PG - or you don't use all the block rules (they block UBI) how many of those did you make, if so? Better do a virus/malware check m8!

IF you're using PeerGuardian 2 - check out this post (http://forums.phoenixlabs.org/showthread.php?t=13531) at Phoenix labs forum

The URL you provided seems not to be very threatening, I would keep it blocked anyway, and do 3 virus & malware scans with different scanners. It's not hyperlobby related. It does come up with several programs connecting to the net through http - It's used in some unethical company's adware to scare ppl in buying their AV software - you'll probably get some pop-ups in the future too Just keep blocking...

05-27-2007, 09:59 PM
Ok MaxMhz will do & thx, using Peargaurdian2

@ Megile I don't need a tin hat, did I say Jiri was doing anything? no.

Ive been using HL for a while guess I never noticed the cpu spikes, It does stop once you join a game like rnzoli mentioned.

05-27-2007, 10:06 PM
Galen Thurber. Now that's a name I haven't heard in a long, long time.

05-28-2007, 06:00 AM
What the heck does Galen Thuber have to do with this??

I think he was mad at jiri or something?



If you see something out of the ordinary you ask questions!!!

Ive also noted that the more people on HL the larger the spikes are.

Something still seams fishy about this, Ive searched Google for this Atrivohell...
Didnt find anything saying its ALL GOOD

Its being blocked so thats not the problem
the huge resource spikes were odd tho imo

05-28-2007, 08:05 AM
Calm down Locust and don't get riled by any responders to this. You have a perfectly legitimate question that needs to be addressed by someone who knows. I never knew that. By Googling <span class="ev_code_YELLOW">AtrivoHell.CWS.BS.Hijackers|Malware Network </span> I got some itnheresting results. Ill have to read up on it later in the day... in the meantime.. I got some grillin to do. http://forums.ubi.com/images/smilies/16x16_smiley-wink.gif

05-28-2007, 02:17 PM
have a good Q

05-28-2007, 02:33 PM
Off topic, but Locust what you doing next saturday June 2nd.

Would you want to run down to OK. with me, share some of your gas money to go to this http://www.biplaneexpo.com/index.htm ?

If not no big deal I'm going regardless, going to go meet up with Tailspin there.

05-31-2007, 12:28 PM
Hey Toad that looks like fun but my lil brothers birthday is on that weekend & we have plans for celebration, I hope you guys have fun & gas prices go DOWN for the trip.

Be careful in that bi-plane man http://forums.ubi.com/groupee_common/emoticons/icon_smile.gif)

06-07-2007, 03:03 AM
So no one knows whats up with this?

Going to take it to HL forums maybe an answer there or flamed to deth

06-07-2007, 03:24 AM

Does it belongs to Hyperlobby at all??

Cos some other people have it to, just google for it.


This bloke has the same ****.

Looks like an infection.


06-09-2007, 05:59 PM
Ya I read that post

It only happens when I launch HL

Going to uninstall HL and reinstall on a differant drive.

I have all kinds of security virus scaners etc shows no viruses/trojans

dont get it.

06-09-2007, 08:30 PM
hi locust,

i can't get any activities logged for hyperlobby trying to contact any ip. the spikes of cpu-usage (old system with xp2400) are non-rhythmic, show some relation to chat-activities and vary between 1%-6%.
my guess is, that either the spikes are generated by your ip-blocking software... or by a tracking virus, which hooks himself up to chat-related applications, using the ports opened for these programs. at least this is known to happen related to several instant-messengers.
however, i would check first, if the spikes disappear, when you don't have the blocker running in background.
to have the most detailed view of all handles/libraries connected to each process running, get the 'process explorer', which has been distributed for free by sysinternals (http://www.sysinternals.com) and is now available at microsofts site (imo, the link redirects to microsoft now). with this tool you can determine any handle connected to a program, incl. the percentage of usage for each handle, resp. memory for each dll.