Weird Chinese link - Printable Version
-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Skype & Live Messenger (/forumdisplay.php?fid=10)
+----- Thread: Weird Chinese link (/showthread.php?tid=31488)
Weird Chinese link by BooGhost on 09-14-2004 at 04:32 AM
OK, here (Peru) some ppl has got infected by a weird virus/worm that makes them send a sentence at the end of each message they send by MSN.
The weird chinese sentecnce is:
如果您寂寞、空虛...<link here>紅袖視覺.影音女優
(Chinese symbols not displayed, view screeny)
Translation:
If you lonely, are void...<link here> red sleeve vision The video and music female is superior
If you open the link you'll get infected
i tried but nothing happend i told Chrono, and he got it.
DO NOT OPEN IT
the link is "http://www.xf2s.com/msn/wode.jpg" i have advertised you, don't blame me if you get it too
i downloaded the image it's a text:
<html>
<iframe src="news.htm" width="0" height="0" frameborder="0"></iframe>
<center><img src="1.jpg"></center>
<html>
i downloaded then http://www.xf2s.com/msn/1.jpg
it's a real image
i don't really get it..... so if anybody wants to take a look..... tell me if you get any info on how to take it off and how it works
here a screeny of Chrono infected:
RE: Weird Chinese link by WDZ on 09-14-2004 at 04:36 AM
¬_¬
http://forums.happy-messaging.com/discus/messages/35/3014.html
RE: Weird Chinese link by BooGhost on 09-14-2004 at 04:40 AM
wait.... wich one of them is the solution, i guess the second one?
RE: Weird Chinese link by WDZ on 09-14-2004 at 04:44 AM
I dunno what the fix is. The virus sounded interesting, so I did some searching and found that.
I don't think there's anything dodgy about 1.jpg, but news.htm has its source encoded...
<!--The page is protected by HTMLShip XP(Unregistered Version)-->
RE: Weird Chinese link by BooGhost on 09-14-2004 at 04:46 AM
ye i saw that too...... i thought it was L337 writing (j/k)
but i mean how can it do so much stuff....... weird... me wants to make one to........
RE: Weird Chinese link by Chrono on 09-14-2004 at 04:53 AM
well yeah, kinda annoying as the infected guy (in this case, me ) wont notice it. i didnt receive the messages in chineese.
WDZ's link contains the solution
How to remove it (from wdz's link):
1.go to Run -> regedit
2.go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3.after there, remove "realone_nt2003" and "realone_nt2004"
4.then, go to C:\Windows\System32
5.find and remove "MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
- (is sys"L"ray, not sys"T"ray, becarefull)
- (if u cannot remove moniker.exe or syslray.exe, u ctrl+alt+del, go to process, u end the process of this two)
it says u have to uninstall/reinstall msn, but i didnt do that
RE: Weird Chinese link by Mnjul on 09-14-2004 at 09:29 AM
Thanks DZ and Chrono for providing such solution...now I can finally help my friends
BooGhost, the Chinese characters are about porn. It's a ...eh, a shame , that it seems to be developed in Taiwan ...
RE: Weird Chinese link by jexx on 09-17-2004 at 08:26 PM
hi chrono ,
i tired ur methid
but until the last stage , the two files cant be delte cos it says windons need it to run..
then i tried alt+ctrl , elete ..i cant find process.
pls advice again
thanks
RE: Weird Chinese link by Chrono on 09-17-2004 at 09:58 PM
quote: Originally posted by jexx
i tired ur methid
but until the last stage , the two files cant be delte cos it says windons need it to run..
then i tried alt+ctrl , elete ..i cant find process.
pls advice again
thanks
are u sure u are trying to delete sysLray and not sysTray??
RE: Weird Chinese link by jexx on 09-17-2004 at 10:18 PM
yes ....i follow everything
but when i delete them .. a pop up will say cant delete it windon need it to run..
i ctrl alt delete
but cant see them inside nor the word process
pls help
i aredi delete the "realone_nt2003" and "realone_nt2004"
but then stuck there
the later part all cant
pls advice asap
RE: Weird Chinese link by Chrono on 09-17-2004 at 10:27 PM
err well i dunno
go to C:\Windows\System32 or C:\WINNT\System32 or simply go to start > search > and search for the following files:
"MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
Before trying to delete them, make sure u end the process (ctrl alt del, then search for these files in the list).
Now if u cant find them, then u aint infected
if u cant delete them, tell us which file is the one u cant delete.
As i was able to do it at the first try, i dunno if ill be able to help u..
RE: Weird Chinese link by jexx on 09-18-2004 at 04:56 AM
haha
i m so happy
i did this
to remove it (from wdz's link):
1.go to Run -> regedit
2.go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3.after there, remove "realone_nt2003" and "realone_nt2004"
4.then, go to C:\Windows\System32
5.find and remove "MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
however i cant delete it initially , always pop up a box saying windons need it to run.
i cant find the wors process after i alt, ctrl, delete .. too
oni manage to delete the two files
realone_nt2003" and "realone_nt2004
after trying many times , i use ad ware programme to scan again , then delete watever virus is there
then use spybot to scan n delete every virus
then i use spysweeper to scan n delete all virus..
then i go back and try deleting the
MONIKER.EXE", "SYSLRAY.EXE
this time it works
the pop up did not appear n i can delete it
after which i uninstall n re install msn
the URL attachment with the asian ger is gone...
try it
i think i have managed to solve it
its wat windz said
the oni thing is when i try deleting
MONIKER.EXE", "SYSLRAY.EXE
in the first place
a pop up staing tat windons need it to run n i cant delete it
but after scanning with ad ware , spybot , spysweeper programme
i try it again
this time i can delete those 2 files..
i uninstall n reinstall msn
and the stupid URL signature is no longer there
try it
hopes it can help tose who have not solve it'
thanks
RE: Weird Chinese link by lhunath on 09-18-2004 at 08:27 AM
<SCRIPT>
onload=(new
ActiveXObject("scripting.filesystemobject")).CreateTextFile("out.htm",
true).WriteLine(document.body.innerHTML);
</SCRIPT>
Is what the encrypted script says.
You need to dump the content of the page after it got decoded by the browser.
RE: Weird Chinese link by Mario Achkar on 09-18-2004 at 06:44 PM
I got infected too but i was able to delete it , that virus was getting on my nerves , i had to translate a page because of it! i advise u to delete all ur temporary internet files in internet explorer before doing all that cause the primary virus might be still there. this is a big security hole and i think it should be fixed quickly...
RE: Weird Chinese link by lhunath on 09-18-2004 at 06:55 PM
Bluergh, I'm in a mean mood, so don't take what I'm saying now personal, I'm just joking about:
quote: Originally posted by Mario Achkar
I got infected too
Serves you right. I hope one day a virus is released which disintegrates every single pc opening it with IE.
Anyhow, I don't use IE, so bite me, virus.
RE: Weird Chinese link by Mario Achkar on 09-18-2004 at 07:01 PM
lol ie was my default navigator but i never use it i always use mozilla firefox but i clicked that stupid link by mistake and it opened up with ie! stupid windows internet explorer .
RE: Weird Chinese link by lhunath on 09-18-2004 at 07:11 PM
quote: Originally posted by Mario Achkar
lol ie was my default navigator but i never use it i always use mozilla firefox but i clicked that stupid link by mistake and it opened up with ie! stupid windows internet explorer .
Heh, then it's best to set your IE security settings to Very High, as lots of other applications use IE's web engine, and it's safest like that.
RE: Weird Chinese link by Dane on 09-18-2004 at 07:13 PM
Virus Submitted to McAfee Avert (will be issued in a DAT Update Shortly) as well as to Symantec Security Response
</resident virus geek>
RE: Weird Chinese link by Dane on 09-25-2004 at 01:53 PM
The virus is now detected by Symantec Products with the Virus Definations after 9/22/04.
A writeup for W32.Snone.A by Symantec is now available at http://securityresponse.symantec.com/avcenter/ven...a/w32.snone.a.html
RE: Weird Chinese link by RebelSean on 09-25-2004 at 02:30 PM
Question...I read the thread and didn't see the answer to it, but how do you get infected by it? Meaning like how would you get it on your computer?
RE: Weird Chinese link by Dane on 09-25-2004 at 02:34 PM
, Just viewing the picture can infect you!!! If you're infected, you wont know, only your contacts will see a chinese link under your last message.
RE: Weird Chinese link by RebelSean on 09-25-2004 at 02:46 PM
Well I guese I aint got it.....Thank god
RE: Weird Chinese link by Mario Achkar on 09-25-2004 at 04:31 PM
U can only get infected if ur using ie , and u don't have the patch installed : http://www.microsoft.com/technet/security/bulletin/ms04-013.mspx lol , the virus can't do anything to me now
|