Shoutbox

Weird Chinese link - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Skype & Live Messenger (/forumdisplay.php?fid=10)
+----- Thread: Weird Chinese link (/showthread.php?tid=31488)

Weird Chinese link by BooGhost on 09-14-2004 at 04:32 AM

OK, here (Peru) some ppl has got infected by a weird virus/worm that makes them send a sentence at the end of each message they send by MSN.

The weird chinese sentecnce is:
&#22914;&#26524;&#24744;&#23490;&#23518;&#12289;&#31354;&#34395;...<link here>&#32005;&#34966;&#35222;&#35258;.&#24433;&#38899;&#22899;&#20778;

(Chinese symbols not displayed, view screeny)

Translation:
If you lonely, are void...<link here> red sleeve vision The video and music female is superior

If you open the link you'll get infected

i tried but nothing happend i told Chrono, and he got it.


DO NOT OPEN IT

the link is "http://www.xf2s.com/msn/wode.jpg" i have advertised you, don't blame me if you get it too :P

i downloaded the image it's a text:

<html>
<iframe src="news.htm" width="0" height="0" frameborder="0"></iframe>
<center><img src="1.jpg"></center>
<html>

i downloaded then http://www.xf2s.com/msn/1.jpg

it's a real image

i don't really get it..... so if anybody wants to take a look..... tell me if you get any info on how to take it off and how it works :p

here a screeny of Chrono infected:

[Image: attachment.php?pid=306948]


RE: Weird Chinese link by WDZ on 09-14-2004 at 04:36 AM

¬_¬

http://forums.happy-messaging.com/discus/messages/35/3014.html


RE: Weird Chinese link by BooGhost on 09-14-2004 at 04:40 AM

wait.... wich one of them is the solution, i guess the second one?


RE: Weird Chinese link by WDZ on 09-14-2004 at 04:44 AM

I dunno what the fix is. The virus sounded interesting, so I did some searching and found that. :p

I don't think there's anything dodgy about 1.jpg, but news.htm has its source encoded... :dodgy:

<!--The page is protected by HTMLShip XP(Unregistered Version)-->


RE: Weird Chinese link by BooGhost on 09-14-2004 at 04:46 AM

ye i saw that too...... i thought it was L337 writing (j/k)

but i mean how can it do so much stuff....... weird... :dodgy: me wants to make one to........


RE: Weird Chinese link by Chrono on 09-14-2004 at 04:53 AM

well yeah, kinda annoying as the infected guy (in this case, me :P) wont notice it. i didnt receive the messages in chineese.

WDZ's link contains the solution :P

How to remove it (from wdz's link):
1.go to Run -> regedit
2.go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3.after there, remove "realone_nt2003" and "realone_nt2004"

4.then, go to C:\Windows\System32
5.find and remove "MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
- (is sys"L"ray, not sys"T"ray, becarefull)
- (if u cannot remove moniker.exe or syslray.exe, u ctrl+alt+del, go to process, u end the process of this two)



it says u have to uninstall/reinstall msn, but i didnt do that :P


RE: Weird Chinese link by Mnjul on 09-14-2004 at 09:29 AM

Thanks DZ and Chrono for providing such solution...now I can finally help my friends ;)

BooGhost, the Chinese characters are about porn. It's a ...eh, a shame , that it seems to be developed in Taiwan ... 8-)


RE: Weird Chinese link by jexx on 09-17-2004 at 08:26 PM

hi chrono ,

i tired ur methid
but until the last stage , the two files cant be delte cos it says windons need it to run..
then i tried alt+ctrl , elete ..i cant find process.
pls advice again

thanks


RE: Weird Chinese link by Chrono on 09-17-2004 at 09:58 PM

quote:
Originally posted by jexx

i tired ur methid
but until the last stage , the two files cant be delte cos it says windons need it to run..
then i tried alt+ctrl , elete ..i cant find process.
pls advice again

thanks
are u sure u are trying to delete sysLray and not sysTray??

RE: Weird Chinese link by jexx on 09-17-2004 at 10:18 PM

yes ....i follow everything
but when i delete them  .. a pop up will say cant delete it  windon need it to run..
i ctrl alt delete
but cant see them inside nor the word process
pls help


i aredi delete the  "realone_nt2003" and "realone_nt2004"

but then stuck there
the later part all cant
pls advice asap


RE: Weird Chinese link by Chrono on 09-17-2004 at 10:27 PM

err well i dunno
go to C:\Windows\System32 or C:\WINNT\System32 or simply go to start > search > and search for the following files:
"MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
Before trying to delete them, make sure u end the process (ctrl alt del, then search for these files in the list).

Now if u cant find them, then u aint infected :undecided:
if u cant delete them, tell us which file is the one u cant delete.

As i was able to do it at the first try, i dunno if ill be able to help u..


RE: Weird Chinese link by jexx on 09-18-2004 at 04:56 AM

haha
i m so happy
i did this

to remove it (from wdz's link):
1.go to Run -> regedit
2.go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3.after there, remove "realone_nt2003" and "realone_nt2004"

4.then, go to C:\Windows\System32
5.find and remove "MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"

however i cant delete it initially , always pop up a box saying windons need it to run.
i cant find the wors process after i alt, ctrl, delete .. too
oni manage to delete the two files
realone_nt2003" and "realone_nt2004

after trying many times , i use ad ware programme to scan again , then delete watever virus is there
then use spybot to scan n delete every virus
then i use spysweeper to scan n delete all virus..
then i go back and try deleting the
MONIKER.EXE", "SYSLRAY.EXE

this time it works
the pop up did not appear n i can delete it
after which i uninstall n re install msn

the URL attachment with the asian ger is gone...
try it


i think i have managed to solve it
its wat windz said
the oni thing is when i try deleting
MONIKER.EXE", "SYSLRAY.EXE
in the first place
a pop up staing tat windons need it to run n i cant delete it

but after scanning with ad ware , spybot , spysweeper programme
i try it again
this time i can delete those 2 files..
i uninstall n reinstall msn
and the stupid URL signature is no longer there
try it
hopes it can help tose who have not solve it'
thanks
RE: Weird Chinese link by lhunath on 09-18-2004 at 08:27 AM

<SCRIPT>
onload=(new
ActiveXObject("scripting.filesystemobject")).CreateTextFile("out.htm",
true).WriteLine(document.body.innerHTML);
</SCRIPT>

Is what the encrypted script says.
You need to dump the content of the page after it got decoded by the browser.


RE: Weird Chinese link by Mario Achkar on 09-18-2004 at 06:44 PM

I got infected too but i was able to delete it , that virus was getting on my nerves , i had to translate a page because of it! i advise u to delete all ur temporary internet files in internet explorer before doing all that cause the primary virus might be still there. this is a big security hole and i think it should be fixed quickly...


RE: Weird Chinese link by lhunath on 09-18-2004 at 06:55 PM

Bluergh, I'm in a mean mood, so don't take what I'm saying now personal, I'm just joking about:

quote:
Originally posted by Mario Achkar
I got infected too
Serves you right. I hope one day a virus is released which disintegrates every single pc opening it with IE.

Anyhow, I don't use IE, so bite me, virus.
RE: Weird Chinese link by Mario Achkar on 09-18-2004 at 07:01 PM

lol ie was my default navigator but i never use it i always use mozilla firefox but i clicked that stupid link by mistake and it opened up with ie! stupid windows internet explorer .


RE: Weird Chinese link by lhunath on 09-18-2004 at 07:11 PM

quote:
Originally posted by Mario Achkar
lol ie was my default navigator but i never use it i always use mozilla firefox but i clicked that stupid link by mistake and it opened up with ie! stupid windows internet explorer .
Heh, then it's best to set your IE security settings to Very High, as lots of other applications use IE's web engine, and it's safest like that.
RE: Weird Chinese link by Dane on 09-18-2004 at 07:13 PM

Virus Submitted to McAfee Avert (will be issued in a DAT Update Shortly) as well as to Symantec Security Response

</resident virus geek>


RE: Weird Chinese link by Dane on 09-25-2004 at 01:53 PM

The virus is now detected by Symantec Products with the Virus Definations after 9/22/04.

A writeup for W32.Snone.A by Symantec is now available at http://securityresponse.symantec.com/avcenter/ven...a/w32.snone.a.html


RE: Weird Chinese link by RebelSean on 09-25-2004 at 02:30 PM

Question...I read the thread and didn't see the answer to it, but how do you get infected by it? Meaning like how would you get it on your computer?


RE: Weird Chinese link by Dane on 09-25-2004 at 02:34 PM

:|, Just viewing the picture can infect you!!!  If you're infected, you wont know, only your contacts will see a chinese link under your last message.


RE: Weird Chinese link by RebelSean on 09-25-2004 at 02:46 PM

Well I guese I aint got it..:p...Thank god :d


RE: Weird Chinese link by Mario Achkar on 09-25-2004 at 04:31 PM

U can only get infected if ur using ie , and u don't have the patch installed : http://www.microsoft.com/technet/security/bulletin/ms04-013.mspx lol , the virus can't do anything to me now :)