Weird Chinese link |
Author: |
Message: |
Chrono
forum admin
;o
Posts: 6022 Reputation: 116
39 / /
Joined: Apr 2002
Status: Away
|
RE: Weird Chinese link
err well i dunno
go to C:\Windows\System32 or C:\WINNT\System32 or simply go to start > search > and search for the following files:
"MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
Before trying to delete them, make sure u end the process (ctrl alt del, then search for these files in the list).
Now if u cant find them, then u aint infected
if u cant delete them, tell us which file is the one u cant delete.
As i was able to do it at the first try, i dunno if ill be able to help u..
|
|
09-17-2004 10:27 PM |
|
|
jexx
New Member
Posts: 5
Joined: Sep 2004
|
RE: Weird Chinese link
haha
i m so happy
i did this
to remove it (from wdz's link):
1.go to Run -> regedit
2.go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
3.after there, remove "realone_nt2003" and "realone_nt2004"
4.then, go to C:\Windows\System32
5.find and remove "MONIKER.EXE", "SYSLRAY.EXE", "HKT1.DLL"
however i cant delete it initially , always pop up a box saying windons need it to run.
i cant find the wors process after i alt, ctrl, delete .. too
oni manage to delete the two files
realone_nt2003" and "realone_nt2004
after trying many times , i use ad ware programme to scan again , then delete watever virus is there
then use spybot to scan n delete every virus
then i use spysweeper to scan n delete all virus..
then i go back and try deleting the
MONIKER.EXE", "SYSLRAY.EXE
this time it works
the pop up did not appear n i can delete it
after which i uninstall n re install msn
the URL attachment with the asian ger is gone...
try it
i think i have managed to solve it
its wat windz said
the oni thing is when i try deleting
MONIKER.EXE", "SYSLRAY.EXE
in the first place
a pop up staing tat windons need it to run n i cant delete it
but after scanning with ad ware , spybot , spysweeper programme
i try it again
this time i can delete those 2 files..
i uninstall n reinstall msn
and the stupid URL signature is no longer there
try it
hopes it can help tose who have not solve it'
thanks
This post was edited on 09-18-2004 at 05:11 AM by WDZ.
|
|
09-18-2004 04:56 AM |
|
|
lhunath
Full Member
.{ Lord Daisy }.
Posts: 343
40 / / –
Joined: May 2004
|
RE: Weird Chinese link
<SCRIPT>
onload=(new
ActiveXObject("scripting.filesystemobject")).CreateTextFile("out.htm",
true).WriteLine(document.body.innerHTML);
</SCRIPT>
Is what the encrypted script says.
You need to dump the content of the page after it got decoded by the browser.
This post was edited on 09-18-2004 at 08:28 AM by lhunath.
{ - - }
|
|
09-18-2004 08:27 AM |
|
|
Mario Achkar
Scripting Contest Winner
Coding The Future...
Posts: 13
35 / / –
Joined: Aug 2004
|
RE: Weird Chinese link
I got infected too but i was able to delete it , that virus was getting on my nerves , i had to translate a page because of it! i advise u to delete all ur temporary internet files in internet explorer before doing all that cause the primary virus might be still there. this is a big security hole and i think it should be fixed quickly...
|
|
09-18-2004 06:44 PM |
|
|
lhunath
Full Member
.{ Lord Daisy }.
Posts: 343
40 / / –
Joined: May 2004
|
RE: Weird Chinese link
Bluergh, I'm in a mean mood, so don't take what I'm saying now personal, I'm just joking about:
quote: Originally posted by Mario Achkar
I got infected too
Serves you right. I hope one day a virus is released which disintegrates every single pc opening it with IE.
Anyhow, I don't use IE, so bite me, virus.
{ - - }
|
|
09-18-2004 06:55 PM |
|
|
Mario Achkar
Scripting Contest Winner
Coding The Future...
Posts: 13
35 / / –
Joined: Aug 2004
|
RE: Weird Chinese link
lol ie was my default navigator but i never use it i always use mozilla firefox but i clicked that stupid link by mistake and it opened up with ie! stupid windows internet explorer .
|
|
09-18-2004 07:01 PM |
|
|
lhunath
Full Member
.{ Lord Daisy }.
Posts: 343
40 / / –
Joined: May 2004
|
RE: Weird Chinese link
quote: Originally posted by Mario Achkar
lol ie was my default navigator but i never use it i always use mozilla firefox but i clicked that stupid link by mistake and it opened up with ie! stupid windows internet explorer .
Heh, then it's best to set your IE security settings to Very High, as lots of other applications use IE's web engine, and it's safest like that.
{ - - }
|
|
09-18-2004 07:11 PM |
|
|
Dane
Non-Elite Member
Dont ask to ask, just ASK!
Posts: 1621 Reputation: 52
35 / /
Joined: Dec 2002
Status: Away
|
RE: Weird Chinese link
Virus Submitted to McAfee Avert (will be issued in a DAT Update Shortly) as well as to Symantec Security Response
</resident virus geek>
|
|
09-18-2004 07:13 PM |
|
|
Dane
Non-Elite Member
Dont ask to ask, just ASK!
Posts: 1621 Reputation: 52
35 / /
Joined: Dec 2002
Status: Away
|
|
09-25-2004 01:53 PM |
|
|
RebelSean
Veteran Member
Microsoft Evangelist
Posts: 2602 Reputation: 59
34 / /
Joined: May 2004
Status: Away
|
RE: Weird Chinese link
Question...I read the thread and didn't see the answer to it, but how do you get infected by it? Meaning like how would you get it on your computer?
|
|
09-25-2004 02:30 PM |
|
|
Pages: (3):
« First
«
1
[ 2 ]
3
»
Last »
|
|