中国DOS联盟论坛

China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --
Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
Guest | Log in | Register | Members | Search | China DOS Union
中国DOS联盟论坛
The time now is 2026-08-04 07:54
48,038 topics / 350,123 posts / today 0 new / 48,251 members
其它操作系统综合讨论区 » Reprint: Hazards and Removal of the New Happy Hour Virus "VBS.KJ"
Printable Version  2,120 / 3
Floor1 MYS Posted 2002-11-01 00:00
元老会员 Posts 1,637 Credits 5,170 From 广东佛山
Harm and Removal of the New Happy Time Virus "VBS.KJ"
Author: Kingsoft Anti-Virus Information Network

Introduction to the Virus Infection Process

VBS.KJ is a script-type virus that infects html/htm, jsp, vbs, php, asp. Similar to the Happy Time "VBS.HappyTime", this virus is written in VBScript language, spreads via email on the Internet, and can also infect files; after infection, the system resources of the infected machine are consumed in large quantities, and the speed slows down; it uses the Windows system's "Windows Explorer" for parasitism and infection.

However, compared with Happy Time, the VBS.KJ virus is obviously improved. First, each infection undergoes a mutation, which can escape the ordinary signature matching and searching method; second, this virus does not actively send emails! Instead, it modifies the settings of Microsoft Outlook Express, Microsoft Outlook 2000/XP in the system, uses html-formatted letterheads to compose emails, and the virus infects all letterheads! When sending an email, the virus will be attached to the email, which is more concealed! Third, it will infect files in formats such as html/htm, jsp, vbs, php, asp, and will not delete system files.

Files Generated and Modified by the Virus

1. Generate desktop.ini and folder.htt files under each detected folder (these two files control the display in Windows Explorer).
2. Generate kjwall.gif in %Windows%\web and %Windows%System32.
3. In Windows 9X system, generate %Windows%\System\Kernel.dll file; in Windows 2000/XP, generate %Windows%\System\Kernel32.dll file.
4. Infect htt files and attach the virus to them; infect html/htm, jsp, vbs, php, asp, and replace their contents with the virus.

Registry Modifications

1. Add the Kernel32 key value under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ to make the virus start with the system;
2. Modify HKEY_CLASSES_ROOT\dllFile\ to change the opening method of dll files;
3. Modify HKEY_CURRENT_USER\Identities\"&UserID&"\Software\Microsoft\Outlook Express\" & OEVersion&"\Mail\Compose Use Stationery" to 1, that is, use letterheads; modify HKEY_CURRENT_USER\Identities\"&UserId&"\Software\Microsoft\OutlookExpress\"&OEVersion&"\Mail\Stationery Name" to point to the letterhead file;
4. Modify HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail related contents to make Outlook 2000 use letterheads to compose emails;
5. Modify HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail related contents to make Outlook XP use letterheads to compose emails;

Signs of Virus Infection

1. There is a Kernel32 key value under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ and it points to the Kernel.dll or Kernel32.dll file;
2. There are a large number of desktop.ini and folder.htt in the system;
3. There is a kjwall.gif file in the system directory;

Manual Removal (Difficulty is relatively high, it is recommended to use antivirus software for virus removal)

1. Open the registry and delete the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Kernel32 key value;
Refer to other machines to restore the key values under HKEY_CLASSES_ROOT\dllFile\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Identities\"&UserID&"\Software\Microsoft\Outlook Express\"&OEVersion&"\Mail\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail\;

2. Delete files (it is recommended to do it in DOS state or use a third-party file management system, such as WinCommander, etc.)
Refer to other machines to restore the folder.htt file in the %Windows%\web directory;
Delete the Kernel32.dll or Kernel.dll file; delete kjwall.gif;
Find all files that have the KJ_start string and delete the virus code at the end of the file;

----------------------The following is what I wrote myself---------------------
The new Happy Time virus is relatively difficult to handle. It can spread through web pages, floppy disks, local area networks, emails, etc.
In my experience, the best tool to prevent it is Rising. Kingsoft Antivirus 2002 can't detect it after the upgrade, but its special-kill tool kills the virus faster than Rising.
Floor2 iiijtgeee Posted 2003-01-17 00:00
初级用户 Posts 3 Credits 106
There is.
The new Happy Time virus here can't be killed.
The whole network is occupied by the new Happy Time virus.
Even the memory is occupied.
A large amount of memory is occupied.
It's very annoying.
Floor3 MYS Posted 2003-01-18 00:00
元老会员 Posts 1,637 Credits 5,170 From 广东佛山
Ruishēng can completely kill and prevent it, but Kingsoft Antivirus can't. I haven't tried Jiangmin KV yet.
Floor4 Wengier Posted 2003-01-18 00:00
系统支持 Posts 10,521 Credits 27,736
Actually, it's very easy to check. You can use the command DIR FOLDER.HTT /A /S to check if the FOLDER.HTT file exists.
[ Contact the Union admin team - 中国DOS联盟 - Standard version ]
Sponsored by ifanr Inc | © 2001–2023