Harm and Removal of the New Happy Time Virus "VBS.KJ"
Author: Kingsoft Anti-Virus Information Network
Introduction to the Virus Infection Process
VBS.KJ is a script-type virus that infects html/htm, jsp, vbs, php, asp. Similar to the Happy Time "VBS.HappyTime", this virus is written in VBScript language, spreads via email on the Internet, and can also infect files; after infection, the system resources of the infected machine are consumed in large quantities, and the speed slows down; it uses the Windows system's "Windows Explorer" for parasitism and infection.
However, compared with Happy Time, the VBS.KJ virus is obviously improved. First, each infection undergoes a mutation, which can escape the ordinary signature matching and searching method; second, this virus does not actively send emails! Instead, it modifies the settings of Microsoft Outlook Express, Microsoft Outlook 2000/XP in the system, uses html-formatted letterheads to compose emails, and the virus infects all letterheads! When sending an email, the virus will be attached to the email, which is more concealed! Third, it will infect files in formats such as html/htm, jsp, vbs, php, asp, and will not delete system files.
Files Generated and Modified by the Virus
1. Generate desktop.ini and folder.htt files under each detected folder (these two files control the display in Windows Explorer).
2. Generate kjwall.gif in %Windows%\web and %Windows%System32.
3. In Windows 9X system, generate %Windows%\System\Kernel.dll file; in Windows 2000/XP, generate %Windows%\System\Kernel32.dll file.
4. Infect htt files and attach the virus to them; infect html/htm, jsp, vbs, php, asp, and replace their contents with the virus.
Registry Modifications
1. Add the Kernel32 key value under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ to make the virus start with the system;
2. Modify HKEY_CLASSES_ROOT\dllFile\ to change the opening method of dll files;
3. Modify HKEY_CURRENT_USER\Identities\"&UserID&"\Software\Microsoft\Outlook Express\" & OEVersion&"\Mail\Compose Use Stationery" to 1, that is, use letterheads; modify HKEY_CURRENT_USER\Identities\"&UserId&"\Software\Microsoft\OutlookExpress\"&OEVersion&"\Mail\Stationery Name" to point to the letterhead file;
4. Modify HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail related contents to make Outlook 2000 use letterheads to compose emails;
5. Modify HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail related contents to make Outlook XP use letterheads to compose emails;
Signs of Virus Infection
1. There is a Kernel32 key value under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ and it points to the Kernel.dll or Kernel32.dll file;
2. There are a large number of desktop.ini and folder.htt in the system;
3. There is a kjwall.gif file in the system directory;
Manual Removal (Difficulty is relatively high, it is recommended to use antivirus software for virus removal)
1. Open the registry and delete the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Kernel32 key value;
Refer to other machines to restore the key values under HKEY_CLASSES_ROOT\dllFile\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Identities\"&UserID&"\Software\Microsoft\Outlook Express\"&OEVersion&"\Mail\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail\;
2. Delete files (it is recommended to do it in DOS state or use a third-party file management system, such as WinCommander, etc.)
Refer to other machines to restore the folder.htt file in the %Windows%\web directory;
Delete the Kernel32.dll or Kernel.dll file; delete kjwall.gif;
Find all files that have the KJ_start string and delete the virus code at the end of the file;
----------------------The following is what I wrote myself---------------------
The new Happy Time virus is relatively difficult to handle. It can spread through web pages, floppy disks, local area networks, emails, etc.
In my experience, the best tool to prevent it is Rising. Kingsoft Antivirus 2002 can't detect it after the upgrade, but its special-kill tool kills the virus faster than Rising.
Author: Kingsoft Anti-Virus Information Network
Introduction to the Virus Infection Process
VBS.KJ is a script-type virus that infects html/htm, jsp, vbs, php, asp. Similar to the Happy Time "VBS.HappyTime", this virus is written in VBScript language, spreads via email on the Internet, and can also infect files; after infection, the system resources of the infected machine are consumed in large quantities, and the speed slows down; it uses the Windows system's "Windows Explorer" for parasitism and infection.
However, compared with Happy Time, the VBS.KJ virus is obviously improved. First, each infection undergoes a mutation, which can escape the ordinary signature matching and searching method; second, this virus does not actively send emails! Instead, it modifies the settings of Microsoft Outlook Express, Microsoft Outlook 2000/XP in the system, uses html-formatted letterheads to compose emails, and the virus infects all letterheads! When sending an email, the virus will be attached to the email, which is more concealed! Third, it will infect files in formats such as html/htm, jsp, vbs, php, asp, and will not delete system files.
Files Generated and Modified by the Virus
1. Generate desktop.ini and folder.htt files under each detected folder (these two files control the display in Windows Explorer).
2. Generate kjwall.gif in %Windows%\web and %Windows%System32.
3. In Windows 9X system, generate %Windows%\System\Kernel.dll file; in Windows 2000/XP, generate %Windows%\System\Kernel32.dll file.
4. Infect htt files and attach the virus to them; infect html/htm, jsp, vbs, php, asp, and replace their contents with the virus.
Registry Modifications
1. Add the Kernel32 key value under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ to make the virus start with the system;
2. Modify HKEY_CLASSES_ROOT\dllFile\ to change the opening method of dll files;
3. Modify HKEY_CURRENT_USER\Identities\"&UserID&"\Software\Microsoft\Outlook Express\" & OEVersion&"\Mail\Compose Use Stationery" to 1, that is, use letterheads; modify HKEY_CURRENT_USER\Identities\"&UserId&"\Software\Microsoft\OutlookExpress\"&OEVersion&"\Mail\Stationery Name" to point to the letterhead file;
4. Modify HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail related contents to make Outlook 2000 use letterheads to compose emails;
5. Modify HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail related contents to make Outlook XP use letterheads to compose emails;
Signs of Virus Infection
1. There is a Kernel32 key value under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ and it points to the Kernel.dll or Kernel32.dll file;
2. There are a large number of desktop.ini and folder.htt in the system;
3. There is a kjwall.gif file in the system directory;
Manual Removal (Difficulty is relatively high, it is recommended to use antivirus software for virus removal)
1. Open the registry and delete the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Kernel32 key value;
Refer to other machines to restore the key values under HKEY_CLASSES_ROOT\dllFile\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Identities\"&UserID&"\Software\Microsoft\Outlook Express\"&OEVersion&"\Mail\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail\;
Refer to other machines to restore the relevant key values under HKEY_CURRENT_USER\Software\Microsoft\Office\10.0\Outlook\Options\Mail\;
2. Delete files (it is recommended to do it in DOS state or use a third-party file management system, such as WinCommander, etc.)
Refer to other machines to restore the folder.htt file in the %Windows%\web directory;
Delete the Kernel32.dll or Kernel.dll file; delete kjwall.gif;
Find all files that have the KJ_start string and delete the virus code at the end of the file;
----------------------The following is what I wrote myself---------------------
The new Happy Time virus is relatively difficult to handle. It can spread through web pages, floppy disks, local area networks, emails, etc.
In my experience, the best tool to prevent it is Rising. Kingsoft Antivirus 2002 can't detect it after the upgrade, but its special-kill tool kills the virus faster than Rising.
我的网志
http://hzmys.blog.163.com/
我的网盘
firststep.qjwm.com
fsmys.ys168.com
ssmys.ys168.com
www.brsbox.com/fsmys
www.brsbox.com/ssmys
www.brsbox.com/ccdos
http://hzmys.blog.163.com/
我的网盘
firststep.qjwm.com
fsmys.ys168.com
ssmys.ys168.com
www.brsbox.com/fsmys
www.brsbox.com/ssmys
www.brsbox.com/ccdos


