![]() |
China DOS Union-- Unite DOS · Advance DOS · Grow DOS --Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum |
| Guest | Log in | Register | Members | Search | China DOS Union |
|
中国DOS联盟论坛 The time now is 2026-08-25 21:49 |
47,812 topics / 349,910 posts / today 0 new / 48,264 members |
| 其它操作系统综合讨论区 » [Help] !!!!!!!!! Experts, please answer this.... |
| Printable Version 735 / 3 |
| Floor1 kaytur | Posted 2003-09-04 00:00 |
| 初级用户 Posts 2 Credits 107 | |
|
My system is WIN2K, and I have Skynet Firewall installed.
Recently, whenever I go online, Skynet keeps showing that many other IPs are trying to PING my host. And I found that in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RUN\ it shows c:\winnt\system\kernel32.dll What does this mean??? Have I been hit by a newer version of the Glacier Trojan?? Could some expert please give me an answer, many thanks!!!!!!!!!! |
|
| Floor2 LanE | Posted 2003-09-04 00:00 |
| 银牌会员 Posts 648 Credits 1,835 | |
|
Being PINGed is a common phenomenon
and the c:\winnt\system\kernel32.dll under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RUN\ could be a Trojan or something like that. Find an antivirus program and check it. |
|
| Floor3 kaytur | Posted 2003-09-04 00:00 |
| 初级用户 Posts 2 Credits 107 | |
|
What Trojan is this????
Could an expert explain it!!!!!!!!!! |
|
| Floor4 pfox | Posted 2003-09-04 00:00 |
| 银牌会员 Posts 446 Credits 1,451 | |
|
New Happy Time is the Chinese name of this virus; its English names include (the corresponding vendors are in brackets): HTML.Redlof.A , VBS.Redlof , VBS_REDLOF.A , VBS/Redlof-A , VBS.KJ , Script.RedLof , VBS/KJ .
This virus is a polymorphic, encrypted virus written in VBS. It infects files with the extensions .html, .htm, .asp, .php, .jsp, .htt, and .vbs. At the same time, it generates large numbers of folder.htt and desktop.ini files, and creates a file named Kernel.dll in %windir%\System\ (Windows 9x/Me) or Kernel32.dll (Windows NT/2000), modifies the open association for .dll files, and infects Outlook stationery files. (Note: %windir% refers to the Windows directory. For Win9x/Me systems, this directory is usually \Windows; for Windows NT/2000, this directory is usually \WinNT. Pay special attention: the paths where these two Kernel files are generated are both %windir%\System\, not %windir%\System32\.) After being infected with this virus, there are two obvious symptoms: a. folder.htt (infected file) and desktop.ini (directory configuration file) will be generated in every directory; b. the computer becomes obviously slower, and you can see a large number of Wscript.exe programs running in the task list. For more detailed information, please refer to the relevant materials. |
|
|
[ Contact the Union admin team -
中国DOS联盟 -
Standard version ] Sponsored by ifanr Inc | © 2001–2023 |