China DOS Union

-- Unite DOS · Advance DOS · Grow DOS --

Union site: www.cn-dos.net Forum site: www.cn-dos.net/forum
DOS stands for freedom, openness and progress. Let us work hard, learn from the openness and GNU spirit of FreeDOS and Linux, and together build and grow a free GNU GPL world!

中国DOS联盟论坛
The time now is 2026-08-25 23:28
中国DOS联盟论坛 » 其它操作系统综合讨论区 » [Help] !!!!!!!!! Experts, please answer this.... View 738 Replies 3
Original Poster Posted 2003-09-04 00:00 ·  中国 天津 联通
初级用户
Credits 107
Posts 2
Joined 2003-09-04 00:00
22-year member
UID 9409
Gender Male
Status Offline
My system is WIN2K, and I have Skynet Firewall installed.
Recently, whenever I go online, Skynet keeps showing that many other IPs are trying to PING my host.
And I found that in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RUN\
it shows c:\winnt\system\kernel32.dll

What does this mean??? Have I been hit by a newer version of the Glacier Trojan??
Could some expert please give me an answer, many thanks!!!!!!!!!!
Floor 2 Posted 2003-09-04 00:00 ·  中国 河北 石家庄 联通
银牌会员
★★★
Credits 1,835
Posts 648
Joined 2002-11-08 00:00
23-year member
UID 197
Gender Male
Status Offline
Being PINGed is a common phenomenon
and the c:\winnt\system\kernel32.dll under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RUN\
could be a Trojan or something like that. Find an antivirus program and check it.
Floor 3 Posted 2003-09-04 00:00 ·  中国 天津 联通
初级用户
Credits 107
Posts 2
Joined 2003-09-04 00:00
22-year member
UID 9409
Gender Male
Status Offline
What Trojan is this????
Could an expert explain it!!!!!!!!!!
Floor 4 Posted 2003-09-04 00:00 ·  中国 广东 广州 联通
银牌会员
★★★
Credits 1,451
Posts 446
Joined 2002-10-20 00:00
23-year member
UID 29
Gender Male
Status Offline
New Happy Time is the Chinese name of this virus; its English names include (the corresponding vendors are in brackets): HTML.Redlof.A , VBS.Redlof , VBS_REDLOF.A , VBS/Redlof-A , VBS.KJ , Script.RedLof , VBS/KJ .
This virus is a polymorphic, encrypted virus written in VBS. It infects files with the extensions .html, .htm, .asp, .php, .jsp, .htt, and .vbs. At the same time, it generates large numbers of folder.htt and desktop.ini files, and creates a file named Kernel.dll in %windir%\System\ (Windows 9x/Me) or Kernel32.dll (Windows NT/2000), modifies the open association for .dll files, and infects Outlook stationery files.
(Note: %windir% refers to the Windows directory. For Win9x/Me systems, this directory is usually \Windows; for Windows NT/2000, this directory is usually \WinNT. Pay special attention: the paths where these two Kernel files are generated are both %windir%\System\, not %windir%\System32\.)
After being infected with this virus, there are two obvious symptoms:
a. folder.htt (infected file) and desktop.ini (directory configuration file) will be generated in every directory;
b. the computer becomes obviously slower, and you can see a large number of Wscript.exe programs running in the task list.
For more detailed information, please refer to the relevant materials.
Forum Jump: