HELP! Chinese to Hacker-2 Monitor Worm.

HELP! Chinese to Hacker-2 Monitor Worm.

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
HELP! Chinese to Hacker-2 Monitor Worm. Bozeman 08-07-2006
Posted by David H. Lipman on August 7, 2006, 10:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| When attempting to run the command prompt, I am given another window that
| states:
|
| (16 bit MS-DOS Subsystem)
| C:\WINDOWS\System32\command.com
| C:\PROGRA~1\Symantec\S32EVNT1.DLL. An installable Virtual Device Driver
| failed DII initialization. Choose 'Close' to terminate the applications.
|
| I click close, and the program closes.
| I click ignore, and the prompt does not recognize your given commands. Advice
|
| Thanks so much for your help thus far!
|


Go to ...
Start --> Run
enter; %windir%\system32\services.msc

Find; "Messenger"

"Stop" the Service
"Disable" the Service.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?UGFuZGFfbWFu?= on August 8, 2006, 5:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Useful tips:

It appears to be you are running non-SP2 Windows XP

Make sure your Internet Connection Firewall is ENABLED using the
instructions here
http://www.microsoft.com/windowsxp/using/networking/learnmore/icf.mspx

If you are home user and you do not share your your hard drive with
friends/family , make sure you goto Control Panel-> Network Connection and
right click on every connection you have and then UNCHECK File and Printer
sharing

Make sure your have up-to-date antivirus and antuspyware softwares

Service Pack 2 for Windows XP:
http://www.microsoft.com/windowsxp/sp2/default.mspx

Protect your PC:
http://www.microsoft.com/protect


--
Panda_man
Bronze level Contributor

Posted by Malke on August 7, 2006, 8:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Bozeman wrote:

> yes, yes it does.
>
> "David H. Lipman" wrote:
>
>>
>> | Help the computer challenged! I get a windows message every minute
>> | from "RABIE to WORKGROUP" claiming that "some one killed
>> | ChineseHacker-2 Monitor".
>> |
>> | How do I get a patch...or rid my system of this?
>> |
>> | I have Internet Explorer Version 6.0. Thanks!!!!
>>
>> Does the border of the Pop-Up Window indicate; "Messenger Service" ?

This means that you have Windows XP and 1) you don't have a firewall; 2) you
haven't applied Service Pack 2. Take the computer off the Internet and any
local area network and clean it up by going through these removal steps
systematically:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

If you don't have a current version antivirus installed, then follow the
instructions to scan with either Sysclean or Multi_AV. If this is your
case, I would also include scanning with Ewido.

Once you are absolutely sure your computer is clean, do the preparatory work
for SP2 (including backing up your data), install it, use the SP2 Windows
Firewall, and then go on line and get the subsequent Windows Updates.

Here are links to help you prepare for SP2:

Are You Ready for WinXP SP2? -
http://support.microsoft.com/default.aspx?pr=windowsxpsp2

Download full SP2 - http://tinyurl.com/5bobl

Order SP2 on CD from MS - http://tinyurl.com/6g675

Follow the Service Pack Installation Checklist -
http://www3.telus.net/dandemar/spackins.htm

SP2 links to OEMs - http://www.microsoft.com/windowsxp/sp2/oemlinks.mspx

http://aumha.net - See SP2 forums

http://www.kellys-korner-xp.com/xp_s.htm#sp2 - Windows SP2 Information,
Guidelines and Troubleshooting

http://www.michna.com/kb/WxSP2.htm#General

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a professional computer repair
shop (not your local version of BigStoreUSA).

Malke
--
MS-MVP Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"

Posted by Marek Kalisz on August 8, 2006, 4:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
It might have nothing to do with your current problem but the word:
"Chinese" clicked something in my memory.
A few years ago, at different times, I was looking for the replacement
systems. Three times I ordered custom build (instead of assembling myself -
lack of time) systems from shops - happened to be run by Chinese. Many
parts (I realized) were made in China (Taiwan or mainland, whatever). It
cost me also less then similar configurations from known makers.
Everything worked fine but soon I started to have some strange not only
feeling but some blinking for a moment at the corner of screen small
windows, etc. AV couldn't catch anything. Often, on two systems, during
reboot or turning off I saw small casual window closing program named: "you
can not see me..." I searched for the program/process with similar name or
containing this expression - with available then tools couldn't find any
visible on my systems. Finally I decided to take systems apart, put them
back and reinstall XPs from scratch. Somehow it helped.
Then in my paranoid mind something started to click. In late 90s and early
2000s I observed a lot of small computer shops or distributors offering much
cheaper parts and services than others - run by Chinese. They were and are
everywhere around country. Idiotic idea: maybe some of those were setting
some gadgets (even on motherboards) that allowed them to monitor customer's
system and traffic and (for some reason) collect those information from
behind any firewalls, AV, etc. without even our, customers, slight
realization?
Idiotic thought.
Maybe.
Maybe not.
Marek Kalisz

> Help the computer challenged! I get a windows message every minute from
> "RABIE to WORKGROUP" claiming that "some one killed ChineseHacker-2
> Monitor".
>
>
> How do I get a patch...or rid my system of this?
>
> I have Internet Explorer Version 6.0. Thanks!!!!



Similar ThreadsPosted
PC ACME Keylogger Monitor...can't uninstall March 10, 2006, 10:06 pm
Is monitor.exe in ZoneAlarm directory a keylogger? May 27, 2007, 2:34 pm
Virus Makes Monitor Go Black Upon Detection July 20, 2006, 12:06 pm
Worm VB.AS Aliases W32.Alcra.B and W32/Alcan.worm!p2p July 18, 2005, 8:37 am
WORM/DELF.FPV - new worm?? January 14, 2008, 6:58 am
new worm? June 20, 2006, 5:09 am
new worm i think November 22, 2006, 6:15 pm
RE NEW WORM November 23, 2006, 5:24 pm
Worm? November 11, 2008, 1:17 pm
Virus/worm? October 25, 2005, 2:29 am

The site map in XML format XML site map

Contact Us | Privacy Policy