http://www.nhanhlen.com/  -- is it infected by virus.

http://www.nhanhlen.com/ -- is it infected by virus.

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
http://www.nhanhlen.com/ -- is it infected by virus. 2Sweet 01-15-2008
Posted by 2Sweet on January 15, 2008, 3:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
When double-click 'C' or 'D' drive in "My Computer", it goes to the link
http://www.nhanhlen.com/ intead of showing the content of the drive.
Could it be the workstation infected by virus? Symantec antivirus did not
detect virus after performed a full scan.



Posted by Volodymyr Shcherbyna on January 15, 2008, 3:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
This can be an adware, which is represented as BHO (Browser Helper Object)
which hooks DocumentComplete & BeforeNavigate events, since when you go to
some folder location, these events are fired, adware takes control,
retrieves the path of a folder, and makes popup.

Try to change the AV, or try to remove the registered BHO extension.

--
Volodymyr

> When double-click 'C' or 'D' drive in "My Computer", it goes to the link
> http://www.nhanhlen.com/ intead of showing the content of the drive.
> Could it be the workstation infected by virus? Symantec antivirus did not
> detect virus after performed a full scan.
>



Posted by 2Sweet on January 15, 2008, 4:22 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the response!
Can guide me how to remove the registered BHO extension?


> This can be an adware, which is represented as BHO (Browser Helper Object)
> which hooks DocumentComplete & BeforeNavigate events, since when you go to
> some folder location, these events are fired, adware takes control,
> retrieves the path of a folder, and makes popup.
>
> Try to change the AV, or try to remove the registered BHO extension.
>
> --
> Volodymyr
>
>> When double-click 'C' or 'D' drive in "My Computer", it goes to the link
>> http://www.nhanhlen.com/ intead of showing the content of the drive.
>> Could it be the workstation infected by virus? Symantec antivirus did
>> not detect virus after performed a full scan.
>>
>
>



Posted by Volodymyr Shcherbyna on January 15, 2008, 4:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
http://www.microsoft.com/windowsxp/using/web/sp2_addonmanager.mspx

But usually, I open regedit and look at the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects

It contains list of GUIDS - these are class ids of COM extensions (in a
simple words, GUID is some long and strange number). Basically, edit the
GUID, for example, my first GUID is:

I just edit it by changing the first elements,
and then you can try to check, whether
the bug disappeared or not. If not, restore the original value of GUID and
play with second GUID.

Also, remember, that adwares and other crap tryies to restore it's GUIDs in
BHO registry keys. So, if you delete the entry from registry, it appears
there again within second. This also can be checked.

--
Volodymyr

> Thanks for the response!
> Can guide me how to remove the registered BHO extension?
>
>
>> This can be an adware, which is represented as BHO (Browser Helper
>> Object) which hooks DocumentComplete & BeforeNavigate events, since when
>> you go to some folder location, these events are fired, adware takes
>> control, retrieves the path of a folder, and makes popup.
>>
>> Try to change the AV, or try to remove the registered BHO extension.
>>
>> --
>> Volodymyr
>>
>>> When double-click 'C' or 'D' drive in "My Computer", it goes to the link
>>> http://www.nhanhlen.com/ intead of showing the content of the drive.
>>> Could it be the workstation infected by virus? Symantec antivirus did
>>> not detect virus after performed a full scan.
>>>
>>
>>
>
>



Posted by Volodymyr Shcherbyna on January 15, 2008, 4:51 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Also, this tool:
http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx will help you
to manage explorer's BHO's.

--
Volodymyr
> http://www.microsoft.com/windowsxp/using/web/sp2_addonmanager.mspx
>
> But usually, I open regedit and look at the following key:
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
> Helper Objects
>
> It contains list of GUIDS - these are class ids of COM extensions (in a
> simple words, GUID is some long and strange number). Basically, edit the
> GUID, for example, my first GUID is:
>
>
> I just edit it by changing the first elements,
> and then you can try to check,
> whether the bug disappeared or not. If not, restore the original value of
> GUID and play with second GUID.
>
> Also, remember, that adwares and other crap tryies to restore it's GUIDs
> in BHO registry keys. So, if you delete the entry from registry, it
> appears there again within second. This also can be checked.
>
> --
> Volodymyr
>
>> Thanks for the response!
>> Can guide me how to remove the registered BHO extension?
>>
>>
>>> This can be an adware, which is represented as BHO (Browser Helper
>>> Object) which hooks DocumentComplete & BeforeNavigate events, since when
>>> you go to some folder location, these events are fired, adware takes
>>> control, retrieves the path of a folder, and makes popup.
>>>
>>> Try to change the AV, or try to remove the registered BHO extension.
>>>
>>> --
>>> Volodymyr
>>>
>>>> When double-click 'C' or 'D' drive in "My Computer", it goes to the
>>>> link http://www.nhanhlen.com/ intead of showing the content of the
>>>> drive.
>>>> Could it be the workstation infected by virus? Symantec antivirus did
>>>> not detect virus after performed a full scan.
>>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
How to get infected by virus? February 15, 2007, 10:18 pm
pc infected but cannot find the virus February 5, 2006, 11:35 am
Re: Infected with Sohanad-O virus November 24, 2007, 1:56 am
virus alert "your computer is infected" ?? March 26, 2006, 6:33 am
Re: Server Infected by virus and unable to clean May 31, 2007, 2:04 am
http://spaces.msn.com/dvdbarato/ March 6, 2006, 6:04 pm
http://www.tech-forum.perfectschools.com May 21, 2006, 11:17 am
hey, is this you? http://www.imstuff.us/profile.php?msn=username@hotmail.com February 18, 2006, 9:51 am
Attempted Intrusion "HTTP Macromedia Long Filename BO" from your April 1, 2007, 7:02 pm
Send Free SMS Worlwide to any mobile phone iphone gsm http://free4sms.info November 28, 2008, 10:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy