Results 1 to 8 of 8

Thread: Chinese Hacker-2 Infection

  1. #1

    Question Chinese Hacker-2 Infection

    Hello Friends,

    Okay, I have another problem. My School network is infected with some trojan / virus or what-ever it says:

    "My God! Some one killed Chinese Hacker-2 Monitor"

    And then the message keep coming on all PCs. We run Xps over most of the PC, linux PCs are not infected.

    How to remove this? Any resource or advise will be appreciated.

    Thanks in advance,
    Zeeshan Alam

  2. #2
    Senior Member
    Join Date
    Jul 2005
    Posts
    277
    have you ran a spyware/malware program yet?

    if not, run it in safe mode on the pc.

    If there is a quicker way to clean up across the network, one of the more
    experienced guys around here can help.

    If its the school network, hopefully you have admin rights to fix them.
    Difficult takes a day, Impossible takes a week~Kthln01!

  3. #3
    Senior Member
    Join Date
    May 2003
    Posts
    1,199
    are you sure its not somone messing with netsend?

    do you have an antivirus software installed? (if not slap your admin)

    Has the AV given you any indication what it is?

    where does this pop up? is it like a webpage pop-up, or like an error message, but with that message?

    do you have the messenger service disabled?

    we need WAY more information at this point.

    but here is a generic answer.

    Update all virus Definitions,
    Install something like adaware, update that
    unplug from the network
    restart in safemode,
    scan for viruses
    scan for adware.


    do it on one computer that is having the problem, to start with, find the problem before trying to fix it on every other computer.

    still having the problem, let us know.
    Everyone is going to die, I am just as good of a reason as any.

    http://think-smarter.blogspot.com

  4. #4
    Senior Member
    Join Date
    Jul 2005
    Posts
    277
    yeah at first it sounded like one of those programs that schools use to control the screens in computer labs. I figured that could be easily identified tho.
    Difficult takes a day, Impossible takes a week~Kthln01!

  5. #5
    Senior Member
    Join Date
    Dec 2004
    Posts
    3,171
    Hi AceSpy,

    Sorry nothing here...

    http://www.esafe.com/home/csrt/index.asp
    Virus Updates - Virus Alerts

    or here...

    http://www.us-cert.gov/cas/bulletins/SB05-089.html
    US-CERT Cyber Security Bulletin

    ( which is updated till August 2nd )


    But I did find someone else who has the same problem...unfortuately no solution...

    http://www.google.ca/url?sa=t&ct=res...FMzE4QGfooSLDg
    Microsoft ISA Server Message Boards: About Chinese hacker-2 Monitor

    so...I don't think it'd be a school problem.

    Also came across a Chinese guy calling himself Hacker2 who has a major hate on for the Japanese...and some game references to kills by and of a Hacker2



    Eg

  6. #6
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    May I be the first to congratulate your school's it administrators?

    http://vil.nai.com/vil/content/v_99518.htm

    McAfee's analysis of it.

    This malware is THREE YEARS OLD so, unless this is a brand new variant, any decent AV product should detect it.


  7. #7
    Thank you Mr. Nihil and all other guys for answering. So all end up with a Worm! Sux! I will install McAfee to ensure its removal. I will also try to remove it manually.

    Yeah, the dept. Administration SUX! All they know to solve a problem is to format the HDD.

    Thanks again,
    Zeeshan Alam

  8. #8
    Senior Member nihil's Avatar
    Join Date
    Jul 2003
    Location
    United Kingdom: Bridlington
    Posts
    17,188
    Hi Zeeshan,

    Please go here:

    http://www.diamondcs.com.au/index.php?page=products

    There are a number of useful tools, but the one your school might find particularly useful is "RegistryProt" This will warn you of additions and amendments to the Registry, and let you reverse them.

    These products are free, even for institutions

    Good luck, and remember when you are fighting malware it is best to run your tools in SAFE MODE

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •