problem with hao123.com

Chat & Discussion about the general, everyday stuff
Official Member
User avatar
Posts: 150
Joined: Mon Mar 26, 2007 0:00
Location: France

problem with hao123.com

Postby Lady_Deadly_Nade » Wed Aug 15, 2007 11:40

DO NOT OPEN THAT CITE!

Hi guys, 2 days ago the lady that i care of looked for a producer of natural products from India on Google. Then she saw on the right of the screen commercials, she clicked the page and what we have : hao123... bla bla. A chianese website for meetings or whatever i didnt saw good cause i opened only its desription. So the problem came after she visited it. Somehow in her startup menu this adress is written as startup page, and when she open a window on Firefox or I.E. she have in the space up the cite adress but nothing else no info nothing... just white screen 8O So that startup menu is INACTIF and when i click on it its written 'what's that' and normally we can change the page with whatever we want. And the most curious is that she is connected on internet but no website can be opened normally. And + the website is classified as dangerous site by her antivirous.
And i cant really work with bios i mean i can but i think it will be nice if someone have some solutions or i ll just reinstall her windows .. OO Thnks a lot ..

Veteran
User avatar
Posts: 413
Joined: Tue Jun 06, 2006 0:00
Location: BZH

Postby Millenium » Wed Aug 15, 2007 12:02

Hmm this is a very known thing when surfing the web, happened to me severals times on several sites at my beginning.
If you're lucky you can find a prog especially for this problem (try the name under wich one your anti vir recognize it on google ) or you have to test X number of anti-vir, anti spywares, anti bar adress ....wich is very borying :p

Hmm in my noob opinion you'll have a better result in re-installing all your windows partition :s and immediately do your updates.

Hope that will help !!

Mill

EDIT: Dont smoke too much of Indians Natural products !! :P

Spam Noob
User avatar
Posts: 6
Joined: Sun Nov 26, 2006 1:00

Postby Xavandy » Wed Aug 15, 2007 14:36

maybe this Trojan? http://www.sophos.com/security/analyses ... stsal.html
or
http://www.sophos.com/security/analyses ... tpabe.html

If you cant acces normal website it's because the trojan modify the HOSTS file as describe in Advanced tab.

go in C:\WINDOWS\system32\drivers\etc and open HOSTS by notepad.
In it there is only in normal situation

Code: Select all
127.0.0.1       localhost


The trojan have certainly modify the registry too...

anti virus, adware,... There's some advice on the website I gave for recovery.

and in last action format.

Veteran
User avatar
Posts: 382
Joined: Tue Dec 19, 2006 1:00

Postby Repta » Wed Aug 15, 2007 14:43

never had these kind of problems: AVG, add-ware, spybot search & destroy, spyware blaster, zonealarm and firefox + addblock plus. No problems :)

Official Member
User avatar
Posts: 150
Joined: Mon Mar 26, 2007 0:00
Location: France

Postby Lady_Deadly_Nade » Thu Aug 16, 2007 19:26

Thnks a lot.

But now the virus is on every hardware and its making craps OOo Even its glued on the USB omfg Oo ...

We ll see ... its impossible to delate it and stufs but i ll search more. 8O

Veteran
User avatar
Posts: 382
Joined: Tue Dec 19, 2006 1:00

Postby Repta » Thu Aug 16, 2007 19:57

Lady_Deadly_Nade wrote:Thnks a lot.

But now the virus is on every hardware and its making craps OOo Even its glued on the USB omfg Oo ...

We ll see ... its impossible to delate it and stufs but i ll search more. 8O


format your PC then the trojan will be no more.... but the rest of your files/programs too :) so make a back up of the important files (if that is still possible)

Official Member
User avatar
Posts: 150
Joined: Mon Mar 26, 2007 0:00
Location: France

Postby Lady_Deadly_Nade » Sat Aug 18, 2007 12:13

Ha......ha..........

Whats the point to format when you wanna beat the virus and you face that kind of challange for 1st time in your life.

..................... 5h later....................

Everything is just pointless ammmm... i give up, cant find way to clean the Goh.exe from :/C and D oO. I'll delate all her files omfg she will kill me.

The stupid Symentek makes antyvirus and the viruses ENTER trou IT if you dont have full version or updates...

One thing, I STOPPED using ANTYVIRUS Just put hight lvl protection and block all incoming cookies :P

I was reading about the Trojans and its too much info and it's about old versions of virus and about this one i cant see eny solutions, but for me the only one way to beat that is to learn for programming and stufs OO NO ?

Spam Noob
User avatar
Posts: 6
Joined: Sun Nov 26, 2006 1:00

Postby Xavandy » Sat Aug 18, 2007 19:38

If her files are already erased you can format to make a proper install :)

hided solution

Learning programming can be usefull if you want to make a virus, not really to delete it.

Be carefull on the website you launch! Never click on Ads! Antivirus up-to-date, firewall,...
or Linux!

17years on computers, 10 years on internet and I never had a virus :'(

Return to General Discussion

Who is online

Users browsing this forum: Google [Bot] and 34 guests