Hi Joseph_Moore,
i have reinstall os w98 but problem is still remains. virus infacts a lot of my website files it is imposible to me check every page and remove it. no antivirus scans this virus. my system is slow down and some times hang up. a new problem is occur that after every boot up system desktop goes white. noting seen on the desktop when i refresh it comes on normal condition. please also think about this problem. thanks
Main Topics
Browse All Topics





by: Joseph_MoorePosted on 2004-01-24 at 08:21:30ID: 10191482
Well first off,here is the write-up by Symanetc on this virus: mantec.com /avcenter/ venc/data/ html.redlo f.a.html
http://securityresponse.sy
The article does list every Registry change this virus makes. So, you could go through the article and your system, and remove/repair all of the Registry chagnes. The changes aren't tough to reverse at all. I have seen worse from many other viruses!
Now, the file changes are another matter entirely. It "Infects .html, .htm, .asp, .php, .jsp, and .vbs files" with its own viral code, plus it adds itself as a Stationary to Outlook Express, so it sends itself whenever you send e-mail. The OE Stationary thing you can fix easy.
It is the file infection of all of those file types that is gonna be hard. Your choices are, I'm afraid to say, limited.
If you know HTML, and Java, and PHP, and VBS, you could go through all of the .html, .htm, .asp, .php, .jsp, and .vbs files on your system, find the viral code in them all, and remove it. Technically possible, yes. Fun to do? Not by a long shot!
A better solution would be ot restore these files from a backup of them, if you made a backup. Do you have a backup of your system?
If not, then you are, I'm afraid to say, gonna have to do a repair (depending on your Windows OS version) or do a re-install. Win2K and XP both have a Repair install mode you can do. The older Windows OS versions don't ( I don't know if WinME has a Repair mode or not).
Good luck.