Summary: This female virus is written in VB and requires a VB dynamic link library. Some user systems may not have this file, so the virus cannot be activated. After the virus is infected with the user's system, the virus may occasionally show terror on the computer, accompanied by the sound of gloomy and horrible ghosts. Every time a female appears for about 30 seconds, she hangs down her head and emits red light in her eyes. In addition, when the computer is turned on at night, she cannot help but feel pale and scared.
The technical features of the virus are as follows:
Virus name: GirlGhost2
Virus size: 344064 Bytes
Virus File Name: (no key value is set). EXE
Virus Infection analysis:
A. The pattern of the virus is pseudo-installed into a directory. After the script is executed, the file .exe and (unset key value. exeare generated in the Windows System directory, and the mm2.jpg.exe file is generated in the IE directory at the same time.
B. Modify the registry key
The default value of hkey_classes_root1_fileshellopencommand is C: WINDOWSTemporary Internet Filesmm2.jpg.exe % 1.
When you double-click a jpg file, the virus will be executed.
Modify the following registry key to automatically load the system boot:
Modify the default value of HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun to (unset key value limit (corresponding to the generated file (unset key value limit .exe );
Modify the default value of HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices? Exe ).
C. After being poisoned, a horrible female ghost appears on the computer, accompanied by a gloomy and horrible cry. Every time a female appears for about 30 seconds, she hangs down her head and emits red light in her eyes. In addition, when the computer is turned on at night, she cannot help but feel pale and scared.
Clear method:
1. Update the virus database of your antivirus software;
2. Delete the key value created by the virus in the registry:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun = % Registrypath where the file was run % gfg.exe
HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices =
% Registrypath where the file was run % gfg.exe
3. Restart the machine;
4. Scan through anti-virus software. immediately remove the virus once detected.