Female ghost virus specifically killed

Source: Internet
Author: User

Ghost virus is written in VB language, need a dynamic link library VB, some users may not have this file on the system, the virus can not be activated. The female ghost virus in the infected user system, will not be timed to appear on the computer horror Ghost, and accompanied by eerie guikulanghao voice. Every time the female ghost appeared for about 30 seconds, lowered her head, her hair, her eyes still glowing red, and the eerie sound of horror, so that when I opened the computer at night, I could not help but get the creeps and the legs soft.
The technical characteristics of the virus are as follows:
Virus name: GirlGhost2
Virus Size: 344064Bytes
virus body FileName: (no key value set). EXE
Virus infection Analysis:
A. Virus disguised as a directory icon, after execution delete itself, in the Windows system directory to generate the. exe and (not set key value). exe two files, and generate Mm2.jpg.exe files in the temporary directory of IE.
B. Modify registry key
The default value for Hkey_classes_root\jpegfile\shell\open\command is C:\WINDOWS\Temporary Internet files\ Mm2.jpg.exe%1
The virus executes when a JPG file is double-clicked.
Modify the following registry key to enable system startup to load automatically:
Modify the default value of HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to (not set key values) (corresponding to its generated file (not set key value). exe);
Modify hkey_local_machine\software\microsoft\windows\currentversion\ The default value for RunServices is changed to (corresponding to its generated file? exe).
C. After poisoning, a scary ghost (about 30 seconds) appeared on the computer and accompanied by eerie howling noises.

Purge method:
1. Update the virus database of your anti-virus software;
2. Delete the key values created by the virus in the registry:
hklmsoftwaremicrosoftwindowscurrentversionrun=%registry path where the file was run% Gfg.exe
hklmsoftwaremicrosoftwindowscurrentversionrunservices=
%registry path where the file was run% Gfg.exe
3. Reboot the machine;
4. Use antivirus software for scanning, once found, immediately kill.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.