Virus analysis:
The virus is written in Delphi, and upack0.39 is shelled.
The virus has the following behaviors:
1. The virus releases midimap ??. Dll and midimap ??. Dat files to the system directory (?? Represents two random letters ).
We can first use the Windows Search function to search for midimap in the system directory ??. Dll file (Note: midimap. dll is not a virus and must be followed by two random letters and midimap ??. Dll and midimap ??. Dat is a pair of viruses.) Figure 1
(Figure 1)
2. The virus also modifies the registry information for automatic loading upon startup.
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID {4F4F0064-71E0-4f0d-0018-708476C7815F} points to midimap ??. Dll file
Start-run-enter regedit to open the Registry Editor:
HKEY_LOCAL_MACHINESOFTWAREClassesCLSID
Search for the following subkeys for {4F4F0064-71E0-4f0d-0018-708476C7815F }.
If you expand the sub-key, the sub-key points to the virus file % systemroot % system32midimap ??. Dll 2
(Figure 2)
If you see the midimap ??. If the dll file name is the same as the file you just searched for, it proves that it is poisoned. Figure 3
(Figure 3)
3. In addition, a friend familiar with Process Explorer can also use Process cyclerto check whether there is a midimap in the thread of assumer.exe ??. Dll 4
(Figure 4)
4. After the virus runs, the hacker will visit the website specified by the hacker to download other Trojan viruses, steal the online game account, and send the stolen information to the hacker in the background, so as to damage the interests of online game players.
Manual Handling Method:
Step 1: delete a virus file:
Use wsyscheck to manage files. Go to the system directory (c: windowssystem32 by default) and find midimap ??. Dll and midimap ??. Dat file, right-click the file, and select "send to restart Delete list ".
Step 2: delete the registry key value modified by the virus:
1. Use the wsyscheck tool or the Registry Editor to delete the following key values:
The value of HKEY_LOCAL_MACHINESOFTWAREClassesCLSID {4F4F0064-71E0-4f0d-0018-708476C7815F} is "c: windowssystem32midimap ??. Dll"
2. restart the computer.