This week, the National Computer Virus emergency response center monitored the Internet and found a new variant of "gray pigeon" (Backdoor_Huigezi.RPG ). After running in the infected computer system, the virus file is copied to the specified directory of the system, and the file attribute is set to read-only, hidden, or archived, this prevents computer users from discovering and deleting them. The variant also modifies the startup entry in the infected system registry so that the variant runs automatically as the computer system starts.
In addition, this variant calls the IE browser process in the background of the infected system and writes malicious code to the memory address space of the IE process. If a malicious attacker uses this variant to intrude into the computer user system, the variant will enable the infected computer system to actively connect to the server specified by a malicious attack in the Internet, at the same time, malicious attackers can obtain the real IP address of the system, resulting in full control of the infected computer system and theft of information in the system, which seriously threatens the security of confidential information of computer users.
Red girl, the new virus this week announced by rising. win32.RedGirl. a) "This is the variant. The virus can invalidate multiple anti-virus software and be remotely manipulated by hackers to perform various dangerous operations, such as downloading files from computer viruses, snoop on the screen, and stealing passwords. The icon of the "red girl" virus is a video file named "Sister's video ".
For this type of virus and its variants, experts suggest: 1. many viruses must be patched to the system in a timely manner when exploiting vulnerabilities. 2. install professional anti-virus software to the latest version, and open the Real-time Monitoring Program; 3. install professional personal firewall software to defend against hacker attacks. Quan mengli