The concept of ghost virus
Ghost virus refers to a virus that is parasitic on the disk master boot record (MBR) and cannot be removed even if the system is formatted and reinstalled. When the system restarts again, the virus will be loaded before the operating system kernel. When the virus runs successfully, no abnormalities can be found in the process or system startup add-ons, and the virus "haunts" the infected computer like a "ghost".
Introduction to the source of ghost virus
"Ghost" virus is a relatively rare technical virus in recent years. The virus author has superb programming skills. Due to the limitations of the WinXP system, general methods of rewriting the MBR will be deemed illegal by the system. This is also an important factor in the demise of boot sector viruses. This technology of bypassing the security restrictions of WinXP and directly rewriting MBR is mainly spread in foreign technology forums. Before the "ghost" virus, there were few cases of this technology being actually used by hackers on a large scale. Kingsoft Security Lab engineers said that at present, the "ghost" virus only targets WinXP systems, and the virus cannot yet damage Vista and Windows 7 systems. According to researchers from Kingsoft Security Laboratory, among the current domestic security manufacturers and private anti-virus experts, only a handful of people can completely analyze the "ghost" virus. Because the virus is parasitic on the master boot record (MBR) of the hard disk, the driver released by the virus can destroy most security tools and system auxiliary tools. If the virus is already infected, it is difficult to use existing tools to remove the virus. Kingsoft has launched a ghost killing tool. Kingsoft Antivirus has been upgraded to detect and kill the parent files that spread the "ghost" virus to prevent more users from being harmed by the "ghost" virus. Users only need to upgrade online to obtain the corresponding defense capabilities. Kingsoft Network Shield has added the malicious web pages that spread the virus to the list of blocked access to prevent more users from downloading this mysterious "ghost" virus.
Characteristics of ghost viruses
No host required. Ends all anti-virus software.
Once this virus enters the computer, it is like a demon, hiding outside the system. It has no files, no system startup items, and no process modules. It ends all anti-virus software before the system is running. It can download AV terminators, account-stealing Trojans, IE homepage modifications, and many other viruses.
Subvert the tradition and cannot be cleared by reinstalling the system.
General computer viruses are applications under the Windows system and run after Windows is loaded. The main code of the "ghost" virus is parasitic on the master boot record (MBR) of the hard disk. Even if the user reinstalls the system, it still cannot be completely removed. When the system restarts again, the virus will be loaded before the operating system kernel. When the virus runs successfully, no abnormalities can be found in the process or system startup add-ons, and the virus "haunts" the infected computer like a "ghost". The "ghost" virus is the first boot sector downloader virus in China. It subverts the infection characteristics of traditional viruses and the way users handle virus problems. It not only achieves the "three noes" characteristics - no files, no system startup items, and no process modules, but even if the user reinstalls the system, the virus will still enter the user's new system again.
Security software fails and the computer slows down significantly
After the "ghost" virus invades, it will release the driver to rewrite the hard disk MBR (Master Boot Record). The driver will attack many anti-virus software during the boot process, rendering the anti-virus software ineffective, and then download the traditional AV Terminator Trojan downloader. The ultimate goal is still to spread the account-stealing Trojan and steal the user's virtual property for profit. After being poisoned, the most intuitive phenomenon is that the security software cannot run normally, the computer slows down significantly, and the IE homepage is changed.
Possible symptoms after computer infection
1. The computer is very stuck, the operating program has a clear sense of stagnation, and common anti-virus software cannot be opened normally. At the same time, it is found that the problem still cannot be solved after repeated reinstallation of the system. 2. After the system file is infected by anti-virus, it prompts that the corresponding dll cannot be found or the system function is abnormal. Currently rpcss. dll, ddraw. dll is a system dll that is often modified by account-stealing Trojans. 3. QQ numbers are stolen and can be used by hackers to spread advertisements, etc.Game accounts such as World of Warcraft, DNF, Tian Long Ba Bu, Fantasy Westward Journey, etc. were stolen. 4. iexplor exists in the process. exe process and points to an abnormal website. 5. The common characteristic of ghosts now is that there is ali in the process. exe 6. An annoying "player" shortcut appears on your computer desktop and cannot be deleted.
How ghost viruses work
Ghost viruses disguise themselves as shareware and trick users into downloading and installing it. After the virus runs, 2 drivers will be released into the user's computer and loaded. The driver will modify the system's boot sector (mbr) and write the b driver to the disk to ensure that the virus starts up before the system and that the virus files are saved outside the system. After entering the system in this way, the virus is loaded into the memory, but no startup items, virus files, or process modules can be found in the process. After restarting the system, the malicious code existing in the boot sector will monitor the entire startup process of the Windows system. It is found that when the system loads the ntldr file, the malicious code is inserted to cause it to load the b driver written to the fifth sector of the boot sector. After the b driver is loaded, it will monitor all process modules in the system. If there is a security software process, it will be terminated directly. The b driver will download the av terminator to the computer and run it. AV Terminator will modify system files, add a large number of image hijacks to security software processes, and download a large number of account-stealing Trojans. Further steal users' virtual property. This virus only targets Winxp systems and cannot yet damage Vista and Win7 systems.
Ghost virus treatment method
Reinstall the system
Format the C drive, enter the dos state, and run the fdisk/mbr command to clear the virus boot code in the main boot area. At this time, you can reinstall the system, but this is only effective after a complete installation. If you use GHOST to install the system, you need to do the following steps: 1. Enter the PQ/PM partition tool through the GHOST system disk, which is generally included with the GHOST system disk. 2. Right-click the c drive and select Advanced-Set as Function. This will rewrite the MBR boot layer, so that the viruses in the boot layer will naturally be eliminated. 3. It is OK to install the system directly using the GHOST system disk.
Manual killing method under DOS
The first step: Find a special killing tool: It is recommended to use "One-click GHOST", in which the small tool DISKRW that comes with the DOS toolbox can perfectly solve the problem. Step 2: Kill the MBR virus 1. Clear the hard disk reserved sectors other than MBR. Install or create "One-Click GHOST", boot into One-Click GHOST. When the red interface finally appears, press the ESC key to return to the main menu. Press the arrow keys to select "DOS Toolbox" --> "DISKRW" --> "3. Clear" --> "Clear (2)" --> OK. (Note, try to use the 2010 version, earlier versions are not guaranteed to have this function). 2. Repair the MBR (a critical step that must be done), then the next step, select "4. Repair" --> "Repair (F)" --> OK. Step 3: Reinstall or restore the system. After the second step is completed, do not restart the computer and enter WINDOWS, otherwise it will be infected again. The correct method is to put the system installation CD into the CD-ROM drive and reinstall the system. Or if you have a local system backup (of course the backup you made before you were infected with the virus), you can also use the "One-click system recovery" function to restore it. Step 4: Complete anti-virus. After returning to WINDOWS, you need to upgrade your anti-virus software to the latest version (the latest virus database), and then perform a "full scan and kill". This can kill the virus host files remaining in non-system disks (such as D drive, E drive, F drive), so as to "eliminate the roots".
Edit this paragraph MBRFix cooperates with 360 Security Guard for killing under Windows OK after restart
Special killing tool for ghost virus
One of the characteristics of "ghost" virus is that the security software cannot run normally. The cumulative number of infections of this virus is about 300,000. If netizens find that the security software installed on their computers cannot run normally for no apparent reason, and common repair tools cannot run normally, please try to use the "ghost" virus killing tool released by Kingsoft Security Center to check and repair the virus. Currently, this tool is suitable for ghost viruses that have not yet mutated. Once the virus mutates, the special kill will be ineffective. I would like to remind everyone to pay attention to network protection when surfing the Internet, and to turn on anti-software scans regularly. Currently, Kingsoft Antivirus has been able to kill the ghost mother body. Analysis of the breadth of the spread of the "ghost" virus. Kingsoft Cloud Security System analyzed the download frequency of the malware, combined with the analysis of website traffic that spreads the virus, and estimated that the daily download volume of the virus is approximately between 20,000 and 30,000.
Good BT virus——Ghosting
Replies (6)
Put this in the internet cafe
I have a lot of mobile phone viruses, private message me if you want them. Restocking advice: if you're not a tech expert, don't touch it.
Huangfu, you're way too shady!
So long, so long, so long...
Very interested, downloading it to try how fun this virus is. It's been a long time since I've seen a powerful virus; 'Panda Burning Incense' was also eliminated by me, and not with antivirus software!
Ignore me, I'm annoyed, just finished being raped by the girl. I didn't want to, but she wouldn't do it, gripping my balls with both hands. She pressed me into her hole, making me squirm, and the anxious girl shouted, "Big brother, big brother, hurry up! This is entirely my own choice." Compared to me, you're on the side. I once messed with Wu Zetian, but today I'm not bragging for you. My first love, Yang Guifei, not just my wild breath, Cixi has slept with me. My skills are strong. I've also slept with Du Shiniang, Xi Shi has played the flute for me, Diao Chan is my bud, the sun is a wolf, the sun is a tiger, the sun is a leopard, flying a plane and a day of swallows. Yesterday, the world is day after day, lying on the ground like an ant. Day by day, cockroach, testing bees, crawling into holes to grow worms. The door panel has a hole in the sun, the flat ground turns into a pit in the sun. Back then, eight rounds in one night didn't need a break; today, peeing is done with your hands. Back then, with bold spirit, you could casually brave the wind and pee three zhang high; now, possessed by evil spirits, you can wet your shoe with the wind
— All replies loaded —