Mysterious “ghosting” Can Not Attack Winxp Reinstall Removed – Ghost, Viruses, Heavy


Posted by 14 January, 2012

Previously, users typically heard that the poisoning was okay, massive deal reinstall the program. But now, these words will become history. March 15, Jinshan security laboratory is named to capture a kind of “ghosting” of pc viruses, the virus lives in the disk master boot record (MBR), even if the format re-install the program, can not get rid of the virus. When the technique reboot once again, the virus will be back in initial load the operating technique kernel. When the virus following a effective run, in the process, the technique boot loader can not discover any unusual items, the virus as “ghosting” on the same laptop or computer in the poisoning, “lingers.”

To overturn the conventional method can not eliminate heavy equipment
Jinshan security anti-virus authorities stated, “the common system under pc virus is a Windows application, run right after the Windows load. And” ghosting “parasitic virus, the main code is in the hard disk master boot record (MBR ), the pc system startup process prior to the core plan directly loaded into the pc memory to run. who currently parasitic on the MBR of the virus, security software program can not be blocked. simply because of the virus than the security software start off-up even earlier.

Li Tiejun said that “ghosting” virus is the 1st boot downloader virus infection subversion of the standard characteristics of dealing with AIDS concerns, and user mindset, not only do the “three noes” feature?? No file, without having system startup items, no method module, and even if the user reload the method, the virus will still re-enter the new program users new virus technologies, a breakthrough from ordinary antivirus computer software protection, “ghosting” the virus can stated to be a “landmark” feature of computer viruses.

Drastically slow down the personal computer security software program failure
Jinshan Safety Laboratory in analysis, this “ghosting” virus is bundled with the software installed on some shared access to a computer, the present day is about 2-3 million infected computers. “Ghosting” viruses will release the driver overwrite the difficult disk MBR (master boot record), the driver of numerous attacks in the course of the boot method of antivirus software, antivirus software program that failure to download the conventional AV Terminator Trojan downloader, the ultimate aim continues by way of the dissemination of Daohao Trojan, steal virtual assets for profit. Poisoning, the most intuitive phenomenon is not running security software, laptop or computer slow down significantly, IE residence page was changed.

Rare virus technology from abroad “Ghosting” the virus is fairly rare in current years, technology-sort virus, the virus author has exceptional programming capabilities. WinXP program due to the fact of the restrictions, rewrite the MBR will be the general way the system determined to be illegal, which is close to extinction boot sector viruses an critical aspect. This bypass security restrictions Winxp, direct overwrite MBR technology mainly in the dissemination of foreign technologies forum in the “ghosting” the virus prior to, this technology is hardly ever the case of hackers utilizing the actual mass. Kingsoft Security Lab engineers stated that the current “ghosting” virus only for Winxp program, the virus still can not destroy Vista and Windows7 technique. According to Kingsoft

security laboratory personnel revealed that in the existing domestic security and civil anti-virus vendor master in, to a complete analysis, “ghosting” the virus had been few. Parasitic on the difficult drive due to virus master boot record (MBR), the virus can damage the driver released the majority of security tools and system support tools, in the case had been poisoned, it is difficult to use existing tools to complete the virus removal, Jinshan security lab is preparing for the “ghosting” virus Zhuanshagongju.

Duba has been upgraded, can be spread killing “ghosting” parent virus file, to keep away from the much more users by the “ghosting” victims of the virus, users can only access the suitable line to upgrade defense capabilities. Jinshan net shield has spread the virus to avoid access to malicious Web page to join the list, to avoid a lot more users to download the mysterious “ghost” virus.
winxp operating program

Mysterious 8220ghosting8221 Can Not Attack Winxp Reinstall Removed 8211 Ghost Viruses Heavy


One Response to “Mysterious “ghosting” Can Not Attack Winxp Reinstall Removed – Ghost, Viruses, Heavy”

  1. interesting articles says:

    That’s good to hear, I was worried

Leave a Reply

Mysterious “ghosting” Can Not Attack Winxp Reinstall Removed – Ghost, Viruses, Heavy during 2012

Get Adobe Flash player