Guangwai boys' remote control software is a professional remote control and network monitoring tool developed by guangwai programmer Network (former guangwai Female Network Team. In addition to the features that common trojans should have, boys from guangwai also have unique features: 1. the client is highly imitated by WINDOWS Resource Manager. 2. powerful File Operations. 3. the technology of "rebound port principle" and "thread insertion" is used.
Boys outside Guang can use dll insertion thread technology to prevent Process Termination and penetrate the firewall! I will not describe it in detail.
To delete a table, follow these steps:
1. open the HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun command to view the EXE file run by boys from outside China. the key value does not have a complete running path because the executable file can be directly run in the system32 folder. delete the auto-START key and then delete the corresponding EXE file in the system32 system folder.
2. this step is very important, although the above items are deleted but will be started again next time. this is because boys from Guang Wai modify the registry so that the dll runs automatically. After the dll is run, the dll inserted into the explorer process cannot be deleted. Even if you finally click the explorer process, the dll will still be inserted into other processes. in this step, you need to know the name of the boys dll file. You can find the file size in the system32 system folder is kb or kb. find the boy dll in Guang Wai, copy the file name, open the system registry, click --> edit --> Search, enter the name of the dll file you just copied, find the key value, and delete it. the reason is that the location of the Registry is changed when the dll is automatically run by boys outside China.
Note: you must use the dll file name to search for the entire registry and delete the key value so that boys outside Guang can not run automatically.
3. After the computer is restarted, delete the dll file in the system32 system folder, Which is kb or 115kB.
Cleared... if you have any questions, please send me a letter! Email: 19821119@vip.sina.com
Thank you for your support for the Internet of programmers outside China! Apologize to Machine Fox