Manually delete boys from guangwai

Source: Internet
Author: User

Guangwai boys' remote control software is a professional remote control and network monitoring tool developed by guangwai programmer Network (former guangwai Female Network Team. In addition to the features that common trojans should have, boys from guangwai also have unique features: 1. the client is highly imitated by WINDOWS Resource Manager. 2. powerful File Operations. 3. the technology of "rebound port principle" and "thread insertion" is used.

Boys outside Guang can use dll insertion thread technology to prevent Process Termination and penetrate the firewall! I will not describe it in detail.

To delete a table, follow these steps:

1. open the HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun command to view the EXE file run by boys from outside China. the key value does not have a complete running path because the executable file can be directly run in the system32 folder. delete the auto-START key and then delete the corresponding EXE file in the system32 system folder.

2. this step is very important, although the above items are deleted but will be started again next time. this is because boys from Guang Wai modify the registry so that the dll runs automatically. After the dll is run, the dll inserted into the explorer process cannot be deleted. Even if you finally click the explorer process, the dll will still be inserted into other processes. in this step, you need to know the name of the boys dll file. You can find the file size in the system32 system folder is kb or kb. find the boy dll in Guang Wai, copy the file name, open the system registry, click --> edit --> Search, enter the name of the dll file you just copied, find the key value, and delete it. the reason is that the location of the Registry is changed when the dll is automatically run by boys outside China.

Note: you must use the dll file name to search for the entire registry and delete the key value so that boys outside Guang can not run automatically.

3. After the computer is restarted, delete the dll file in the system32 system folder, Which is kb or 115kB.

Cleared... if you have any questions, please send me a letter! Email: 19821119@vip.sina.com

Thank you for your support for the Internet of programmers outside China! Apologize to Machine Fox

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.