The PcShare wooden horse is a section of formidable remote control software, it has the domestic origination actuation hideaway port technology, might be known as is the system perfect essence back door. Even if in intrepid kills the poisonous software, sometimes could hoodwink by it the eye, the following author has put out two pictures to do for the ironclad proof (Figure 01) (Figure 02).

Figure 01 the auspicious star looks up kills the result

Figure 02 Caba Siji looks up kills the contact surface
The author in has not made any processing to its wooden horse in the situation, it may escape kills the poisonous software Zha Sha, obviously its wooden horse's confidentiality is very strong. How as for to eliminate, we already saw from above, the light depending on kills softly is definitely incorrect, therefore here we eliminate on the union manual method its wooden horse.
Using Find.exe tool search wooden horse
In order to eliminate wooden horse's authenticity, author in own this aircraft, moved its wooden horse's service end document, such wooden horse will be succeeded loads to the system, thus has controlled the entire computer. How then do we eliminate its load the wooden horse? Here single-clicks “the start” in turn -> “the movement” the dialog box, in springs “the movement” in the dialog box, the input “CMD” the order carriage return, may the dialog box open “the order prompt”, or system's in CMD document, the duplication glues under some table of contents, and double-clicks this CMD execution document, may also achieve springs “the order prompt” the dialog box goal (Figure 03).

Figure 03 opens the CMD order prompt dialog box
Then skips the table of contents to the Find.exe tool table of contents place, then in the cursor twinkle's position, inputs Find - the f order carriage return, this time then may search way C:\program Files\dzgmhncg.sys which the wooden horse hides, as well as wooden horse service name “1 hidden service” (Figure 04).

Figure 04 searches the wooden horse using the Find tool to hide the way
Since had known the wooden horse way as well as its service name, we are forbid first its wooden horse service, lets its stop in system's movement, here continues in “the cursor twinkle” the command line place, the input “Find - cd dzgmhncg.sys” the order carriage return, then may serve it is forbid successfully (Figure 05).

Figure 05 the success is forbid the wooden horse service
Then examined that this service present's attribute, in its following cursor twinkle place, the input “Find - c dzgmhncg.sys” the order carriage return, this time looked demonstrates its wooden horse service the condition (Figure 06).

Figure 06 uses the Find order examination attribute
From the chart may clear see that its result is The Service “dzgmhncg.sys” has not been the found information, then the expression has not discovered this service, i.e. this service now opening condition. Has known these, we enter to C:\ program Files\ table of contents, finds the Uwupqudn.dll document which the back door releases, and deletes it (Figure 07).
Other pages: : 1 * 2 * Next>>
|