How to Get Rid of the Backdoor Graybird

104 27

    End System Processes

    • 1). Press the "Ctrl," "Shift" and "Esc" keys at the same time to start the Task Manager.

    • 2). Click the "Processes" tab.

    • 3). Select "-396109520.exe" and click "End Process."

      Do the same thing for the following files: "50b825f5.exe," "930905eb.exe," "backdoor.graybird.c.exe," "backdoor.graybird.e.exe," "backdoor.graybird.f.exe," "backdoor.graybird.m.exe," "backdoor.graybird.p.exe," "backdoor.graybird.w.exe," "h_client.exe," "brc_Server.exe," "WINDOWS111.exe," "Server1.2.exe," "Hacker.com.cn.exe," "GrayPigeon.exe," "prsvr.exe," "VPort1.1.exe," "explore.exe" and "Puesto.exe."

    • 4). Close the Task Manager.

    Delete Registry Entry

    • 1). Go to the Start menu and select "Run."

    • 2). Type "regedit" in the search line and click "OK" to start the Registry Editor.

    • 3). Browse to and remove the following entry:

      SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\RAVMOND

    • 4). Close the Registry Editor.

    Unregister DLLs

    • 1). Go to the Start menu and select "Run."

    • 2). Type "cmd" in the search line and click "OK" to start the command line window.

    • 3). Type "regsvr32 /u backdoor.graybird.l.dll" and hit "Enter" to unregister the DLL.

      Do the same for "backdoor.graybird.l[2].dll," "backdoor.graybird.m.dll," "backdoor.graybird.s.dll" and "brc_Server.dll."

    • 4). Close the command line window.

    Delete Files

    • 1). Go to the Start menu and select "Search."

    • 2). Select the hard drive from the drop-down menu and check "All Files and Folders."

    • 3). Type "-396109520.exe" and hit "Enter." Delete all search results.

      Do the same for "50b825f5.exe," "930905eb.exe," "backdoor.graybird.c.exe," "backdoor.graybird.e.exe," "backdoor.graybird.f.exe," "backdoor.graybird.m.exe," "backdoor.graybird.p.exe," "backdoor.graybird.w.exe," "h_client.exe," "backdoor.graybird.l.dll," "backdoor.graybird.l[2].dll," "backdoor.graybird.m.dll," "backdoor.graybird.s.dll," "cserver.dat," "cserver_dll," ".dat," "h_client.chs," "h_client.cht," "heibai.net.txt," "help.chm," "operate.ini," "sserver.dat," "brc_Server.dll," "brc_Server.exe," "RAVMOND," "WINDOWS111.exe," "Server1.2.exe," "Hacker.com.cn.exe," "GrayPigeon.exe," "prsvr.exe," "VPort1.1.exe," "cmdle.com" and "Puesto.exe."

    • 4). Restart your computer.

Subscribe to our newsletter
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
You can unsubscribe at any time

Leave A Reply

Your email address will not be published.

"Technology" MOST POPULAR