How to Get Rid of the Backdoor Graybird
- 1). Press the "Ctrl," "Shift" and "Esc" keys at the same time to start the Task Manager.
- 2). Click the "Processes" tab.
- 3). Select "-396109520.exe" and click "End Process."
Do the same thing for the following files: "50b825f5.exe," "930905eb.exe," "backdoor.graybird.c.exe," "backdoor.graybird.e.exe," "backdoor.graybird.f.exe," "backdoor.graybird.m.exe," "backdoor.graybird.p.exe," "backdoor.graybird.w.exe," "h_client.exe," "brc_Server.exe," "WINDOWS111.exe," "Server1.2.exe," "Hacker.com.cn.exe," "GrayPigeon.exe," "prsvr.exe," "VPort1.1.exe," "explore.exe" and "Puesto.exe." - 4). Close the Task Manager.
- 1). Go to the Start menu and select "Run."
- 2). Type "regedit" in the search line and click "OK" to start the Registry Editor.
- 3). Browse to and remove the following entry:
SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\RAVMOND - 4). Close the Registry Editor.
- 1). Go to the Start menu and select "Run."
- 2). Type "cmd" in the search line and click "OK" to start the command line window.
- 3). Type "regsvr32 /u backdoor.graybird.l.dll" and hit "Enter" to unregister the DLL.
Do the same for "backdoor.graybird.l[2].dll," "backdoor.graybird.m.dll," "backdoor.graybird.s.dll" and "brc_Server.dll." - 4). Close the command line window.
- 1). Go to the Start menu and select "Search."
- 2). Select the hard drive from the drop-down menu and check "All Files and Folders."
- 3). Type "-396109520.exe" and hit "Enter." Delete all search results.
Do the same for "50b825f5.exe," "930905eb.exe," "backdoor.graybird.c.exe," "backdoor.graybird.e.exe," "backdoor.graybird.f.exe," "backdoor.graybird.m.exe," "backdoor.graybird.p.exe," "backdoor.graybird.w.exe," "h_client.exe," "backdoor.graybird.l.dll," "backdoor.graybird.l[2].dll," "backdoor.graybird.m.dll," "backdoor.graybird.s.dll," "cserver.dat," "cserver_dll," ".dat," "h_client.chs," "h_client.cht," "heibai.net.txt," "help.chm," "operate.ini," "sserver.dat," "brc_Server.dll," "brc_Server.exe," "RAVMOND," "WINDOWS111.exe," "Server1.2.exe," "Hacker.com.cn.exe," "GrayPigeon.exe," "prsvr.exe," "VPort1.1.exe," "cmdle.com" and "Puesto.exe." - 4). Restart your computer.