GRAYBIRD.C VIRUS.
Backdoor.Graybird.C is a Backdoor Trojan and a variant of Backdoor.Graybird.
It gives a hacker unauthorized access to your computer. It opens port 52013 to listen for commands. The existence of the file, HGZSERVER.EXE, is an indication of a possible infection. The Trojan uses special icon to attempt to disguise itself as an ordinary .txt file.
Starts an FTP server on port 21, which allows the hacker to use the compromised computer as a temporary storage device.
To disable activity of this worm navigate to each of these the keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value - huigezi %System%\HgzServer.exe
Also, make the changes in the Win.ini file
Use RegRun Startup Optimizer to remove it from startup.
Removal: HgzServer.exe is removed by RegRun.
Read more... Removal instructions...
Recommended software:
UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com
RegRun Security Suite - removal and protection.
http://www.regrun.com
RegRun Reanimator - free removal tool.
greatis.com/reanimator
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
May 12 2008
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?