![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Nov 2007
Posts: 29
OS: XPSP2
|
BackDoor.Greybird Virus & more - help needed
I just ran a scan on my PC (Symantec Internet Security) and it found 6 items (Backdoor.Greybird, Downloader, Trojan Horse x4) I tried to remove the Backdoor.Greybird item but with no luck I booted in safe mode and went in to Regedit like the instructions said and search for the strings but did not find them and on this second scan I still get found 6 items. Arghhh. Help please. I have XP SP2.
Instructions I followed for the first one were these found at Symantec's website. Click Start, and then click Run. (The Run dialog box appears.) Type regedit Then click OK. (The Registry Editor opens.) Navigate to each of these the keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ RunServices HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run NOTE: All the keys do not exist on all the systems. For each one, in the right pane, delete any of the following values: "svchost" = "%System%\Svch0st.exe" "winlogon" = "%System%\Winlogon.exe" "system" = "%System%\Explorer.exe" "ravmond" = "%System%\Explorer.exe" If you are running Windows NT/2000/XP, navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows In the right pane, delete the value: "run" = "%system%\svch0st.EXE" "run" = "%system%\ravmond.exe" Exit the registry editor. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home
|
Re: BackDoor.Greybird Virus & more - help needed
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#4 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home
|
Re: BackDoor.Greybird Virus & more - help needed
If you want help here in removing infection, read the link from my last post, follow the steps, post the logs in the correct forum (indicated when you read the information), and wait for help.
It may take some time to receive a reply in the HijackThis Log Help forum, as like all forums, we're swamped.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#6 (permalink) | |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home
|
Re: BackDoor.Greybird Virus & more - help needed
Quote:
http://www.techsupportforum.com/newt...newthread&f=50 Here's why: http://www.techsupportforum.com/secu...here-span.html Thanks, I'll be removing that last post shortly.
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
|
#8 (permalink) | |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home
|
Re: BackDoor.Greybird Virus & more - help needed
I think there's one more bit of pertinent information you can add to the new thread.
Quote:
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: Nov 2007
Posts: 29
OS: XPSP2
|
Re: BackDoor.Greybird Virus & more - help needed
I looked after a rescan and it gives nothing more then the name of the infection and the I can hit review which launches a webpage to tell me about it.
http://securityresponse.symantec.com...040217-2506-99 Should I post it in the message also or not? Thanks |
|
|
![]() |
| Thread Tools | |
|
|