Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Closed Thread
 
LinkBack Thread Tools
Old 02-28-2008, 06:43 PM   #1 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 29
OS: XPSP2


BackDoor.Greybird Virus & more - help needed

I just ran a scan on my PC (Symantec Internet Security) and it found 6 items (Backdoor.Greybird, Downloader, Trojan Horse x4) I tried to remove the Backdoor.Greybird item but with no luck I booted in safe mode and went in to Regedit like the instructions said and search for the strings but did not find them and on this second scan I still get found 6 items. Arghhh. Help please. I have XP SP2.


Instructions I followed for the first one were these found at Symantec's website.

Click Start, and then click Run. (The Run dialog box appears.)

Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to each of these the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RunServices
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

NOTE: All the keys do not exist on all the systems.


For each one, in the right pane, delete any of the following values:

"svchost" = "%System%\Svch0st.exe"
"winlogon" = "%System%\Winlogon.exe"
"system" = "%System%\Explorer.exe"
"ravmond" = "%System%\Explorer.exe"


If you are running Windows NT/2000/XP, navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows


In the right pane, delete the value:

"run" = "%system%\svch0st.EXE"
"run" = "%system%\ravmond.exe"


Exit the registry editor.
tim_ver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-28-2008, 07:46 PM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home


Re: BackDoor.Greybird Virus & more - help needed

If you think your computer is infected....
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-28-2008, 08:25 PM   #3 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 29
OS: XPSP2


Re: BackDoor.Greybird Virus & more - help needed

Ok so How do I fix this issue?
tim_ver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-28-2008, 08:28 PM   #4 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home


Re: BackDoor.Greybird Virus & more - help needed

If you want help here in removing infection, read the link from my last post, follow the steps, post the logs in the correct forum (indicated when you read the information), and wait for help.

It may take some time to receive a reply in the HijackThis Log Help forum, as like all forums, we're swamped.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-29-2008, 09:18 AM   #5 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 29
OS: XPSP2


Re: BackDoor.Greybird Virus & more - help needed

Ok thanks.

Here are the two files from DSS scanner.

Last edited by tim_ver; 02-29-2008 at 09:27 AM.
tim_ver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-29-2008, 09:21 AM   #6 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home


Re: BackDoor.Greybird Virus & more - help needed

Quote:
If you want help here in removing infection, read the link from my last post, follow the steps, post the logs in the correct forum (indicated when you read the information), and wait for help.
Follow this link, please:

http://www.techsupportforum.com/newt...newthread&f=50

Here's why:

http://www.techsupportforum.com/secu...here-span.html

Thanks, I'll be removing that last post shortly.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-29-2008, 09:31 AM   #7 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 29
OS: XPSP2


Re: BackDoor.Greybird Virus & more - help needed

Ok if you want kill the whole thread. I have reposted as instructed above as a new post with txt files and HJT log pasted also.

Thanks Much
tim_ver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-29-2008, 09:46 AM   #8 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,564
OS: 2000 Pro; XP Pro; XP Home


Re: BackDoor.Greybird Virus & more - help needed

I think there's one more bit of pertinent information you can add to the new thread.

Quote:
I tried to remove the Backdoor.Greybird item but with no luck I booted in safe mode and went in to Regedit like the instructions said and search for the strings but did not find them and on this second scan I still get found 6 items
What exactly is Symantec finding....registry locations, file names and paths...all this is helpful.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-29-2008, 11:14 PM   #9 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 29
OS: XPSP2


Re: BackDoor.Greybird Virus & more - help needed

Ok, I will add that in to the post in a bit. I have to get back on that pc and rerun the scan to get that info.


Thanks
tim_ver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-01-2008, 02:03 AM   #10 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 29
OS: XPSP2


Re: BackDoor.Greybird Virus & more - help needed

I looked after a rescan and it gives nothing more then the name of the infection and the I can hit review which launches a webpage to tell me about it.


http://securityresponse.symantec.com...040217-2506-99


Should I post it in the message also or not?

Thanks
tim_ver is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:07 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85