1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Virus- Backdoor.Graybird

Discussion in 'Malware and Virus Removal Archive' started by Roy78, 2005/09/18.

  1. 2005/09/18
    Roy78

    Roy78 Inactive Thread Starter

    Joined:
    2005/07/04
    Messages:
    8
    Likes Received:
    0
    I do not know whether any of you fellas know about this virus, I cannot remove it with my System Restore which I tried first for 2 weeks back from the time I must have got it on my computer. My virus program all up to date is Norton Internet Security and every time I open (start up) my computer it tells me it found and deleted the virus (Backdoor.Graybird) for me, I click OK and the next time I start up it tells me again and again, every time I now boot up it is again telling me it deleted this virus. So it must be hiding somewhere on my system and some how reinfects :confused: my computer every time it is booted up, I have done a full Scan twice both in the Safe mode and ordinary mode at the highest ability of the scanning program but cannot find the place where it is hiding and then I carry on the boot (after Safe mode) it again finds it and warns me and tells me it it deleted! Anyone have any ideas what I should do, it is very tricky this, I leave it with you gentlemen (and of cause Ladies) to perhaps give me any ideas. With many thanks Roy.
     
  2. 2005/09/19
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    This would seem to be a very old trojan - removal details are given here at Symantec.
    Problem here is that the System Restore data is also infected and, if you do clear the trojan, running System Restore will restore it! You must turn off System Restore immediately - this will delete all restore points - get rid of the trojan and then turn System Restore back on.
     

  3. to hide this advert.

  4. 2005/09/19
    Roy78

    Roy78 Inactive Thread Starter

    Joined:
    2005/07/04
    Messages:
    8
    Likes Received:
    0
    PeteC Thanks so much for helping me, I do not knw how to backup the registry and how to turn off for the time the System Restore perhaps you would be so kind to help me with these points, I know I should know but have forgotten through memory lost (g).I found the page OK and have copied it and will try and see to it over the next few days and maybe my son will come and help me out too. Many thanks and appreciation Roy.
    Later-
    PS Have been into the registry and checked and I feel that nothing yet has been changed so perhaps the 'thing' is caught every day before it can do any damage, at least I am hoping so. I found and backed up the registry and things before I went in there just to be on the safe side. Should I still try and delete all my System Restores I have got saved, if so how should I go about it if you can let me know I will see to it. Thanks again will be back on Wednesday to check any answers. Thanks again Roy.
     
    Last edited: 2005/09/19
  5. 2005/09/19
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  6. 2005/09/20
    rebar5058

    rebar5058 Inactive

    Joined:
    2004/01/12
    Messages:
    30
    Likes Received:
    0
    Virus-Backdoor.Graybird

    I too have had the virus on my computer. Am also running Norton AV which "detected and removed" Backdoor.Graybird from my computer yesterday. The virus has not shown up since, with other Norton scans. PeteC, thanks for the helpful info ... turning off the System Restore and the registry backup info. Although Norton has not detected the virus since removal, am wondering how likely is it that my computer has been infected and what might possibly show up or happen to indicate that files have been infected? I have had a few unusual things happen, programs hanging up, etc. but nothing serious thus far (I don't believe). Any thoughts would be appreciated. Thanks again ...
     
  7. 2005/09/20
    Roy78

    Roy78 Inactive Thread Starter

    Joined:
    2005/07/04
    Messages:
    8
    Likes Received:
    0
    PeteC. I went and read all you told me and ended up deleting the file SVCHOST.EXE which I found in window task monitor and the Norton on nexr boot did not find the virus and I was pleased. I also had deleted all my System Restore points as advised and this morning while on the net checked again and found 4 more of the same name so deleted them and it then said it had to reboot which it did so I had to connect again so now I am hoping it will now be fully deleted. Thanks so much for your help Roy. :)
    Later added-
    Forgot- I had ofcause spent some time checking out the registry and could not see anything added so was pleased maybe caught before any damage done, pleased thanks again Roy.
    Later-
    ! Hour later. Just for fun I again checked out Win Task Manager and found agin the last 4 things I had deleted and it then re bootted , the ones which had come back were-
    SVCHOST Local Service, Network service, Service,Network Service and again System. very hard for me to understand this :confused:
     
    Last edited: 2005/09/20
  8. 2005/09/20
    Roy78

    Roy78 Inactive Thread Starter

    Joined:
    2005/07/04
    Messages:
    8
    Likes Received:
    0
    Virus Backdoor.graybird. Need More Help Please-

    Need more help please -
     
  9. 2005/09/21
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Roy

    Hold fire there - out today, but will come back to you this evening.
     
  10. 2005/09/21
    balo

    balo Inactive

    Joined:
    2004/06/01
    Messages:
    73
    Likes Received:
    0
    This was supposedly fixed by the Norton Update of 9/17. Check to see that you have all the latest updates.
     
    balo,
    #9
  11. 2005/09/21
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hello Roy,

    The instances that you list are legitimate XP processes:
    Microsoft reference on SVCHOST.EXE http://support.microsoft.com/?kbid=314056

    An example of a trojan with the same or similiar name: http://www.neuber.com/taskmanager/process/svchost.exe.html

    Regards - Charles
     
    Last edited: 2005/09/21
  12. 2005/09/21
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Roy

    Charles has filled you in on SVCHOST.EXE - note in the Symantec document I posted the critter is Svch0st.exe - note the o has been replaced by 0 (zero).

    Do you still have a problem?
     
  13. 2005/09/24
    Roy78

    Roy78 Inactive Thread Starter

    Joined:
    2005/07/04
    Messages:
    8
    Likes Received:
    0
    Thanks so much for your help PeteC and ofcause Charlesvar, have been off but just got in and I had realized what you say about the Trojan having an 0 number instead of the letter o, how silly I feel. I saw my son and he told me that the other few files were needed for XP system and of cause when I deleted them I was put off the net as it had to boot to put them back on, at the time I thought they MUST have been needed and were not the same as before. Anyway I have no trouble now and I do want to thank you great helpers for all the help you have given me, all my programs like Adaware, SpywareBlaster and Norton are all up to date checked every time I go on the net first thing to play safe. This is my first Trojan/virus ever and got me pretty worked up. All the best to you All Roy. ;)
     
  14. 2005/09/24
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Hi Roy

    You're welcome - glad to hear that you have no further problems :)

    Some of these viruses/trojans are cunning little beasts and the writers are equally cunning and attempt to disguise them by changing the odd letter of a well known - and legitimate file in the hope that they will not be noticed :D
     
  15. 2005/09/24
    oshwyn5

    oshwyn5 Inactive

    Joined:
    2005/08/25
    Messages:
    736
    Likes Received:
    0
    http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.html

    Note the manual recovery steps you must follow after norton antivirus has removed this trojan.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.