Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251

Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
Strange trojan (?) Backdoor.Graybird
Strange trojan (?) Backdoor.Graybird

Strange trojan (?) Backdoor.Graybird

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Strange trojan (?) Backdoor.Graybird developmental2 09-16-2005
Posted by on September 16, 2005, 2:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

David H. Lipman wrote:
>
> | I started having the same problem this morning on both my laptop and my
> | desktop. I also tried a complete system scan and found nothing. I also
> | tried a system scan with Spy Sweeper. I have the latest versions of
> | both NIS and Spy Sweeper, and both are up to date as of this morning. I
> | tried all of the steps suggested by Symantec for removing the graybird
> | trojan to no avail. I could find only one of the files mentioned in
> | their writeup, winlogon.exe, and none of the registry entries that they
> | said should be there. Winlogon appears to be a legitimate Microsoft
> | file. I'll try the multivendor scan tonight, but I am beginning to
> | think that Symantec has a problem that they have not yet acknowledged.
> | Either that, or this is a new version of graybird that installs itself
> | as a rootkit. Unfortunately, I had a rootkit remover at one time, but
> | now I can't find it. Any suggestions for a freeware version?
>
> Sysinternals has RootKit Revealer. I can't say if this would be effective
with this
> Backdoor Trojan.
> http://www.sysinternals.com/Utilities/RootkitRevealer.html
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm


Posted by on September 16, 2005, 2:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We ran into the problem this afternoon and it looks like it is realated
to Spy Sweeper and the latest update. We're on the phone with support
and they know about the problem. I'm not sure if it is a false
positive or what. I hope that helps.


Posted by on September 16, 2005, 2:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

ejcornw...@coopertire.com wrote:
> We ran into the problem this afternoon and it looks like it is realated
> to Spy Sweeper and the latest update. We're on the phone with support
> and they know about the problem. I'm not sure if it is a false
> positive or what. I hope that helps.

After more inspection it is a False Positive on Symantec's part. They
are removing a temp file created by Spy Sweeper. I believe it is
related to the newest defs of each and should be fixed in the next
release.

:)


Posted by on September 16, 2005, 3:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We just came to the same conclusion about it being the latest Symantec
definitions. I was just about to contact Symantec, but it appears that
Webroot is on the case and should have better luck than me getting it
resolved.
Cheers.


Posted by =?Utf-8?B?S2Fo?= on September 16, 2005, 3:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I do not have SpySweeper, but do have Spyware doctor, Spyware Blaster, and
Spybot.
Anyway, I am glad this is being looked into. Thanks everyone for posting
this information.

"rod.funk@sierraclub.org" wrote:

> We just came to the same conclusion about it being the latest Symantec
> definitions. I was just about to contact Symantec, but it appears that
> Webroot is on the case and should have better luck than me getting it
> resolved.
> Cheers.
>
>

Similar ThreadsPosted
backdoor.trojan April 25, 2006, 1:43 pm
Backdoor Trojan? March 2, 2007, 11:12 am
irc backdoor trojan May 9, 2008, 8:28 am
trojan horse backdoor irc/sdbot.myx December 15, 2005, 5:29 pm
trojan horse IRC/backdoor.sdbot.myx December 15, 2005, 5:35 pm
Trojan horse BackDoor.Generic3.EKW September 9, 2006, 10:14 pm
Graybird July 10, 2005, 10:25 am
Strange one October 17, 2007, 12:39 am
Strange virus October 3, 2006, 9:16 pm
Strange AVG behavior. March 31, 2007, 3:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy