Backdoor.Graybird problem.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Banano, Nov 4, 2013.

  1. Banano

    Banano Private E-2

    I am running a Windows 7 64 bit laptop, and ever since I downloaded a file this Norton message has been popping up all the time. Norton can't do anything about it. I can't do anything through Norton. It is driving me crazy. Help.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual update Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only RogueKiller and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run the rest of the READ & RUN ME FIRST instructions on the infected account.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Banano

    Banano Private E-2

    I can post all that it says on the error window, but it is in spanish, and I can't find a way to change Norton's language. I will make my best to translate it.

    Resolved Threats:
    No risks have been resolved

    Unresolved Threats:
    Backdoor.Graybird
    Type: Anomaly
    Risk: High (High Stealth, High Removal, High Performance, High Privacy)
    Categories: Virus
    Status: Remove Failed
    -----------
    2 Registry Entry

    1 File

    1 Browser Cache

    1 System Action
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can either give me an exact file or folder that it is flagging, or if it cannot do this, you need to follow my instructions. :)
     
  5. Banano

    Banano Private E-2

    I am doing it all, just give me some time :) Just finished the Malwarebytes scan.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries! Take your time. :)
     
  7. Banano

    Banano Private E-2

    Umm, Hitman Pro opened in spanish, I imagine the log will also be so. I hope this is not a problem.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a problem at all. :)
     
  9. Banano

    Banano Private E-2

    Here they are :)
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [SERVICE][BLVALUE] HKLM\[...]\CCSet\[...]\Services : IBUpdaterService (C:\Windows\System32\dmwu.exe [7]) -> FOUND
    • [SERVICE][BLVALUE] HKLM\[...]\CS001\[...]\Services : IBUpdaterService (C:\Windows\System32\dmwu.exe [7]) -> FOUND
    • [SERVICE][BLVALUE] HKLM\[...]\CS002\[...]\Services : IBUpdaterService (C:\Windows\System32\dmwu.exe [7]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Delete this file if you see it:
    • C:\Windows\System32\dmwu.exe



    Re run Hitman and have it delete Potential Unwanted Programs



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Is Norton still alerting you about Graybird??
     
  11. Banano

    Banano Private E-2

    When I scan it with RK, all it detects is 2 HKEY_CURRENT_USER and 10 HKEY_LOCAL_MACHINE. I didn't proceed with any other steps.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Skip RK then if it does not find those entries and continue on with other instructions. :)
     
  13. Banano

    Banano Private E-2

    There is nothing in Hitman that says that. How do I do it?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I need all this gone, which Hitman finds:

     
  15. Banano

    Banano Private E-2

    It says No threaths found. And I haven't done anything.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just continue with the rest of the instructions then.
     
  17. Banano

    Banano Private E-2

    Here.
     

    Attached Files:

    • JRT.txt
      File size:
      28.1 KB
      Views:
      2
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ...and is Norton still alerting you about Graybird or not at this point? :)
     
  19. Banano

    Banano Private E-2

    It is.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then as previously explained, I need much more information that Norton is supplying you with. usually, when an antivirus finds what it considers to be a threat, it gives a file or folder name, and a location where it resides....

    Unfortunately, Norton finds Backdoor.Graybird is not helping us much. Check carefully, is what it found supposed to be in quarantine or can Norton not even fix what it finds? See if it gives us more info please. It could just be a false positive but we cannot tell at this stage.
     
  21. Banano

    Banano Private E-2

    Ruta completa: g:\razor1911\the_sims_3_keygen.exe
    Amenaza: Backdoor.Graybird
    ____________________________
    ____________________________
    En los equipos a partir de 18/10/2013 a las 10:12:22 a.m.
    Último uso 18/10/2013 a las 10:14:46 a.m.
    Elemento de inicio No
    Iniciado Sí
    ____________________________
    ____________________________
    Muchos usuarios
    Decenas de miles de usuarios de la Comunidad Norton han usado este archivo.
    ____________________________
    Maduro
    Este archivo se lanzó hace 4 años 2 meses.
    ____________________________
    Alto
    El riesgo de este archivo es alto.
    ____________________________
    Detalles de amenaza
    Tipo de amenaza: Virus. Programas que infectan otros programas, archivos o áreas de un equipo insertándose o adjuntándose a ese medio.
    ____________________________
    Origen: Soportes externos


    Archivo de origen:
    the_sims_3_keygen.exe
    ____________________________
    Acciones del archivo
    Evento: Proceso en ejecución: C:\Users\Luis\AppData\Local\virtualstore\program files (x86)\internet explorer\iexplore.exe
    No se requiere ninguna acción
    Evento: Proceso en ejecución: C:\Program Files (x86)\Internet Explorer\iexplore.exe
    No se requiere ninguna acción
    Archivo infectado: g:\razor1911\the_sims_3_keygen.exe
    Error en la eliminación
    ____________________________
    Acciones del registro
    Cambio de registro: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->AntiVirusDisableNotify:0
    No se intentó reparar
    Cambio de registro: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\->UpdatesDisableNotify:0
    No se intentó reparar
    ____________________________
    Huella digital del archivo - SHA:
    c3c2e7de4c571f506adfa711d31e3c2660d64b5326782c5444000b34d5ab1201
    ____________________________
    Huella digital del archivo - MD5:
    c1a2273e68be3fedd18778018ce16dda
    ____________________________
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So Norton is finding a keygen you installed for the sims. Delete it, these things will invite in troubles!

     
  23. Banano

    Banano Private E-2

    When I enter g:\razor1911\the_sims_3_keygen.exe in the windows explorer, it says that windows couldn't find it. Same happens when I just do g:\
     
  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you ever, at any point actually have a keygen for the sims? :confused
     
  25. Banano

    Banano Private E-2

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you search your machine for keygen.exe does anything crop up?
     
  27. Banano

    Banano Private E-2

    Nothing.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you need to tell Norton to "ignore" the threat. Most times antivirus gives the user a chance to intervene, make a choice whether the AV quarantines it, deletes it, or leaves it alone.

    Can you interact with Norton at all in this way? :confused
     
  29. Banano

    Banano Private E-2

    The file in in quarantine, and I have an exclude option. No ignore.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Empty the quarantine please.
     
  31. Banano

    Banano Private E-2

    Aparently, it isn't in quarantine. Even though it says so, but when I open the files in quarantine it isn't there, it is in the unresolved problems.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    From the unresolved problems section you mentioned, can you do anything with it there?
     
  33. Banano

    Banano Private E-2

    Erase it (The main problem is that Norton can't erase it, so I don't think it will work) exclude and send to Symantec.
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I really think you ought to post about this in the symantec forums. :) Best of luck!
     
  35. Banano

    Banano Private E-2

    Ok then. Thanks!
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem! :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds