Malware

Win32/GreyBird.NBS removal guide

Malware Removal

The Win32/GreyBird.NBS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GreyBird.NBS virus can do?

  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:9999
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/GreyBird.NBS?


File Info:

crc32: E9E8E7E3
md5: 677ff5efbf8681f1cf6c3191090519cf
name: 677FF5EFBF8681F1CF6C3191090519CF.mlw
sha1: 55b92ee5ad54172c9474cca360ea0191d5de5394
sha256: 75bfd64ddab27272609497660087ef3593b730be09727e2e1f61c869430a3a9c
sha512: 8c7aef918be557989c701d5b52294636f3b210b759e3e780be6e7d3326b76c69af9d959663f3b56566589b37d9ca2cf4bb52f7f9653acc66a4942a9096f51324
ssdeep: 3072:ddPRzaQAfdAzagzHu7MmV4D4LrKoXgyPtrCLRt2eiNID0FW430b4N3hPu/0:HJzKWagq7Mik4LrVNlrc7t0FfE8NxP/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/GreyBird.NBS also known as:

K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Iauh
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.30
CylanceUnsafe
ZillyaBackdoor.Hupigon.Win32.90686
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.fbf868
CyrenW32/Backdoor.YDCS-4033
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GreyBird.NBS
APEXMalicious
AvastWin32:PePatch-BL [Trj]
ClamAVWin.Trojan.Hupigon-1048
KasperskyBackdoor.Win32.Hupigon.aejq
BitDefenderGen:Heur.Mint.Zard.30
NANO-AntivirusTrojan.Win32.Hupigon.edesrk
ViRobotBackdoor.Win32.GrayBird.178176
MicroWorld-eScanGen:Heur.Mint.Zard.30
Ad-AwareGen:Heur.Mint.Zard.30
SophosML/PE-A + Troj/GrayBir-AJ
ComodoBackdoor.Win32.GreyBird.LI@2ls0
F-SecureTrojan.TR/Patched.Ren.Gen
BitDefenderThetaGen:NN.ZelphiF.34670.kSWbaOZ3dZb
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
TrendMicroMal_HPGN-1
McAfee-GW-EditionBehavesLike.Win32.Downloader.cc
FireEyeGeneric.mg.677ff5efbf8681f1
EmsisoftGen:Heur.Mint.Zard.30 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Huigezi2005.adx
AviraTR/Patched.Ren.Gen
eGambitUnsafe.AI_Score_89%
KingsoftHeur.SSC.2708363.1216.(kcloud)
MicrosoftBackdoor:Win32/Hupigon
GridinsoftTrojan.Heur!.032121A1
ArcabitTrojan.Mint.Zard.30
ZoneAlarmBackdoor.Win32.Hupigon.aejq
GDataGen:Heur.Mint.Zard.30
TACHYONBackdoor/W32.Hupigon.178688.J
AhnLab-V3Trojan/Win32.Hupigon.C41500
McAfeeGeneric.dc
MAXmalware (ai score=89)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.3356511380
TrendMicro-HouseCallMal_HPGN-1
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazrtA140dJzZjHZpPMaO8xvd)
YandexTrojan.GenAsa!85/7sIsLiZw
IkarusBackdoor.Win32.GrayBird.li
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Hupigon.OSE!tr.bdr
AVGWin32:PePatch-BL [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM13.0.6367.Malware.Gen

How to remove Win32/GreyBird.NBS?

Win32/GreyBird.NBS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment