Page 1 of 1

**Virus Help**

PostPosted: Fri Sep 16, 2005 2:43 pm
by Jimbo
Well playing on an Online multiplayer game i recieved a Virus, yes 100& free!

The virus is called backdoor.graybird.

Norton AV 2005 said it dicovered it and automatically deleted it.

Does this mean my system is now 100% safe from this.

Can i take any more steps?

I Turned the Anti-virus off whilst playing :-[ :-[, i know i did stupid and dont menion it again, My own stupid fault :-[ :'(

Anyway as much info as possible would be very helpful and thanks for yout advice!

Many thanks

James

Re: **Virus Help**

PostPosted: Fri Sep 16, 2005 3:41 pm
by GeForce
If Norton found it and said it deleted it, you can probably believe it. And because it got rid of it, you can be failr sure it will do it again if you happen to recieve that virus again.

Nevertheless read this page: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.graybird.p.html

Cheers,

Jon

Re: **Virus Help**

PostPosted: Fri Sep 16, 2005 5:06 pm
by Jimbo
Thanks Jon for the info, Much appreciated.

Norton now says its "found the virus and has automatically removed" Everytime i LOG ON so the virus must and has to still be there.

Any other ideas? My system has quite a bit of junk lying about aswell, but i hope i can get this fixed,

Only other option involves Doing a re-format which is OK because i can get rid of the junk and the virus and start from fresh.'

Cheers

James

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 12:01 am
by Katahu
Do a full system scan every week and run live update every once in a while to stay up to date.

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 7:04 am
by GeForce
Do a full system scan every week and run live update every once in a while to stay up to date.


Good advice. If it's doing it everytime you log on it might have "half-removed" the virus. Ie. parts of it have been gotten rid of and it can't do any damage. But the virus may have affected system .dlls and the like. Norton can't muck around with these because they are constantly in use when the system is running, and you know that Windows won't let you change something when it's in use.

Basically, if you can't see anything that the virus is doing, leave it alone.

Could you post a screenshot of the notice Norton comes up with at logon?

Cheers,

Jon

PS. If you want to do a reformat, you may as well. Cleans out the system nicely, just make sure you back everything up!!

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 9:51 am
by Jimbo
AAh thanks, Greatly appreciated.

I have re-formatted and backup it all up now, making do' with the laptop.

I didn't know you could get a Virus from online multiplayer games? ???

I was playing battlefield 2, and zonealarm kept mentioning a High risk or somethin, i didn't take that much notice because sometimes its just programs loading up, but i restarted my PC and the norton Virus sign came up saying it had found one and automatically deleted it, and this now happens every time i logon.

But ive re-formatted now, so A fresh system!

So what do you think? Did i get it from an online multiplayer game? Or something else?

All i go on is SimV and PC hardware sites and thats all.

Many thanks indeed.

James, ;)

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 10:10 am
by Jimbo
ALSO IS spoolsv.exe  a system process???

I have just looked in windows task manager, thats all.

Wondered if it was a safe application.

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 10:41 am
by Fozzer
Hi Jimbo...!

If you have problems in getting Norton to remove a Trojan or Virus, when Windows is running, start the computer in "Safe" mode...
Press the F8 key during boot-up.
When the screen has loaded, locate your CD Rom with the Norton disk in it.
Double click the CD to run Norton scan... ;D...!

When running in Safe Mode Windows is not operating, and will not be "using" it's registry, allowing Norton to modify it as required.. ;)...!

This works much more successfully then trying to get Norton to do the job whilst Windows is running...!

Cheers Jimbo...!

Paul... 8)...!

Norton's tip:
----------------
Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode. Once you have restarted in Safe mode, run the scan again.

After the files are deleted, restart the computer in Normal mode.

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 10:49 am
by Jimbo
Cheers foz!, a bit late now, but VERY handy in the future!

Cheers mate

James ;)

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 11:03 am
by Fozzer
Cheers foz!, a bit late now, but VERY handy in the future!

Cheers mate

James ;)



Good-on-ya, Jimbo... ;D...!

For anyone who is interested, an alternative method...>>>

Press "Delete" during boot up to go into the BIOS.
Select your CD ROM as the first boot disk instead of the hard drive.
Pop the norton disk in the CD ROM.
Save the BIOS, and re-start the computer.

The CD will be detected first and the Norton disk will perform a scan.
When all is completed satisfactorally, go back into BIOS, change the first boot disk back again to the hard drive.
Save the BIOS, and re-start the computer as normal.
Sorted... ;)...!

This method also performs the scan before Windows starts...!

Cheers...!

Paul.

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 2:17 pm
by GeForce
[quote]ALSO IS spoolsv.exe

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 4:23 pm
by Jimbo
Oook Jon.

you have been a real help pal, very appreciated, i hope you know that! ;)

Its a mystery to me, im just trying to find out where i got it from so that i dont do it again.
But next time i will enable norton and spyware sweeper on!

Cheers mate :)

James 8)

Re: **Virus Help**

PostPosted: Sat Sep 17, 2005 6:01 pm
by Katahu
Note: If all of the above fails, there is always the hammer. Enjoy. ;D

Re: **Virus Help**

PostPosted: Sun Sep 18, 2005 3:40 pm
by GeForce
Note: If all of the above fails, there is always the hammer. Enjoy. ;D


Trust you! ;D

No problem James, anytime ;)

Jon 8)