Endpoint Protection

 View Only
  • 1.  Antivirus detection continuously deleting same threat

    Posted Mar 25, 2010 06:05 PM

    The antivirus detection results window has been up and running for over 24 hours. It is continuously deleting the same risk with the following name:

    Backdoor.Graybird!gen

    The system spent the first 8 hours detecting it and the last 16 deleting it, updating every 3 seconds or so. How can i complete this action? Every time i close the box it reopens, sometimes two window for every one i delete.



  • 2.  RE: Antivirus detection continuously deleting same threat

    Posted Mar 25, 2010 06:41 PM
    Are these all Auto-Protect detections?  If so, something may be trying really hard to get onto your computer.

    http://www.symantec.com/security_response/writeup.jsp?docid=2007-051115-2423-99

    sandra


  • 3.  RE: Antivirus detection continuously deleting same threat

    Posted Mar 25, 2010 07:41 PM
    they are all auto-protect detections. But if it is a program trying to get into my computer, why would it still be continuously detected and deleted after i disconnect the internet connection. Im not very computer savvy, but that doesnt make sense to me. So it leads me to believe it is a Symantec issue and not a virus. Of course i may be wrong. Any advice on how to proceed from here will be greatly appreciated.


  • 4.  RE: Antivirus detection continuously deleting same threat

    Posted Mar 25, 2010 07:52 PM

    Hi Dane82,

    I recommend that you disconnect that computer from your network at once and read this article: Best practices for responding to active threats on a network

    It sounds like there is eitehr something on the network which is constantly trying to infect the computer, or something currently undetected on the computer which is creating a Graybird which is detected.

    Get Rapid Release definitions onto the computer and perform a full system scan in safe mode: that's where I'd start.

    Please kepe the forum up-to-date with your progress!

    Thanks and best regards,

    Mick



  • 5.  RE: Antivirus detection continuously deleting same threat

    Posted Mar 26, 2010 01:17 AM
    I am agreeing with Mick.You can use Risk tracer also for finding the PC which is attacking your server.Refer this article.
    Worms and threats that spread across networks by network shares have become more common in recent years.--Like Downadup/Conficker