The Graybird computer virus
Moderator: Vraith
The Graybird computer virus
Last evening, to my horror, my Norton anti-virus software isolated the Graybird virus.
www.symantec.com/avcenter/venc/data/bac ... ird.o.html
My computer was down for about 10 minutes during this - and it was 10 minutes of pure terror for me. Fortunately Norton seems to be done its job, and my computer seems to be running fine.
The thing that is worrying me is - where did this come from? I downloaded nothing yesterday evening - only some gaming, online poker and internet use.
I appreciate any thoughts you experts may have.
www.symantec.com/avcenter/venc/data/bac ... ird.o.html
My computer was down for about 10 minutes during this - and it was 10 minutes of pure terror for me. Fortunately Norton seems to be done its job, and my computer seems to be running fine.
The thing that is worrying me is - where did this come from? I downloaded nothing yesterday evening - only some gaming, online poker and internet use.
I appreciate any thoughts you experts may have.
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
do you use Web Root "Spy Sweeper"? The same thing happened to a client of mine as he was updating it. I am waiting for news on this as well, but Web Root may have been hacked....
go here for a quick online free scan
House Call
www.antivirus.com
or this DIRECT LINK to Mcafee's Stinger. (it's safe)
download.nai.com/products/mcafee-avert/stinger.exe
vil.nai.com/vil/stinger/

go here for a quick online free scan
House Call
www.antivirus.com
or this DIRECT LINK to Mcafee's Stinger. (it's safe)
download.nai.com/products/mcafee-avert/stinger.exe
vil.nai.com/vil/stinger/
- duchess of malfi
- The Gap Into Spam
- Posts: 11104
- Joined: Tue Oct 15, 2002 9:20 pm
- Location: Michigan, USA
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
- Fist and Faith
- Magister Vitae
- Posts: 25450
- Joined: Sun Dec 01, 2002 8:14 pm
- Has thanked: 9 times
- Been thanked: 57 times
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
- Fist and Faith
- Magister Vitae
- Posts: 25450
- Joined: Sun Dec 01, 2002 8:14 pm
- Has thanked: 9 times
- Been thanked: 57 times
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
That's sort of a toss-up. Just start disabling stuff 'till your computer won't run right. A lot of stuff looks legit, but it isn't.
"There is only one basic human right, the right to do as you damn well please. And with it comes the only basic human duty, the duty to take the consequences." - PJ O'Rourke
_____________
"Men and women range themselves into three classes or orders of intelligence; you can tell the lowest class by their habit of always talking about persons; the next by the fact that their habit is always to converse about things; the highest by their preference for the discussion of ideas." - Charles Stewart
_____________
"I believe there are more instances of the abridgment of the freedom of the people by gradual and silent encroachments of those in power than by violent and sudden usurpations." - James Madison
_____________
_____________
"Men and women range themselves into three classes or orders of intelligence; you can tell the lowest class by their habit of always talking about persons; the next by the fact that their habit is always to converse about things; the highest by their preference for the discussion of ideas." - Charles Stewart
_____________
"I believe there are more instances of the abridgment of the freedom of the people by gradual and silent encroachments of those in power than by violent and sudden usurpations." - James Madison
_____________
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
unfortunately, there IS a way!
The best way I have found is to check it as soon as a "fresh load" (reformat) is done, when nothing but "the regular" programs are on there. Then, as each "new program" is installed, you check it again to see if it put anything there, and compare, and so on, SO, when "the internets" dumps something in there, you can immediately identify the "new entry", eh? follow me?
in addition, sometimes they "say" who they are associated with, like Norton, Office, etc, and you can leave those. Thats debatable, and I try to keep mine clean, but sometimes those programs do run better when they "load up" with the system. I'll stop here in case I rambled.
(cail's approach has been known to work.
)

The best way I have found is to check it as soon as a "fresh load" (reformat) is done, when nothing but "the regular" programs are on there. Then, as each "new program" is installed, you check it again to see if it put anything there, and compare, and so on, SO, when "the internets" dumps something in there, you can immediately identify the "new entry", eh? follow me?
in addition, sometimes they "say" who they are associated with, like Norton, Office, etc, and you can leave those. Thats debatable, and I try to keep mine clean, but sometimes those programs do run better when they "load up" with the system. I'll stop here in case I rambled.

(cail's approach has been known to work.

- [Syl]
- Unfettered One
- Posts: 13021
- Joined: Sat Oct 26, 2002 12:36 am
- Has thanked: 2 times
- Been thanked: 1 time
Yeah, I had something nasty install itself on my comp a couple weeks ago (and it wasn't from a music site
). I just dl'd the latest updates from MS, antivir, and adaware (is it just me, or is Spybot completely useless now?). Started in safe mode and ran full sweeps. Then cleaned up the registry. Still had to run down an exec (with the aforementioned methods) that tried to reinstall the stuff, but other than that it was a quick fix.
If you look around on some tech sites, you'll find a lot of tips for speeding up your comp. Among those are instructions for disabling certain options (like a lot of remote/networking stuff) that you're probably not using, eliminating a lot of those processes that you aren't using, and so forth.
Of course, I also lost the ability to switch users or use most XP features (I run my stuff in classic style, but the wife wanted her flashy stuff back and was a wee upset
), but it's a small price to pay for a faster, more secure comp.

If you look around on some tech sites, you'll find a lot of tips for speeding up your comp. Among those are instructions for disabling certain options (like a lot of remote/networking stuff) that you're probably not using, eliminating a lot of those processes that you aren't using, and so forth.
Of course, I also lost the ability to switch users or use most XP features (I run my stuff in classic style, but the wife wanted her flashy stuff back and was a wee upset

"It is not the literal past that rules us, save, possibly, in a biological sense. It is images of the past. Each new historical era mirrors itself in the picture and active mythology of its past or of a past borrowed from other cultures. It tests its sense of identity, of regress or new achievement against that past.”
-George Steiner
-George Steiner
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
You may well be correct there, syl, but I think it all depends on the "Tea Timer" option, (resident shield), that stops the crap from getting in in the first place, plus regular scans and updates seem to work ok for me, but I have limited my internet usage to mainly this site and google, (which can get me into "trouble"), and downloading drivers and tech bulletins/news. This "disqualifies" me in many senses to these types of problems, since I quit going "willy-nilly" all over the net and don't expose myself to these things as much as the "average" user. And keeping it under control from the getgo with constant checks seems to help as well. I know that people who bring systems in to me all infested can rarely have their "current" system saved or cleaned, it gets in so many places, the best choice in those situations is usually "nuke it" (reformat). No chance of any "critters" hiding around. So "after the fact" spyware cleaners aren't my best forte, mainly since I avoid them as carefully as possible.Syl wrote:(is it just me, or is Spybot completely useless now?)

The Esmerator
thought you guys might get a kick out of it...


- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
our website is back up! (slightly out of date, but mostly accurate, we're working on it!)
www.bruincomputer.com
check it
(anyone may qualify for a commission if you find product for us, but CHECK WITH ME FIRST!!!!)

www.bruincomputer.com
check it
(anyone may qualify for a commission if you find product for us, but CHECK WITH ME FIRST!!!!)

Last edited by The Laughing Man on Thu Sep 22, 2005 5:44 am, edited 1 time in total.
- [Syl]
- Unfettered One
- Posts: 13021
- Joined: Sat Oct 26, 2002 12:36 am
- Has thanked: 2 times
- Been thanked: 1 time
Too bad I didn't know about this when I was decommissioning the La Salle. You wouldn't believe how much junk we threw away. Nor would you believe how many hard drives I had to smash, floppies I had to tear up, and so forth. That part was actually fun. Finally got to put all those sledgehammers to good use (remember, kids, wear your eye protection), and there's an art to throwing floppies so they explode on impact.
"It is not the literal past that rules us, save, possibly, in a biological sense. It is images of the past. Each new historical era mirrors itself in the picture and active mythology of its past or of a past borrowed from other cultures. It tests its sense of identity, of regress or new achievement against that past.”
-George Steiner
-George Steiner
- The Laughing Man
- The Gap Into Spam
- Posts: 9033
- Joined: Sun Aug 28, 2005 4:56 pm
- Location: LMAO
duuuuuude! MASSIVE BANK! massive fun tho to smash, ain't it? heh. We actually bid on a lot of Govt. stuff, I mainly see US Dept. of Commerce, plus a few other Depts. here and there, and a lot of Police/Fire units, mainly laptops for those guys (mobile), plus they usually use Panasonic ToughBooks. You can't kill those sucka's! You can't buy them either, unless your govt/civil service. Touchscreens on them are nice too! We also do alot of Lockheed Martin's stuff too. We do provide "certificates of destruction", but most places prefer to do it themselves, as you can attest to. But I still get a pc or two now and then with "data" still on it, actually saw the Highway budget for Mass. one time. BORING! Never anything good on those.
But the Colleges! WHOOOO! Can you imagine the stuff I find on them?
haha! I currently have about 300 gigs of mp3's laying around my shop. And thats just what I liked and kept!
But seriously, if you find us a good account, (this simply means finding anyone with a boatload of pc equipment to get rid of, you don't need to be a "recycler salesman" or anything, and this goes for anyone here.), my boss will hook you up brotha. Just check with me before you go "dognuts" and get all wound up in something we may not be interested in. We don't take all comers, as some bids just aren't profitable. peace!
you gotta watch the cd's tho, eh? eye slivers! 
(
it just occurred to me, "what would a commission on a decommission be for a non-commissioned officer"?)
check it
But the Colleges! WHOOOO! Can you imagine the stuff I find on them?

haha! I currently have about 300 gigs of mp3's laying around my shop. And thats just what I liked and kept!

But seriously, if you find us a good account, (this simply means finding anyone with a boatload of pc equipment to get rid of, you don't need to be a "recycler salesman" or anything, and this goes for anyone here.), my boss will hook you up brotha. Just check with me before you go "dognuts" and get all wound up in something we may not be interested in. We don't take all comers, as some bids just aren't profitable. peace!

hell yea! haha!Syl wrote:...there's an art to throwing floppies so they explode on impact.


(

check it