ardi Posted May 23, 2003 Posted May 23, 2003 Noton alerts are popping up like mad on my machine. The XP firewall is (and has) been on, but the virus is still here. I can find the infected file that Norton identifies, but it won't delete. This is what Norton says:Virus Alert: Object name: C:Windows\Systen32\wininetd.exeVirus Name: Backdoor.WinetAction taken: Access to file was denied Delete failedSo far, it has done no damage that I am aware of, but I need to get rid of it. Suggestions anyone?
sedative Posted May 23, 2003 Posted May 23, 2003 Did you try booting into safe mode and deleting it that way?
ardi Posted May 23, 2003 Author Posted May 23, 2003 No, I didn't know that would make any difference. I'll try that next.BTW have you heard of this virus? I've never seen Norton defeated like this.
rik Posted May 23, 2003 Posted May 23, 2003 I know you've probably already seen this but I'll add it anyway. The page that SARC has on this virus. http://securityresponse.symantec.com/avcen...otron.worm.htmlRemoval instructions are at the bottom.
MSNwar Posted May 23, 2003 Posted May 23, 2003 Did not find anything about on Google. Write NAV and tell them about it. Bet they would be interested.Maybe Trojan Cleaner will kill it. http://www.moosoft.com
.PsychoMerc. Posted May 23, 2003 Posted May 23, 2003 I had Backdoor.netdevil, that thing was freakin evil. I tried everything and I finally had to reformat.
ardi Posted May 26, 2003 Author Posted May 26, 2003 Fixed!!! No damageThis is a new worm, only discovered on May 20. Norton can now deal with it if you have the latest virus definitions. I was just unfortunate to get it before the update was out on the 21st. There is a whole page devoted to it on their site.One lesson learned: I didn't have to edit manually the changes the worm made to my registry. System Restore did it automatically for me. Discovered this while thrashing around trying to fix it myself.Thanks to all who responded with help.
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now