Graybird

Graybird

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Graybird =?Utf-8?B?UmljaGFyZCBH?= 07-10-2005
| `--> Re: Graybird =?Utf-8?B?Umlja...07-12-2005
---> Re: Graybird David H. Lipman07-10-2005
  ---> Re: Graybird Joan Archer07-11-2005
  | `--> Re: Graybird David H. Lipman07-11-2005
  |--> Re: Graybird =?Utf-8?B?Umlja...07-12-2005
  ---> Re: Graybird David H. Lipman07-12-2005
    ---> Re: Graybird =?Utf-8?B?Umlja...07-15-2005
      `--> Re: Graybird David H. Lipman07-15-2005
Posted by =?Utf-8?B?UmljaGFyZCBH?= on July 10, 2005, 10:25 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Despite running ‘Spyware Doctor’, ‘Antivir XP’, firewalls in place etc.
and
running ‘Sysclean’ in safe mode, every time I turn on my PC, I get following
warning:

….temp file ‘contains a signature of the (dangerous) backdoor programme
BDS/Graybird N1 backdoor server programmes’.

How do I get rid of it?

Thanks in anticpation of any help.


Posted by Malke on July 10, 2005, 1:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Richard G wrote:

> Despite running ‘Spyware Doctor’, ‘Antivir XP’, firewalls in place
> etc. and running ‘Sysclean’ in safe mode, every time I turn on my PC,
> I get following warning:
>
> ….temp file ‘contains a signature of the (dangerous) backdoor
> programme
> BDS/Graybird N1 backdoor server programmes’.
>
> How do I get rid of it?
>
> Thanks in anticpation of any help.

Googling for "BDS/Graybird brings up a few sites, but the ones that look
useful are in German, which unfortunately I can't read. Obviously you
have some sort of malware that has a "guard" .dll or some other program
that is respawning the bad stuff. The best thing for you to do would be
to run HijackThis and post your log at *one* of the following web
forums. You'll get the expert help you need there. Read the posting FAQ
at whatever site you choose. I like the AumHA forum, but all of these
sites are excellent:

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
another tutorial
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by =?Utf-8?B?UmljaGFyZCBH?= on July 12, 2005, 2:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for your comments. Looks a bit technical for a simple soul like me but
will see what I can do.

"Malke" wrote:

> Richard G wrote:
>
> > Despite running ‘Spyware Doctor’, ‘Antivir XP’, firewalls in place
> > etc. and running ‘Sysclean’ in safe mode, every time I turn on my PC,
> > I get following warning:
> >
> > ….temp file ‘contains a signature of the (dangerous) backdoor
> > programme
> > BDS/Graybird N1 backdoor server programmes’.
> >
> > How do I get rid of it?
> >
> > Thanks in anticpation of any help.
>
> Googling for "BDS/Graybird brings up a few sites, but the ones that look
> useful are in German, which unfortunately I can't read. Obviously you
> have some sort of malware that has a "guard" .dll or some other program
> that is respawning the bad stuff. The best thing for you to do would be
> to run HijackThis and post your log at *one* of the following web
> forums. You'll get the expert help you need there. Read the posting FAQ
> at whatever site you choose. I like the AumHA forum, but all of these
> sites are excellent:
>
> http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
> Eshelman
> http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
> another tutorial
> http://aumha.net - forums
> http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
> forum
> http://www.wilderssecurity.com/
> http://forums.tomcoyote.org/
>
> Malke
> --
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic!"
> MS-MVP Windows - Shell/User
>

Posted by David H. Lipman on July 10, 2005, 9:04 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Despite running ‘Spyware Doctor’, ‘Antivir XP’, firewalls in place etc. and
| running ‘Sysclean’ in safe mode, every time I turn on my PC, I get following
| warning:
|
| ….temp file ‘contains a signature of the (dangerous) backdoor programme
| BDS/Graybird N1 backdoor server programmes’.
|
| How do I get rid of it?
|
| Thanks in anticpation of any help.

What is the filly qualified path and name of the file that is being flagged by
this ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Joan Archer on July 11, 2005, 5:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
<lol> You been watching the racing <g>
Sorry Dave couldn't resist <g>
Joan


David H. Lipman wrote:
>
> What is the filly qualified path and name of the file that is being
> flagged by this ?



Similar ThreadsPosted
Strange trojan (?) Backdoor.Graybird September 16, 2005, 10:24 am

The site map in XML format XML site map

Contact Us | Privacy Policy