trojan horse backdoor.agent.ba virus

darrenf

Well-known member
481 3
trojan horse backdoor.agent.ba

My AVG anti virus software has detected a virus "trojan horse backdoor.agent.ba" and has located the offending file on my hard drive. However, The AVG software is unable to delete this, neither am I able to delete the file manually.

Have done a search on windows update to see if there is a patch to fix this virus but to no avail.

I am not sure what this virus does exactly but I have noticed my PC running slower recently.

Does anyone know what this is and how I can go about getting rid of it?

Cheers
 

darrenf

Well-known member
481 3
Hi

Not sure what you mean by quarantined, but it (AVG) did ask if i would like to place it in the virus vault. I said yes, but AVG was unable to move the file.

When I try to delete it manually, I get the message:-

"Cannot delete reseef: access is denied.

Make sure the disk is not full or write protected and that the file is not currently in use"

(filename is reseef.dll if that means anything to anyone)

In properties, it says that the file is read only. I am able to delete other files with no problem but not this blighter!

Also, not sure what "system restore disabled" option is on AVG. Can't find it on mine (free version)?
 

Trader333

Moderator
8,504 882
System Restore is a Windows option and not AVG. What it does is backs up your entire hard drive to a place that cannot be deleted. So if you have a virus it can be backed up in System Restore and not able to be deleted.

Also it sounds like the file is in use when you are trying to delete it. So the first thing to do is go to
Start select Settings and Select Control Panel
Now select "System" and you will see a tab that says "System Restore" Click on "Turn Off System Restore" you will get a few "Are you sure" boxes but just go ahead and do it.

Re-boot your pc and try running AVG again and if you still are not able to delete this file then find where it is in Windows and reboot to safe mode the locate it and delete it.

One other thing if you do a search for the file using file manager you can often look at the properties and change a "read only" file to not being read only which may also help.


Paul
 

oatman

Senior member
2,879 22
System restore is in XP and ME. I don't know what OS you're running.
I've been searching for this troj and indeed it is a b*gger. The best bet at the moment is that link I posted, Response 8. I don't think any of the scans will do it.
 

darrenf

Well-known member
481 3
Thanks for all your suggestions. I am still working through them and it may take me some time.
Will let you know how I get on.

Just one more quick question for the time being (from an IT illiterate), how do I reboot to safe mode?

Many thanks again.

Darren

PS. Am running XP and have found system restore. Switched off/ rebooted/ re ran AVG but still not able to shift it! On to the next suggestion on my list!
 

darrenf

Well-known member
481 3
Grrrrr. This is a pesky little critter.

Have rebooted in to safe mode but when I try to locate the file, it's no longer there.

I know exactly where it is, and in normal mode, it's sat right there.

However, in safe mode, it has just disappeared! Even a file search throws a blank!!

Have tried following instructions in the link provided by oatman (response 8), but the fact that I have no security options and the fact that the file seems to have disappeared are hindering me somewhat!

If any one has any other bright ideas or comes across a downloadable patch to rid me of this, it would be very much appreciated.

To rub salt in to the wounds, I keep getting an AVG pop up window now telling me I have the virus. As if I need reminding!! Doh!
 

dav10

Junior member
40 0
use restore from reg on me ,go to start,run type,scanregw /restore, Dont forget to put space after w
 

Similar threads


AdBlock Detected

We get it, advertisements are annoying!

But it's thanks to our sponsors that access to Trade2Win remains free for all. By viewing our ads you help us pay our bills, so please support the site and disable your AdBlocker.

I've Disabled AdBlock