Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » Spyware / AdWare » [Pending] Trojan horse Backdoor.Agent.BA - HELP!!!!

Spyware / AdWare - [Pending] Trojan horse Backdoor.Agent.BA - HELP!!!! posted in the Security & Safety forums; HELP, I've got my first virus and can't bet rid off the little bleeder! AGV (Version 7) tells me the virus is called "Trojan horse Backdoor.Agent.BA" and it at the ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-14-2005
Bronze Member
 
Join Date: Feb 2005
Posts: 5
orange - See this Members User comments on their Profile page
Send a message via AIM to orange
Default [Pending] Trojan horse Backdoor.Agent.BA - HELP!!!!

HELP,

I've got my first virus and can't bet rid off the little bleeder! AGV (Version 7) tells me the virus is called "Trojan horse Backdoor.Agent.BA" and it at the following location - "C:\WINNT\system32\hlp.dll"

AGV can detect the virus, but can't delete or quarantine it.

I've tried runing my PC in safemode then running AVG again - nothing, virus is still there!

I've downloaded a "free" version of Xoftspy, which found loads of threats on my PC, but says I need to buy their softwear to remove everything.

Is this the case, or is there some free softwear out there to help rid my PC of this virus?

Please help, its slowly driving me crazy!!!


  #2  
Old 02-14-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Southern England
Posts: 11,299
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: Trojan horse Backdoor.Agent.BA - HELP!!!!

Hey Orange, welcome to PCHF

The file uses very special NTFS file system permissions to make its read-only property unchangeable! To delete it:-Create a temp directory called anything you like.

Move the file into the temp directory.

Change the properties of the temp directory (remove read-only) and select apply.

When prompted, select Apply changes to this folder, subfolders and files.

Delete the file!



__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation
  #3  
Old 02-14-2005
Bronze Member
 
Join Date: Feb 2005
Posts: 5
orange - See this Members User comments on their Profile page
Send a message via AIM to orange
Default Re: Trojan horse Backdoor.Agent.BA - HELP!!!!

Cheers for that but no dice -

I'm now also getting two different pop up messages, one saying "IEXPLORE.exe has generated errors and will be closed by windows" which is preventing me opening NTEXPLORER, My Documents and My Computer, so I can't get in to find the file in question,

The other message I'm getting is "cannot find the file 'monitor.exe' (or one of its components)"

Not sure if these are as a result of the virus, or something else??

Also, to further complicate things I'm getting the AVG pop up VIRUS DETECTED window about every 20 seconds - as if I didn't know I had a virus.

Honestly, I don't think my computer could be any more stuffed if I gave it a hot bath!!!!!

Any more ideas???


  #4  
Old 02-14-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Southern England
Posts: 11,299
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: Trojan horse Backdoor.Agent.BA - HELP!!!!

Yea...I vote against the hot bath!! PC + water = :cry: :evil:

Download this: http://securityresponse.symantec.com...oval.tool.html and run it

ALSO and after....

Turn off System Restore. Run AVG again. If AVG reports all clear this time around then re-boot and turn on SR again and make a new restore point called system clean.

Very often AVG makes you think your PC is still infected but it has actually put the virus into a safe vault instead.



__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation
  #5  
Old 02-15-2005
Bronze Member
 
Join Date: Feb 2005
Posts: 5
orange - See this Members User comments on their Profile page
Send a message via AIM to orange
Default Re: Trojan horse Backdoor.Agent.BA - HELP!!!!

Ok - I've downloaded the software, and its running as we speak - infact its been running for over 45 minutes now!

Being a computer novice, can you explain what/how I turn off (and on) System Restore?

Thanks for all your help so far - I really wanna beat this thing now!!!!


  #6  
Old 02-15-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Southern England
Posts: 11,299
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: Trojan horse Backdoor.Agent.BA - HELP!!!!

Originally Posted by orange
Being a computer novice, can you explain what/how I turn off (and on) System Restore?
Right click on "My Computer" > properties > system restore tab > check the box "Turn off system restore"

Please note that this will remove all previuos restore points!

Further detailed info on system restore is available here: http://www.pchelpforum.com/forum/ind...pic,145.0.html



__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation
  #7  
Old 02-15-2005
Bronze Member
 
Join Date: Feb 2005
Posts: 5
orange - See this Members User comments on their Profile page
Send a message via AIM to orange
Default Re: Trojan horse Backdoor.Agent.BA - HELP!!!!

Thanks - I ran the software, it says there are no traces of Backdoor.Agent.B on my system.

However, I'm running Microsoft 2000 Prefessional, and don't have a system restore tab in the properties of My computer

Help????



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:08 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top