SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


PSW Agent H Trojan found

Reply
 
Thread Tools Search this Thread Rating: Thread Rating: 3 votes, 5.00 average. Display Modes

  #16  
Old 05-06-2004, 02:25 PM
MikeAngelastro Offline
Junior Member
 
Join Date: May 2004
Posts: 2
Hi,

I did wait until the process count decreased by one. The processed stopped for only one quarter of a second or less - not long enough for me to change windows and delete the file. Maybe I haven't played enough computer games to be able to wield my mouse quickly enough. Anyway the process I discovered works immediately and without a contest.

Thanks,

Mike
Reply With Quote

  #17  
Old 05-07-2004, 05:09 PM
jackk Offline
Junior Member
 
Join Date: May 2004
Posts: 1
Another way of stopping sysupd.exe is to go to "run", type "msconfig", and click on the startup tab. There is a line there with sysupd. Uncheck that box, click apply, and restart the system. AVG should take care of the rest. Don't forget to turn off system restore before starting the scan.
Reply With Quote

  #18  
Old 05-09-2004, 09:20 AM
Rev. Bruce Offline
Junior Member
 
Join Date: May 2004
Location: N.W. Pa.
Posts: 2
Smile in 98

I don't know if this works in XP but in windows 98 I just started in safe mode. Then I deleted "sysupd.exe" then "_UPATE.DAT". Fallowed by a reboot and all is just fine now. By the way I would have never known what to deleted if I had not found you guys, Thanks.
__________________
I am Who I am, I think!!
Reply With Quote

  #19  
Old 05-09-2004, 09:29 AM
windamyr Offline
Junior Member
 
Join Date: May 2004
Posts: 1
Hi all,

New here and thought I'd post how I got rid of this stupid Trojan.

I'll admit, I am a technodummy, and have a hard time doing anything beyond the basics on my computer. I spent a week trying to figure out how to cleanse the machine! My kids go to game sites, and I think that's where I got this one, as well as a couple of other nasty bugs!

Anyway, I managed to get rid of all the viruses except this PSW.Agent. H. I did however finally figure out how to do it simply!

Run the computer in Safe Mode, run your AVG virus scan, and guess what? It heals this last bugger without you having to do a thing!

Ahhhh, life is good when you have a clean computer!!
Reply With Quote

  #20  
Old 05-09-2004, 11:34 AM
ORHusky Offline
Junior Member
 
Join Date: May 2004
Location: NW US
Posts: 1
Thanks

Thanks all for the great info. Was able to get my wife's computer up and running. Where did this one come from and any ideas on how it spreads???
__________________
ORHusky
Reply With Quote

  #21  
Old 05-09-2004, 06:37 PM
Rev. Bruce Offline
Junior Member
 
Join Date: May 2004
Location: N.W. Pa.
Posts: 2
Nice one windamyr, and I thought my fix was simple. The way you did it you don't even have to know what files to look for. I don't think "technodummy" is the right word for you, how about if we say "tech genius in training" instead.
__________________
I am Who I am, I think!!
Reply With Quote

  #22  
Old 05-09-2004, 06:39 PM
Azn_tweaker's Avatar
Azn_tweaker Offline
w1nD0w5 xP Tw3aK3r GuRu
 
Join Date: Feb 2004
Location: Toronto, Canada
Posts: 811
lol
__________________
joined my friends forum.
www.osdevil.com
Pentium 4 1.5GHz, 128RDRAM, 40GB HD, WinXP Pro w/SP1, NOD32, XP ICF, SpywareBlaster 3.1, SBS&D 1.3, Ad-Aware 6.0 Professional, CWshredder 1.57
Reply With Quote

  #23  
Old 05-13-2004, 12:57 PM
Cartman Offline
Junior Member
 
Join Date: May 2004
Posts: 2
Pleez help

Hey ppl, i need help with removing that Agent.H virus! I've tried everything as written in this thread but nothing works:

i've tried searching that sysupd.exe but the only match my computer found was a single sentence in a wordpath of Doctor Norton anti-virus. Howcome??

i've also tried restarting my commputer in save modus and running the AVG programm...but it won't run in save modus!
Howcome?

Anybody has a suggestion? Pleez let me know,
thanx a lot!

Cartman
Reply With Quote

  #24  
Old 05-13-2004, 03:09 PM
MrsBuz's Avatar
MrsBuz Offline
Junior Member
 
Join Date: May 2004
Posts: 1
Similar problem here, although it is a different variant.
Here's what AVG error looks like:

AVG Resident Shield

Virus
Trojan Horse PSW.Agent.G

is found in file
C:\System Volume Information\_restore(94A30892-E7C1-40C8-805F-6672E94D88B2)
\RP134\A0258820.exe

To remove this virus, please run AVG for Windows

Could not apply the 'fixes' for the "H" variant, probably due to the location of mine being different. Nothing close listed in running processes window.

Any more help?
__________________
Rita
Reply With Quote

  #25  
Old 05-13-2004, 04:20 PM
losinsusan Offline
Junior Member
 
Join Date: Apr 2004
Location: IL
Posts: 20
You need to turn off restore, run the virus checker again and turn restore back on
Instructions here:-
http://virusall.com/remrestore.html
Hope it helps.
Report
__________________
"Hang on to Hope"
Reply With Quote

  #26  
Old 05-15-2004, 05:09 AM
Shai_1 Offline
Junior Member
 
Join Date: May 2004
Posts: 2
Didn't Work

I've tried everything here, but nothing has worked. My problem is that I can't find the file "sysupd.exe". The only file I found was "sysupd" and "SYSUPD.EXE-3B2AF10B". I don't know if either of those are the right files, so I don't want to delete one of them unless I'm sure. Please help me if you can.

Thanks! :-)
Reply With Quote

  #27  
Old 05-15-2004, 09:41 AM
Cartman Offline
Junior Member
 
Join Date: May 2004
Posts: 2
AVG won't work in safe modus!

Hey guys,

i've tried everything, but maybe i did it wrong?:

1st:
i've tried starting wndows up in safe modus (system restore is off!) and run AVG (6.0 free edition)... but it says it uses my hard disk to run...and cant run in safe modus!

2nd:
I wen't to "Startmenu/run" and typed msconfig (as mentioned in one of the threads).
I went to startup (or whatever you guys call it, cuz im dutch)...and disabled that line saying "sysupd ..etc
But...there are two lines containg this filename...and one of them keeps getting activated! (system restore still turned off) So AVG still can't remove it

any suggestions?
Thanx a lot
Reply With Quote

  #28  
Old 05-17-2004, 08:25 PM
cmbaetz Offline
Junior Member
 
Join Date: May 2004
Posts: 1
Smile How I fixed this

Hi all, I found this, and had to come up with a way to fix this on a remote computer. I could not boot to safe mode. this is what worked for me on a Win XP machine. and thanks for all the posts so far, it allowed me to find the files needed.

I tried using taksmgr to kill sysupd.exe, and as other described was not fast enough.

So...
I created an old fashon BAT file with the following commands to kill off the quickly reoccuring program, and then delete the thing.

using notepad enter the following, changing the location of the file to delete if needed, and save it as c:\fix1.bat
-----------------
taskkill /F /IM sysupd.exe
taskkill /F /IM sysupd.exe
taskkill /F /IM sysupd.exe
taskkill /F /IM sysupd.exe
taskkill /F /IM sysupd.exe
taskkill /F /IM sysupd.exe
del c:\windows\sysupd.exe
----------------
Next open a command window by choosing start > run > cmd

from the command window type fix1 and hit enter.

You may have to run it 2-3 times. Took me 2

good luck!
Reply With Quote

  #29  
Old 05-18-2004, 09:09 AM
losinsusan Offline
Junior Member
 
Join Date: Apr 2004
Location: IL
Posts: 20
Cartman..I also had two of them running. I did each one separately. Keep deleting it. It comes back up I know. Line up the windows side by side so you can be ready....when the processes finally drops by one. Then you quickly right click and delete the sys file. Do it again for each one there.
__________________
"Hang on to Hope"
Reply With Quote

  #30  
Old 05-18-2004, 10:45 AM
Shai_1 Offline
Junior Member
 
Join Date: May 2004
Posts: 2
I Got It!!!

Never mind about what I said, I finally got the virus off. Thanks so much for your help, Pc Master.
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Horses buddottin Windows XP 1 11-05-2004 08:25 AM
Trojan Backdoor Agent, among other things lyinfait Windows XP 6 07-19-2004 08:33 PM
Downloader.qdown.c trojan (help!) Thorin Hammer Windows XP 14 07-16-2004 04:35 PM
Protection against the First Mac OS X Trojan Horse Azn_tweaker Chit Chat 1 04-10-2004 11:53 AM
Trojan advice needed! chrisinthesun20 Windows XP 3 12-01-2002 09:28 AM



All times are GMT -5. The time now is 03:24 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.