answersLogoWhite

0

Good news : as of today, AVG can heal Trojan horse psw.agent.h !

I had the same Trojan on my computer, booting the OS in safe mode, and disabling system restore did not work for me. I also tried almost every Anti-Virus, Ad-ware, and Trojan software out there but nothing did it. The way to remove this PSW.Agent.H is simple, the only catch is there is a process running called sysupd.exe running which protects the Trojan source file in Documents and Settings (_UPDATE.DAT ) from being removed. So here is what you do.

Read all the steps below before you start.

1. Run a search on the computer for a file called sysupd.exe .

2. Open My Computer, and browse to the folder that contains the file.

3. Press Ctrl+Alt+Del, and click on Task Manager.

4. Look on the bottom of the Task Manager window to see how many process are running, ex (Process:15)

5. Find sysupd.exe and stop it. most likely it will keep starting it self over.

4. Keep looking for it and stopping it, until the number of process' go down by one. Once you reach this point you only have a few second until it restarts, so be quick.

5. Switch to the window where sysupd.exe is located and quickly remove it.

6. Once sysupd.exe have been removed, then you can remove the main file _UPDATE.DAT which will be found somewhere in Documents and Settings. (If you cannot find it run a search for it)

7. Run AVG antivirus again to make sure the Trojan is gone.

I do not use this web site at all, i only found it while I was searching on Google for what people are saying about this Trojan.

NOTE if you can't find the update.dat file after getting rid of the sysupd, its okay, just run your scan from AVG again. Its seems to be the virus software that finds this Agent H and only one that can heal it when you stop that sysupd process from running!

Edit

I had the same virus on my computer and couldn't get rid of it...finally today may 16th when i ran my avg....it healed it and now its gone. so try running avg again they may have figured it out or something. hope this works.

I had psw.agent.h & here's what I did:

I tried the above method but didn't get Task Manager when I used Ctrl-Alt-Del (I suppose it's because I'm not in Windows XP). Anyway, I couldn't get the sysupd.exe to shut off so I could delete it, because windows was currently using it. I restarted in MS-DOS mode (after looking up some commands online because I'm not too experienced with DOS) I went to the directory for windows & was able to delete sysupd.exe from dos, then restart in windows, delete _update.dat and ran AVG to make sure it was gone. So far it is gone (whoo hoo!) and I'm hoping this can help anyone who had similar trouble to mine. Feel free to email me any questions... :)

I tried the recommended ideas above and nothing worked. I would stop the program in tsk mgr and before i could delete it it would restart itself. but i finally found a way to get the program stopped so that avg could put the virus in the vault. i started my computer in safe mode and went in C:Windows and deleted the sysupd.exe because in safemode the program doesnt start up. then i re run avg in reg mode and it found the virus and removed it to the vault so i could delete it. thanks for your help.

All Trojan horses are hidden files so you would need to go to the Files Option (click the View tab)at Control Panel and uncheck both the *Hide file extension for known file types & *Hide protected operating system files (Recommended)-boxes, then OK yourself out. You will then need to restart your computer and and go into Safe Mode by holding the F8 key down -(kind of at the beginning of bootup). When you're at the DeskTop screen go to Start/ Search/ For Files and Folders and type up the NAME OF THE FILE & EXT which would have shown up on your Anti-Virus software, you can delete this file from here. Also, make sure to empty your Recycle Bin.

I have had 4 Trojan horses on my C drive and kinda figured out the above method a week ago. I deleted the Temp file from the Restore folder after unchecking the hidden files boxes, then went to SafeMode to delete what virus files that were still there. My computer is now absolutely FREE of these pests!

I fought this horse for a long time and here's what I finally did to get rid of it: 1. download the kill.exe utility

2. create the following bat file:

kill sysupd.exe

del /F c:\winnt\sysupd.exe

copy c:\winnt\notepad.exe c:\winnt\sysupd.exe

3. run this script from a command prompt over and over until the file sysupd is switched to notepad

4. now the damn horse is gone and you can successfully remove its data file (_update.dat) located somewhere under 'documents and settings'

Thanks to all for the invaluable information. These forums are my first stop when I need info.

I was also having trouble killing sysupd.exe with Task Manager and then deleting the file before it restarted. What worked for me was to start up a couple of CPU intensive apps, like AVG, Spybot, AdAware (all of which I couldn't do without) which slowed down my machine. This gave me enough time to kill the process, flip over to the file and delete it.

I then rebooted, and was able to delete _update.dat which was the infected file.

thanks to all for your help, Ken.

well, i had the szme problem - i run mcafee antivirus...

mcaffee - for some strange reason recognises this virus as backdoor-ajx, i guess they ain't updated their systems..

see now i managed to delete the _updatedat file by going into safe mode... its easy as chips thatway BUT i continously get my mcafee detecting and automatically deleting this 'backdoor-ajx' virus..

ive looked online for this virus and there are manual removal - but when i try them, i do not have the sysptoms...

has anyone else got this problem?

You can get rid of Trojan horse psw agent h and Trojan win32 killreg d from your computer by following these steps .1 Download and intall the Malwarebytes on your computer .

2 Update your Malwarebytes .

3 Scan your computer for all the malwares in your computer .

4 Remove all the malwares , found while scanning with the malwarebytes .

5 Restart your computer .

You need to run these 3 essential programs to remove all the spyware on your computer.

If you do not have an internet security suit and only an anti virus

1. Run Malwarebytes Anti-Malware

2. Run a complete scan with free curing utility Dr.Web CureIt!

3. Run the anti spyware removal programs spybot or Superantispyware

Browsers

Use Mozilla firefox or the Google chrome browser for browsing unsafe websites

Install ThreatFire

ThreatFire, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

Run an online virus scan like

Trend Micro HouseCall

Kaspersky free online virus scanner

Windows Live OneCare safety scanner

BitDefender Online Scanner

ESET Online Antivirus Scanner

F-Secure Online Virus Scanner

avast! Online Scanner

update your software by running

Secunia Online Software Inspector

Install a good antivirus in your computer.

Keep your antivirus updated. If automatic updates are available, configure your antivirus to use them.

Keep your permanent antivirus protection enabled at all times.

User Avatar

Wiki User

10y ago

What else can I help you with?

Related Questions

How do you remove Trojan horse Win32 Hilot I've tried avast and malwarebytes and spybot no positive results even in safe mode?

Download and run the Dr.Web CureIt!


AcuHangoverFullSetupSPexewho to delete it a non win32 .exe file?

Most of the time, win32.exe is added to the system as a result of the RATEGA virus. It is a Trojan horse give a remote user access to your computer. This process is a security risk and should be removed from your system. If found on your system make sure that you have downloaded the latest update for your antivirus application. So it is highly recommended that you should remove win32.exe from your computer immediately.


Why your sound is missing after win32 generic horse?

It must have corrupted the sound drivers


How do i remove Trojan win32 obfuscated?

I had thid god-awful trojan, that wasn't touched by TrendMicro or Ad-Aware or SpyBbot. But it was located and deleted by a FREE Kaspersky scan. www.kaspersky.com/virusscanner.


How do you get rid of genetic win32?

You cannot get rid of the, "win32" application. The reason why, you cannot get rid of the, "win32" application, is because, "win32", is the MOST important application for Microsoft Windows XP, Microsoft Windows Vista, and Microsoft Windows 7 RC, PCs and notebook, because that application helps Windows Firewall work. And also because, "win32", blocks Trojan horses, worms, viruses, and spyware, from hacking into your computer.


How do you remove Win32.Reckmess.A?

Of what i could find out, this is the same one as the one McAfee is calling troj.Downloader-SF.However there is not much known about this one. Best change of successfull removing this Trojan is probably by a Trojan-scanner.There is a online Trojan-scanner at http://www.windowsecurity.com/trojanscan/ Good luckJawwi :-)


How do you remove Trojan Downloader Win32 Istbar ce from a Dell PC running Windows 2000?

Check the security response section of Symantec's Norton AV website.


What is Trojan Horse Musicsearch and how do you remove it from C DOCUME 1?

Download and run firefox to protect your computer from future spyware attacks and pop ups which are coming in through internet explorer (Trojan downloaders, win32 ).Browser attacks aren't easy to spot because they piggyback on legitimate traffic that doesn't exhibit many obvious warning signs1. Run Deckard's System Scanner (DSS)2. Run the vundo and combo fix3. Run Malwarebytes Anti-Malware4. Run the anti spyware removal programs spybot5 Run Superantispyware6. Run a complete scan with free curing utility Dr.Web CureIt!Removing Trojan Horse MusicsearchYou can remove a Trojan horse such as Musicsearch with software such as SpyChecker or AVG. You can download them online and let the software do the work.


How do you remove Trojan horse downloader agent ID?

1. Download and run firefox to protect your computer from future spyware attacks and pop ups which are coming in through internet explorer (Trojan downloaders, win32 ).Browser attacks aren't easy to spot because they piggyback on legitimate traffic that doesn't exhibit many obvious warning signs . 2. Run the vundo and combo fix 3. Run Malwarebytes Anti-Malware 4. Run the anti spyware remove programs spybot 5. Run a complete scan with free curing utility Dr.Web CureIt!


How do you get rid of Trojan horse backdoor agent ioa?

1. Download and run firefox to protect your computer from future spyware attacks and pop ups which are coming in through internet explorer (Trojan downloaders, win32 ).Browser attacks aren't easy to spot because they piggyback on legitimate traffic that doesn't exhibit many obvious warning signs . 2. Run the vundo and combo fix 3. Run Malwarebytes Anti-Malware 4. Run the anti spyware remove programs spybot 5. Run a complete scan with free curing utility Dr.Web CureIt!


What is a Win32 application?

A Win32 application is a 32-bit application for Windows.


What does it mean by Win32 application?

AnswerA Win32 application is a program which has been written to use the Win32 Application Programmer Interface (API). The Win32 API is a collection of program functions which allow a program to trigger almost all operating system actions - such as opening a file. Win32 programs typically run under the Windows OS, however emulation of the Win32 API is available on other platforms.