Trojan Horse Back Door Agent .2.H !
Trojan Horse Back Door Agent .2.H !
Author
Discussion

Tonyrec

Original Poster:

3,984 posts

279 months

Monday 19th July 2004
quotequote all
Has anyone had this recently.

Seems like my free edition of AVG cant shift it.

joust

14,622 posts

283 months

Monday 19th July 2004
quotequote all
If you mean

W32.HLLW.Gaobot.AE

then it's a little bit complicated to remove it.

Follow the instuctions at
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.bt.html

particularly the disabling of system restore (otherwise it will put it back), and the fact that you have to kill the process / restart in safe mode before running your AV programme.

Finally you need to delete the reg key, but back up your registery if you aren't 100% sure what you are doing!

J

slinky

15,704 posts

273 months

Monday 19th July 2004
quotequote all
[hijack]

I know best practice is to backup the registry prior to making changes, but have you ever actually had any problems following a registry change?

slinky
[/hijack]

joust

14,622 posts

283 months

Monday 19th July 2004
quotequote all
slinky said:
[hijack]
I know best practice is to backup the registry prior to making changes, but have you ever actually had any problems following a registry change?
slinky
[/hijack]
Yes - and it took all night to get the dam WinNT 4.0 server back after one of my staff cocked it up slightly.

J

slinky

15,704 posts

273 months

Monday 19th July 2004
quotequote all
ahhh.. one of your staff cocked it up..

Righto..

I tend to only make "prescribed" changes, making sure that they are definitely what needs doing..

[/sanity check]

slinky