Getting rid of BackDoorAgent.BA

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nanc512, Sep 19, 2004.

  1. nanc512

    nanc512 Private E-2

    I have been trying to remove this nasty thing from my son's computer for a week now. I have done everything I have read about and it won't go away.

    I might have made a mistake when I read to rename it and drag it to the desktop. I did that and have run the Symantec Fix it software with no luck.

    I can't reboot in safe mode, it won't let me go to safe mode. I can't download anything from the net, because the home page is hijacked. Everyonce in a while I can get to google. When I do searches they all come back to the hijacked pages.

    I am ready to reformat and I don't want to. He has a lot of stuff on here and the CD drive has somehow been disabled. He didn't keep anything updated, which he has been told about. I have removed at least 13 viruses with AVG and so far none are coming back, but this BackDoorAgent thing.

    Do I give it up and reformat? I can't spend much more time on it, this is my business's busy season and I also work full time.

    Help?

    nancy
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Why wont it let you go to safe mode? Try start, run, msconfig and go to the boot.ini section and check safe boot. Optionally, tapping the f8 key on restart should do it. You really need to get the to do these scans. Let me know if you tried both of these ways and if they both failed.
     
  3. nanc512

    nanc512 Private E-2

    I tried going to Start/Run and then typed in msconfig. It says it can not find, make the path and file name are correct.

    I have tried tapping F8 at least a dozen times when I have rebooted and it just won't let me go into safe mode.

    There are additional programs installed also, and it won't let me remove them through the control panel. The remove button is greyed out.

    I think I have a mess, huh?

    nancy
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have never even mentioned what OS you have. Always provide that when looking for help.

    I believe that BackDoorAgent.BA is another name for the HSA hijacker. If that is the case, the fix will be complicated. You are going to have to be able to download programs somehow and get them onto this PC if you want to fix it. Can you do this someplace else and burn a CD to use on the infected PC?

    In fact a simple starting point would be to use a floppy disk. Download these to another PC and extract all of the .EXE files out of their respective ZIP files. Then copy them to a floppy and run them off the floppy on your problem PC.

    about:Buster: http://www.majorgeeks.com/download4289.html Run it sveral times (at least 3) and save the logs each time to a different file name.
    CWShredder: http://www.majorgeeks.com/download4086.html Make sure you select fix.
    HijackThis: http://www.majorgeeks.com/download3155.html Run a scan and save the log to a .txt
    file

    Come back here and tell me the results, post the about:Buster logs and the HijackThis logs as attachments.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  6. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Didnt see Chaslang, follow both our posts, ending with a Hijack This logfile if our ideas fail.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your right MA. I think your step should be followed first. I'm thinking of a different Backdoor something. I believe it was TrendMicro that used a similar name to identify what we commonly call HSA or only the best.

    While running my steps will not hurt anything, the symantec link you gave is the real fix for the Backdoor.Agent.BA problem.
     
  8. nanc512

    nanc512 Private E-2

    I have tried the fix it from Symantec and it doesn't find it. I ran AVG again last night and it is still there. I am ready to give up and reformat. I have Windows 2000 as the OS, but I can't even see the CD drive in the hardware list. I was just going to reformat and reinstall Windows XP Pro. But, without the CD drive being recognizable, I am lost.

    I am going to download those other files on my computer and put them on a floppy if they will fit.

    I was ready to throw in the towel and start over, but I can't even do that. He just got a new game today also and is patiently waiting for me to see if I can get this fixed.

    Thanks.

    Nancy
     
  9. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Ok, try pressing ctrl alt and delete, end the process that is the virus and then try deleting it. Check startup (start, run, msconfig) for the items being loaded. Im not there, so I dont know the filenames to tell you to look for :(

    I hope this makes sense to you because its gotten difficult.
     
  10. nanc512

    nanc512 Private E-2

    I know it is getting really difficult. I can't even open My Computer to access the drive that I downloaded the files too.

    I can get to the task manager, but there is a huge list of processes and I don't see one that says Back Door, I am sure it is there under an alias. I am not sure what should be there and what shouldn't. I probably need to close any programs in the task bar to make sure I don't kill something I shouldn't.

    I am really ready to reformat, but if I can't get the CD drive to work then it won't do me any good.

    Nancy
     
  11. nanc512

    nanc512 Private E-2

    I found a list of everything I should have in task manager, deleted what I could. There are a few left that I am not sure about, they weren't in the list from MS, but they won't allow me to delete them.

    avgserv.exe (I closed AVG and this till shows)
    hidserv.exe
    regsvc.exe
    MsPMSPSv.exe

    Everything else is legitimate.

    I am to the point of just thinking about repalcing the hard drive. This machine has the memory, graphics and sound card he needs for his games. Hard drives aren't that expensive anymore, so that may be an answer. I have replaced CD burners and done a very small amount of hardware stuff, but I can ask a guy that used to work for me to replace it, if it overwhelms me.

    I am to the point of feeling this "thing" is winning and it makes me mad. I can't believe how hard it is to find and eliminate. I have cleaned up people's computers before and taught them how to do the disk clean up and defrag. I don't give up easily and sounds like you guys don't either.

    Thanks!

    Nancy
     
  12. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We seem to have violate our golden rule somehow in this thread. Perhaps it is time to do things the right way. Maybe it would have caught the problem. So in that line here is the standard starting speech we seem to have skipped.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  15. nanc512

    nanc512 Private E-2

    I did start out there before posting my message the first time. I did get the services.msc to come up and neither of those items are there. I have the clean up programs on my USB memory stick, but I can't access My Computer and when I right cilck on start and click explore, I get an error that explorer.exe has generated errors and has been closed by windows and needs to be restarted.

    I have all those programs ready to load, but don't know how to get them to open since I can't access the drive anywhere.

    I didn't make it very far. If I could figure out how to access the memory stick, I could run them. I can even load Internet Explorer with getting the same error.

    Nancy
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this: Click Start, Run, and enter 'cmd' without the quotes and click okay.

    First try this (all commands are followed by the enter key):
    - cd \windows
    - copy explorer.exe explorer.com
    - explorer.com

    if that works see if you can get your info from the memory sticky. If not, continue below.

    Now at a command prompt. We need to guess at the drive letter of your memory stick so have it plugged in. I assume you have one harddisk and one CD drive, so start by entering E: and hit the enter key. (If that does not connect to the Memory Stick, keep trying other letters.) One connected, type 'dir' without the quotes. You should see the files you loaded. If you do, enter one of their names and hit enter. See if it will run/install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds