Backdoor.Agent


· Overview ·
· Origins ·
· Distribution ·
· Operation ·
· Detection and Removal ·
· Research ·



Overview

Category:

Backdoor: A secret or undocumented means of getting into a computer system, or software that uses such a means to penetrate a system. Some software has a backdoor placed by the programmer to allow them to gain access to troubleshoot or change the program. Software that is classified as a "backdoor" is designed to exploit a vulnerability in a system, and open it to future access by an attacker.

Variants:

  • Backdoor.Agent.a
  • Backdoor.Agent.ac
  • Backdoor.Agent.ag
  • Backdoor.Agent.b
  • Backdoor.Agent.bc
  • Backdoor.Agent.bg
  • Backdoor.Agent.d
  • Backdoor.Agent.h
  • Backdoor.Agent.i
  • Backdoor.Agent.j
  • Backdoor.Agent.m
  • Similar Pests:

    Backdoor

    Origins

    Date of Origin:

    Variants from December, 2003 to August, 2004

    Distribution

    Prevalence:

  • Backdoor.Agent.bc: < 0.00005%
  • Backdoor.Agent.bg: < 0.00005%
  • More Info

    Clot Factor:

  • Backdoor.Agent.bc: 1
  • The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.

    Growth:

  • Backdoor.Agent.bc: Insufficient data to report growth
  • Backdoor.Agent.bg: Insufficient data to report growth
  • Operation

    Storage Required:

  • Backdoor.Agent.a: at least 61 KB
  • Backdoor.Agent.b: at least 41 KB
  • Backdoor.Agent.bc: at least 89 KB
  • Backdoor.Agent.bg: at least 317 KB
  • Backdoor.Agent.d: at least 89 KB
  • Backdoor.Agent.h: at least 73 KB
  • Backdoor.Agent.i: at least 93 KB
  • Backdoor.Agent.j: at least 509 KB
  • Backdoor.Agent.m: at least 37 KB
  • Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    Follow these steps to remove Backdoor.Agent from your machine. Begin by backing up your registry and your system, and/or setting a Restore Point, to prevent trouble if you make a mistake.
    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove AutoRun Reference:

    Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\aqadcup, delete it and reboot the machine immediately.



    Unregister DLLs:

    Unregister these DLLs with Regsvr32, then reboot:

    Clean Registry:

    Remove these registry items (if present) with RegEdit:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Research

    File Analyses:

    More Info:

  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • PestPatrol's Pest Research Center
  • Last Revised:

    April 25, 2005