Jump to content

Backdoor.Agent.PBE


Recommended Posts

Hi. I'm getting a persistent Backdoor.Agent.PBE threat on a customer's PC. File locations is c:\Windows\System32\igfxres.dll

Have done a rename on this file but it still comes back. Spyware Doctor reports that it quarantines the agent on startup but this happens every startup and several times later too. The original infection came on the back of a UPS email attachment scam which the customer opened.

I've done a Combofix scan and HJT logs are clean. Ran a couple of rootkit tools that come back clean. This laptop has the Intel hardware associated with the igfx files (igfxtray.exe etc)

Running paid for SpyDoc 6.0.0.385 with AVG 8 free on XP Home SP3.

Malwarebytes antimalware current DB1242 detects nothing.

Is this a known threat or a false positive on Spyware Doctor's side?

Link to post
Share on other sites

Yep, Virus Total comes back clean. PC Tools have not come back to me yet.

Upgrading to Spyware Doctor 6 from version 5.5 flagged it as an infection. I have a test rig with 5.5 on which detects nothing (even with the hard drive mounted). Have tried lots of antivirus tools which don't pull it in as a virus either.

Just wondering if the MBAM team knew of anything.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.