# Trojan.PWS.Agent.SHZ

**URL:** <https://boards.straightdope.com/t/trojan-pws-agent-shz/499385>\
**Category:** Factual Questions\
**Created:** [June 10, 2009, 9:27pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385 "2009-06-10T21:27:55Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yssy](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@Yssy](https://boards.straightdope.com/u/Yssy)\
**Post date:** [June 10, 2009, 9:27pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/1 "2009-06-10T21:27:55Z")

</div>

Guys,

The above trojan is identifed by Bitdefender, Bitdefender deletes it. Next time I run Bitdefender, Bitdefender identifies it, Bitdefender deletes it …ad nauseam.

I’ve tried to delete the actual file but it just reappears seconds later.  
Spybot and Malwarebytes doesn’t detect anything.  
I’ve tried booting in safe mode and then deleting the file but it still reappears seconds later.

Trojan is embedded in a file called C:\WINDOWS\rgpo.bed.

I’ve tried googling this trojan but can find nothing specific, Bitdefender’s list of trojans doesn’t name this one as above.

I’m running windows XP professional

anyone? Any ideas? Theories? Vague ideas? Any help would be very gratefully received. 🙂

thanks  
Yssy

---

<div class="post-metadata">

**Author:** ![Mr.Slant](https://avatars.discourse-cdn.com/v4/letter/m/c57346/32.png) [@Mr.Slant](https://boards.straightdope.com/u/Mr.Slant)\
**Post date:** [June 10, 2009, 9:56pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/2 "2009-06-10T21:56:40Z")

</div>

Suggest not booting from YOUR copy of Windows.  
Use a bartPE or Linux LiveCD… or similar.

---

<div class="post-metadata">

**Author:** ![Yssy](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@Yssy](https://boards.straightdope.com/u/Yssy)\
**Post date:** [June 10, 2009, 10:01pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/3 "2009-06-10T22:01:48Z")

</div>

> [@Mr.Slant](#):
>
> Suggest not booting from YOUR copy of Windows.  
> Use a bartPE or Linux LiveCD… or similar.

How would I go about that? any good websites you would recommend that could talk me through that?

thanks

---

<div class="post-metadata">

**Author:** ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)\
**Post date:** [June 10, 2009, 10:02pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/4 "2009-06-10T22:02:47Z")

</div>

I’d also try using other ant-virus solutions in addition to what you are using; perhaps one of them can get it permanently.

I recommend free AVG and Microsoft’s Windows Defender (also free). It’s happened that Windows defender was able to get something AVG failed to remove.

---

<div class="post-metadata">

**Author:** ![Covered\_In\_Bees](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@Covered\_In\_Bees](https://boards.straightdope.com/u/Covered_In_Bees)\
**Post date:** [June 10, 2009, 10:05pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/5 "2009-06-10T22:05:33Z")

</div>

Isn’t the standard operating procedure for virus removal is that you boot your computer in safe mode first, _then_ attempt to delete it somehow?

Seriously asking, I’m very much a n00b when it comes to such things.

---

<div class="post-metadata">

**Author:** ![RedRosesForMe](https://avatars.discourse-cdn.com/v4/letter/r/91b2a8/32.png) [@RedRosesForMe](https://boards.straightdope.com/u/RedRosesForMe)\
**Post date:** [June 10, 2009, 10:11pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/6 "2009-06-10T22:11:34Z")

</div>

Thanks for starting this thread, I’m having a very similar problem with a trojan that avg and adaware keep identifying but never actually manage to delete/quarantine/whatever.

I’m trying some of the steps in the “computer questions” thread.

Fingers crossed for you and me both!

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [June 10, 2009, 10:54pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/7 "2009-06-10T22:54:37Z")

</div>

Ive had a lot of success with this [Malwarebytes](http://www.malwarebytes.org/mbam.php) for stubborn removals.

---

<div class="post-metadata">

**Author:** ![WolfpackJeep](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpackjeep/32/2921_2.png) [@WolfpackJeep](https://boards.straightdope.com/u/WolfpackJeep)\
**Post date:** [June 10, 2009, 11:51pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/8 "2009-06-10T23:51:11Z")

</div>

As a last resort, you could post a HijackThis log to a board that specializes in malware/virus removal. I’ve only had to do this once; I was very pleased with the results and response time.

---

<div class="post-metadata">

**Author:** ![samclem](https://avatars.discourse-cdn.com/v4/letter/s/a9a28c/32.png) [@samclem](https://boards.straightdope.com/u/samclem)\
**Post date:** [June 11, 2009, 1:40am UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/9 "2009-06-11T01:40:15Z")

</div>

> [@HorseloverFat](#):
>
> Ive had a lot of success with this [Malwarebytes](http://www.malwarebytes.org/mbam.php) for stubborn removals.

I, too, have had luck with that, but for one very serious virus I had to start the computer in safe mode and then run malwarebytes. But it got it.

---

<div class="post-metadata">

**Author:** ![WolfpackJeep](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpackjeep/32/2921_2.png) [@WolfpackJeep](https://boards.straightdope.com/u/WolfpackJeep)\
**Post date:** [June 11, 2009, 1:54am UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/10 "2009-06-11T01:54:51Z")

</div>

Totally off-topic, but I subscribe to threads to track replies…and that is a very scary subject line to have pop up in one’s inbox. 😉

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [June 11, 2009, 1:54pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/11 "2009-06-11T13:54:38Z")

</div>

> [@Yssy](#):
>
> Trojan is embedded in a file called C:\WINDOWS\rgpo.bed.

What I do when I clean out a recurring trojan file by hand is create a _directory_ by that file name. The trojan parent executable probably isn’t set up to delete a directory (as opposed to a file) and put it’s own version in it’s place. You still have to “unwind” things and find the ceator of the file, but it helps reduce the viral load.

Of course, you don’t let your AV software delete it after you make sure it’s still just a directory.

---

<div class="post-metadata">

**Author:** ![old\_joe](https://avatars.discourse-cdn.com/v4/letter/o/58956e/32.png) [@old\_joe](https://boards.straightdope.com/u/old_joe)\
**Post date:** [June 11, 2009, 3:59pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/12 "2009-06-11T15:59:14Z")

</div>

> [@Yssy](#):
>
> Guys,
> 
> The above trojan is identifed by Bitdefender, Bitdefender deletes it. Next time I run Bitdefender, Bitdefender identifies it, Bitdefender deletes it ..ad nauseam.
> 
> I’ve tried to delete the actual file but it just reappears seconds later.  
> Spybot and Malwarebytes doesn’t detect anything.

try cleaning all the temp files with cleanup! or ccleaner then remove restore on your hard drives. Beasties like to hang out in the restore area. Run HiJackthis and post the results to that forum. Get into safe mode and run Bitdefender (very good av by the way) and Malwarebytes. that should get whatever it is. If you are comfortable with registry then check the run area.  
good luck

joe

---

<div class="post-metadata">

**Author:** ![Yssy](https://avatars.discourse-cdn.com/v4/letter/y/bbce88/32.png) [@Yssy](https://boards.straightdope.com/u/Yssy)\
**Post date:** [June 11, 2009, 6:07pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/13 "2009-06-11T18:07:40Z")

</div>

Guys  
I knew this was the place, thank you all so much and apologies to Jeep Phoenix for the title of the thread!  
I tried AVG (thanks Revtim:)) it was a bugger to install but finally in the wee early hours of the morning it found it **AND** deleted it!

Huzzah!  
Yssy

---

<div class="post-metadata">

**Author:** ![WolfpackJeep](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolfpackjeep/32/2921_2.png) [@WolfpackJeep](https://boards.straightdope.com/u/WolfpackJeep)\
**Post date:** [June 11, 2009, 11:07pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/14 "2009-06-11T23:07:09Z")

</div>

Aww, the title wasn’t really a problem! 😃 Glad your computer is doing better.

---

<div class="post-metadata">

**Author:** ![Revtim](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/revtim/32/1042_2.png) [@Revtim](https://boards.straightdope.com/u/Revtim)\
**Post date:** [June 11, 2009, 11:11pm UTC](https://boards.straightdope.com/t/trojan-pws-agent-shz/499385/15 "2009-06-11T23:11:09Z")

</div>

Glad to hear that it’s gone! You are very welcome.
