Skip to main content
Published Oct 04, 2007 | Updated Sep 15, 2017

Trojan:Win32/Agent.ABA

Detected by Microsoft Defender Antivirus

Aliases: Trojan.Win32.Delf.abn (Kaspersky) W32/Relfeer.worm (McAfee) VIPRE.Suspicious (Sunbelt Software)

Summary

Trojan:Win32/Agent.ABA is a Trojan that may download additional malware and may also provide backdoor/proxy functionality.
Trojan:Win32/Agent.ABA may open connections that allow an attacker to download and install additional malicious software, thus manual removal is not recommended. To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx.
 
The following registry entry requires correcting; replace the value notepd.exe with notepad.exe, and remove "-v" as in this example:
 
 Trojan modified value:
 HKEY_CLASSES_ROOT\txtfile\shell\open\command
  (Default) = <system folder>\notepd.exe "-v" "%1"
 
 Corrected value:
 HKEY_CLASSES_ROOT\txtfile\shell\open\command
  (Default) = <system folder>\notepad.exe "%1"
Follow us