Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Help! AVG Detected Trojan Horse PSW.Agent.ABKU. How do I remove this?

  • Please log in to reply
4 replies to this topic

#1 way lee

way lee

  • Members
  • 1 posts
  • Local time:08:21 AM

Posted 22 July 2009 - 01:11 AM

Hi there,

I'm a first time user to this forum. I use AVG and today when I logged on, they had a pop-up notification for a Trojan Horse PSW.Agent.ABKU, I've googled it and it seems nothing has popped up about this specific Trojan Horse.

AVG keeps informing me that it has infected my C:\\Windows\system32\winlogon.exe.

I am definitely not anywhere near a computer expert and am desperately seeking help! Any information would be appreciated!

(Also, I have performed a quick scan by Malwarebytes and nothing came up, I am currently performing a full system scan in hopes of finding something). Any help or suggestions would be greatly appreciated!!!

Thank you so much!!

-Way Lee

BC AdBot (Login to Remove)


#2 rigel



  • Members
  • 12,944 posts
  • Gender:Male
  • Location:South Carolina - USA
  • Local time:11:21 AM

Posted 22 July 2009 - 07:17 AM

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on launch.exe to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and unheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

"In a world where you can be anything, be yourself." ~ unknown

"Fall in love with someone who deserves your heart. Not someone who plays with it. Will Smith

#3 JGSmith


  • Members
  • 2 posts
  • Local time:10:21 AM

Posted 22 July 2009 - 11:10 AM

Way Lee,

I'm having the same problem but am away from the infected computer at this time.

I can tell you that I've tried scanning with AVG, MBAM, SBS&D, and Ad-Aware... and only AVG detects it, but cannot cure it, so let me know if the above helps you out and I'll keep you posted if I find anything that fixes it for me.

#4 Charlessee


  • Members
  • 1 posts
  • Local time:11:21 AM

Posted 22 July 2009 - 03:05 PM

Wow, I've been having this problem too and I checked with other antispyware software to find no threats/infections. I'm guessing this some sort of problem with avg and these are false positives; I fixed the constant popups by exiting out of the AVG tray, no antivirus running, but the continous pop ups frustrate the hell outta me.

#5 Cubbie3798


  • Members
  • 2 posts
  • Local time:08:21 AM

Posted 24 July 2009 - 12:09 AM

Hi! I have heard from several folks that this probably isn't a false positive. Viruses can exist on our systems and yet go undetected if they are not part of the anti-virus database. Here's what I did to fix mine:

After AVG ran yesterday, it found the psw.agent.abku virus in the winlogon.exe file. After unsuccessfully trying numerous programs to remove it, I found something that worked. My dad and I have the same computer, so I copied his clean winlogon.exe file to a thumb drive and renamed it 'winlogon.new.exe.' I then copied it into my Windows>System32 folder (where the infected file was located). I rebooted the computer in Safe Mode and chose the "Command Prompts" option. Once in DOS, I changed the directory to System32. I then renamed the infected file to 'winlogon.old.exe' and renamed the clean file to 'winlogon.exe'. Because the winlogon file is used all the time while Windows is operating, the only way to change the name is through the DOS commands. I rebooted the computer and verified that the old winlogon file still had the infection (had to make sure it didn't move elsewhere), and deleted that file. I then ran a full system scan, and I am now virus free! You should be able to do this same thing as long as the clean file is coming from a computer running the same operating system and service pack.

Good luck!

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users