Startup List Results
Startup Entry
Startup Entry
Name | Filename | Description | Status |
OSD | ALG.exe | Added by the StartPage-ID TROJAN! - NOTE: this file is located in the WINDOWS\msagent\intl folder! | X |
O23 List Results
Windows Services
Windows Services
Name | Filename | Description | Status |
@%SystemRoot%\system32\Alg. exe,-112 (ALG) | alg.exe | Related to Application Layer Gateway Service Provides support for 3rd party protocol plug-ins for Internet Connection Sharing (ICS). Note: Located in \%WINDIR%\%System%\ Note: This service on Vista or Windows 7 - 64 bit operating system is launched by svchost.exe, but the actual application is what is listed as the filename. | L |
Application Layer Gateway Manager (AppLayerGatewayMgr) | alg.exe | Added by W32/Tilebot-EU WORM!, Note: not to be confused with see_Here Note: located in C:\Windows\System32\ this infection is locate in C:\Windows\ | X |
Application Layer Gateway Service (ALG) | alg.exe | Provides support for 3rd party protocol plug-ins for Internet Connection Sharing and the Internet Connection Firewall Note: Located in C:\%WINDIR%\System32 (Vista /XP/WinNT/2K) | L |
Application Layer Gateway Services | alg.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ | X |
Microsoft Language Service (Windows Language Service) | alg.exe | Added by an unidentified TROJAN! of the Sdbot family. Note: This worm\trojan is located in C:\%WINDIR%\ folder | X |
Drivers List Results
Driver Entry
Driver Entry
Name | Filename | Description | Status |
WinMan | alg.exe FwStar | Added by the Infostealer trojan, detected by Kaspersky antivirus as Trojan.Win32.Swisyn.clao | X |
Active Setup List Results
Active Setup - Installed Component
Active Setup - Installed Component
CLSID | Name | Filename | Description | Status |
{2bf41072-b2b1-21c1-b5c1-0305f4155515} | (no name) | alg.exe | Infostealer, detected as W32/Sdbot-DJD Win32 worm | X |
{E558FC6D-FC2D-AB5E-CFA1-7ACCEECFA2BD} | (no name) | Alg.exe | Infostealer trojan, detected by Kaspersky antivirus as Trojan.Win32.Jorik.Shakblades.ble, see this ThreatExpert Report | X |
{6EFC4044-77D9-47E7-197B-B6BE2C7DB41} | (no name) | alg.exe | Infostealer trojan, detected by Kaspersky antivirus as Trojan.Win32.Autoit.aqx, see here | X |
{6E7LF4NN-5I00-XIRJ-G8AA-CL17M8Q710KX} | (no name) | alg.exe | Infostealer trojan, detected by Kaspersky antivirus as Trojan.Win32.Autoit.aru, see here | X |
{ORRK7KOT-76UJ-N4B5-4OBN-4A5PQNHHBX3Q} | (no name) | alg.exe | Infostealer trojan, detected by Microsoft as Worm:Win32/Rebhip.A - also see here | X |