I’ve tried several searches here for this topic. No luck.
My Sygate Firewall reported this trying to “call out”.
After several searches I found agl.exe is supposed to be Application Layer Gateway Service which is a Windows Service.
The location just did not look right.
Adaware says it is a Win32.Backdoor.Agent.
This is what I have.
SornSoft seem to make some very suspicious software.
It loads on startup.
C:\Program Files\Common Files\alg.exe
Remote Name : www.sorn-soft.com
Remote Address : 188.8.131.52
Should I look further or can I just remove it and forget it?
I noticed RoorRepeal is used a lot.
I downloaded it to see what it looked like.
I tried to run it after turning off all my security.
Auto-protect, Spybot, Firewall. Even spam filter.
It freezes at initializing.
Lots of hard drive activity and lots of memory and 100%CPU.
I needed Task Manager to kill it.
Edited by JoeGons, 15 November 2009 - 02:26 PM.