POPUP_DIALOG.EXE - Dangerous
POPUP_DIALOG.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
POPUP_DIALOG.EXE is known as: Trojan.Win32.Agent2 [Ikarus].
MD5 of POPUP_DIALOG.EXE = 6E20AF089063360EA8DB2C7F7F679407
POPUP_DIALOG.EXE size is 1745408 bytes.
Full path on a computer: %COMMONAPPDATA%\SYSMON\POPUP_DIALOG.EXE
Related Files:
%COMMONAPPDATA%\SYSMON\ASK.DLL
%COMMONAPPDATA%\SYSMON\ASK_KILL.EXE
%COMMONAPPDATA%\SYSMON\FLT_LOADER.EXE
%COMMONAPPDATA%\SYSMON\LOGS\PREVUSER.USR
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONAGGREGATEDLOG.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONAPPLICATIONS.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONCLIPBOARDMONITOR.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONFILEMONITOR.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONKEYLOGGER.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONLOGONLOGOFF.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONMESSENGER.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONPRINTERMONITOR.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONSCREENSHOT.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONSCREENSHOTWEB.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONALLDAYSYSMONWEB.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONAPPLICATIONS.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONCLIPBOARDMONITOR.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONFILEMONITOR.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONGLOBALLOG.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONKEYLOGGER.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONLOGONLOGOFF.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONLOGONLOGOFF_20110828.XMM
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONMESSENGER.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONPRINTERMONITOR.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONSCREENSHOT.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONSCREENSHOTWEB.XSL
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONSCREENSHOT_20110828.XMM
%COMMONAPPDATA%\SYSMON\LOGS\SYSMONWEB.XSL
%COMMONAPPDATA%\SYSMON\NULL_FLT.SYS
%COMMONAPPDATA%\SYSMON\POPUP_DIALOG.EXE
%COMMONAPPDATA%\SYSMON\SYSMON.EXE
%COMMONAPPDATA%\SYSMON\SYSMONFTPUPLOADER.EXE
%COMMONAPPDATA%\SYSMON\SYSMONHELP.CHM
%COMMONAPPDATA%\SYSMON\SYSMONLAN.EXE
%COMMONAPPDATA%\SYSMON\SYSMONSCRCAP.EXE
%COMMONAPPDATA%\SYSMON\XCACLS.EXE