recently i had my awsome system infected with spyware. i formated and they came back, i did again, came back. i tried making new partitions and they stay clen a little while, then come back. i htink my IP is listed and alg.exe is letting third party stuff come into my system and start its crap all over again. i think microsoft will becore suspicious again if i activate windows 5 times a week from formating. iv tried adaware, scan spyware, spy sweeper. alg.exe is ascoiated with firewalling by microsoft. some things i read its not harmful when it really is. i have spent too much time and effort building my awsome system, im not gonna get butt raped much longer by programs interfering with my work. one of my many dreams in life is putting a stop to all this **** by helping to make a law or i think we need to cut some pepoles hands off. so how exactly do i uninstall alg.exe, iv tried to delete it but it comes back. i have no clue what to do as im not as familure with XP as i would like to be. thanks all i need help BAD!

Dani AI

Generated

Short answer: alg.exe is normally the Windows Application Layer Gateway service (used so some protocols — FTP, SIP, games, etc. — can work correctly through the firewall/NAT). Deleting the real alg.exe can break connectivity; was right to warn against blindly removing it. Confirm whether the running alg.exe is the genuine system file before taking action. Microsoft: Application Layer Gateway service. (learn.microsoft.com)

Quick practical checks (do these first): open Task Manager, find alg.exe, right‑click → Open file location — it should be in C:\Windows\System32. Check Properties → Digital Signatures for a Microsoft signature. Check Services (services.msc) or run sc query ALG to inspect the ALG service state. On modern Windows you can also run the PowerShell signature check: Get-AuthenticodeSignature "$env:windir\System32\alg.exe". If the file is somewhere else or unsigned, treat it as suspicious. (win10.io)

If it looks suspicious do NOT delete files at random. Run updated full AV and an offline/rootkit scan (bootable rescue media or Microsoft Defender Offline) and use an anti‑rootkit scanner (for example RootkitRevealer / vendor tools). If re‑infections continue after a full reinstall, consider persistence vectors beyond the OS: MBR/bootkits, infected external media, or even a compromised router (router firmware can harbor persistent malware and re‑infect clients). Repairing MBR/boot configuration or using a clean install image from a known‑good machine is often required; factory‑reset and update router firmware if needed. (learn.microsoft.com)

Suggested triage flow: 1) verify path/signature; 2) collect logs (HijackThis-style log per was a good call) and run offline scans; 3) if malware found, clean with AV + anti‑rootkit tools; 4) if it returns after reinstall, wipe partitions (not just one), rebuild MBR/BCD or reinstall from clean media, and check/reset router/firmware. These steps cover the common causes of the “keeps coming back” problem without trashing a legitimate system service. (learn.microsoft.com)

Recommended Answers

All 3 Replies

Don't remove alg.exe! More info on it here:

Read this thread, it may help:
http://www.daniweb.com/techtalkforums/thread16365.html

Get HijackThis from here so we can help with whatever the real problem is:

Close all browser windows, 'Scan and Save Log' with hijackthis, copy and paste the entire log here in this thread.

iv fixed it, thanks to microsfot anti-spyware beta 1.

amd 3400+
asus K8N-E 800fsb, nforce3
x800 XL @ 420/1100
1gig samsung PC3500

iv fixed it, thanks to microsfot anti-spyware beta 1.

Hey, it's been awhile :)

Glad you got it cleaned up and thanks for letting us know!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.