Windows Security Alert – Trojan-Keylogger.Win32.Agent

Windows Security Alert that displays a warning regarding Trojan-Keylogger.Win32.Agent is a part of rogue application activities. The Trojan do not really exists on the computer and displaying it is a scare tactics to mislead victims.

Rogue security applications are known for producing bunch of false information once they are installed on target computer. This misinformation campaign helps authors to market the fake anti-virus and persuade users to obtain the commercial version of the product.

It is important for computer users to conduct a virus scan immediately when security warnings appear on the system. Whether it is legitimate or false information, a virus scan can directly eliminate presence of threats.

Screen Shot Image:

agentarpt

Technical Details and Additional Information:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Vista

Malware Behavior
The fake application will issue a considerable security alert. It mimics legitimate Windows warnings to deceive computer users. The fake alert will contain the following message:

Windows Security Alert
To help protect your computer, Windows Firewall has blocked some features of this program.
Do you want to block this suspicious software?
Name: Trojan-Keylogger.Win32.Agent.
Risk Level: High
Description: Agent.arpt is a Spyware program that records keystrokes takes screen shot of the computer.
Windows Firewall has detected unauthorized activity, but unfortunately it cannot
help you remove viruses, keyloggers and other spyware threats that steal your
personal information from your computer. Click to download and activate protection.

How to Remove Windows Security Alert – Trojan-Keylogger.Win32.Agent

1. Reboot your computer in Safe Mode with Networking.
- Continue tapping F8 on your keyboard after turning on the computer.
- From the selections menu, select Safe Mode with Networking.

2. Connect to Internet and download SuperAntiSpyware here.
3. Install SAS with default configuration. It will prompt for update when installation has completed.
4. After installation and update, SuperAntiSpyware will open.
5. On main window, select Scan Type, choose Complete Scan. This is recommended to detect all files associated to "Windows Security Alert".
6. Click on Scan your Computer…, this will give you options on which drive to scan.
7. On Scan Location, select c:\Fixed Drive.
8. Click on Start Complete Scan to begin the scanning process.
9. Scanning will take some time. Please be patient. When scanning is done, it will display the Scan Summary.
10. On scanning Window, items infected with "Windows Security Alert" are marked in check.
11. Click Next to remove infected items.
12. It will prompt you to reboot your computer. Click Yes to reboot.
13. After a reboot, open SuperAntiSpyware again. Go to the Main Menu and click Manage Quarantine.
14. Select all items that were quarantined and click Remove. This will completely remove all files and components of "Windows Security Alert".
15. Close the Window to exit SuperAntiSpyware.

What to do next...