Win32:Agent-LRU[Rtk]

hello,
While surfing on the web Avast! detected an .exe file (r-k.exe) as virus in
c:\windows
The properties of this virus are:
Win32:Agent-LRU[Rtk]
Avast! recommandation is to put this file in quarantine (not to delete)

What damages can this .exe file cause in my computer (if not put in quarantine) ?

Hi goofyto8,

‘Agent’ is a fairly generic name, but I think it might be a fake video codec or similar. If run, it might pop up ads for a scam anti-virus product or redirect your browser to scam/spyware sites.

thank you very much.
I agree ,Avast! alert was probably caused by a pop-up window on website.

Hi goofyto8,

Probably avast prevented this from nesting onto your computer,
else here you have the cleansing routine for this malware:

Step 1 : Use Windows File Search Tool to Find Win32.Agent Path

  1. Go to Start > Search > All Files or Folders.
  2. In the “All or part of the the file name” section, type in “Win32.Agent” file name(s).
  3. To get better results, select “Look in: Local Hard Drives” or “Look in:
    My Computer” and then click “Search” button.
  4. When Windows finishes your search, hover over the “In Folder” of “Win32.Agent”,
    highlight the file and copy/paste the path into the address bar.
    Save the file’s path on your clipboard because you’ll need the file path
    to delete Win32.Agent in the following manual removal steps.

Step 2 : Use Windows Task Manager to Remove Win32.Agent Processes

  1. To open the Windows Task Manager, use the combination of CTRL+ALT+DEL or CTRL+SHIFT+ESC.
  2. Click on the “Image Name” button to search for “Win32.Agent” process by name.
  3. Select the “Win32.Agent” process and click on the “End Process” button to kill it.
  4. Remove the “Win32.Agent” processes files:

sskupdater.exe
ssk.exe
sskupdater.exe5102.exe
ssk.exe
5102.exe

Step 3 : Detect and Delete Other Win32.Agent Files

  1. To open the Windows Command Prompt, go to Start > Run > type cmd and then press the “OK” button.
  2. Type in “dir /A name_of_the_folder” (for example, C:\Spyware-folder), which will display the folder’s content even the hidden files.
  3. To change directory, type in “cd name_of_the_folder”.
  4. Once you have the file you’re looking for type in “del name_of_the_file”.
  5. To delete a file in folder, type in “del name_of_the_file”.
  6. To delete the entire folder, type in “rmdir /S name_of_the_folder”.
  7. Select the “Win32.Agent” process and click on the “End Process” button to kill it.
  8. Remove the “Win32.Agent” processes files:

sskupdater.exe
ssk.exe
5102.exe

polonus

Hi Polonus,

thank you for your help but I can’t delete this malware with the step by step process you indicate .
I can’t find the following files
sskupdater.exe
ssk.exe
sskupdater.exe5102.exe
ssk.exe
5102.exe

First I must tell to you that my OS is WIN 98.

  1. The Avast! warning window opens each time I start my computer and Win 98 opens.
  2. The file detected by Avast is named r-k.exe[FMX] located in C:\windows

Avast! windows indicates that it contains the malware Win32:Agent-LRU and the type of virus identified is Rootkit
3) if I click on the delete button in Avast! window, it’s OK for the session, but when I stop my PC and restart it ,Avast! alert still warns me when Windows opens with the presence of the r-k.exe[FMX] file.
It seems that this file although deleted is regenarated

How to do to be able to delete definitively this malware from my hard disk ?

hello,

I’ve completely eliminate the files by checking the case

  • deleting when the OS re-start

instead of trying to kill them immediately