SCAgent

Description: Spyware
Risk Level: High
Date of First Occurence: Tuesday, May 13, 2008
Software Developer: CoolWebSearch.com
Brief Info: SCAgent is a backdoor and likely homepage hijacker, implemented as an Internet Explorer HTML filter with a guardian process scagent.exe in the System32 folder, run as a Windows NT Service that ensures it is not deleted.
Removal: This threat can be removed using "Spyware Terminator"

REMOVER SPYWARE »

Geographical Distribution of Threat "SCAgent"

Threat Info

View All

Detected Items

  1. Detected Files: %WINDIR%\httpfilter.dll MD5: FF734534F960D2B62BDE82BFCE51846E Size:29696 MD5: 19C75E8F90810C6A437267B1A8C67C93 Size:43008 %WINDIR%\digfilt.dll MD5: CD63C7607D2AA119BBB26C454C42C9A4 Size:30208
  2. Detected Files with variable Filenames: MD5: 19C75E8F90810C6A437267B1A8C67C93 Size: 43008 %WINDIR%\httpfilter.dll %WINDIR%\digfilt.dll

Detecting items list:

  1. Files by Name %windir%\httpfilter.dll %windir%\digfilt.dll
  2. Files by CLSID or Name CLSID=EE7A946E-61FA-4979-87B8-A6C462E6FA62

« Go to Software Database