Jump to content
Sign in to follow this  
Diane P.

RogueAgent/Gen-Nullo.(Exe)Process

Recommended Posts

This object was identified and quarantined via Real Time Protection this am. This file was located in C:\Windows\System32\MRT.exe. I understand MRT.exe is the Windows Malicious Software Removal tool executable. This doesn't make sense to me, but that's why I'm posting. I also looked in the real time protection log to fully ID the file and it's location.

 

I have run the full scan as recommended. I have also run Windows Defender and the professional version of MBAM, with no results.

 

I rebooted my laptop and looked in the Real Time Protection folder and the RogueAgent/Gen-Nullo process is no longer there.Is this proper SAS behavior? I did not receive any further messages that the file is on my laptop.

 

I don't know if I need to do anything further....and am seeking further advice here. Thanks.

 

D.

Share this post


Link to post
Share on other sites

There are no entries in the subsequent scan logs; nothing was found. I have scanned with MBAM and Windows Defender as well...nothing was found. I have gotten no further real time pop-up messages from SAS either.

 

Thanks for answering.

 

Diane

Share this post


Link to post
Share on other sites

May have been a minor glitch, or MRT had started in the background and SAS picked it up momentarily as suspicious before deciding it is trustworthy. ???

 

I have no idea to be honest, I've never seen that happen before.

Share this post


Link to post
Share on other sites

I ran MRT and Spybot S & D as well, and nothing was found.

 

I would like to know however, what SAS does when it  finds a file In Real Time Protection & asks that a scan be run which I did. Then after I run the scan and look in the Real Time Protection folder is the file it originally found supposed to be there or not?

 

When I clicked on the Real Time Protection tab, the file was there and quaratined. I did not delete it. I ran a full scan, looked in the folder, the file was gone. Should it have been there or not? it doesn't seem to me I have an issue now, but would like to know for future reference. TIA.

 

Diane

Share this post


Link to post
Share on other sites

According to the documentation, "If the file is detected as an infection it is prevented from running." <source>

 

Other than that without being able to reproduce it I have no idea.

 

You could always ask for a diagnostic, just go to Help and Information on the programs Home page and select Submit a Diagnostic Report.

Share this post


Link to post
Share on other sites

I also have a problem with Rogue.Agent/Gen-Nullo.  The SuperAntiSpyware scan keeps detecting this threat but keeps not removing it.  What can be done about this please.  I have reported that my laptop is infected and I have run Malwarebytes, Spybot, Rkill, Norton Power Erase but I cannot remove this threat.  I have taken a screenshot but can't attach it.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  

×