What is Alg.exe?

What is Alg.exe?

Alg.exe – Definition

Alg.exe (Application Layer Gateway) is a core Windows file and is critical for Windows firewall. The main function of Alg.exe is to provide support to third-party applications, such as firewall, IM clients, and ICS (Internet Connection Sharing).

Alg.exe – File Information

By default, the alg.exe file is located in the C:\Windows\System32 folder. The most common size of the alg.exe file is 44,544 bytes. You may also find the file in 41,984, 40,960, 45,056, 43,520, 51,712, 153,088, 88,576, 59,392, 222,172, 58,880, 48,128, 89,088, 54,272, 55,296, and 45,568 bytes sizes.

Is it safe to terminate alg.exe?

If you use Microsoft Firewall or share files, printers, or resources, then it is recommended that you do not remove this process.

However, if you find that alg.exe is consuming high system resources and you do not use Microsoft Firewall or share files, printers, or resources, then you can safely terminate this process. To do this, perform the following steps:

  1. Press Ctrl+Alt+Del
  2. Click the Processes tab in the Windows Task Manager window.
  3. Locate and click alg.exe to select it.
  4. Click the End Process button.
  5. Close the Windows Task Manager window.

Please note, if you use the services that alg.exe provides but terminate the process, you will lose connection to the Internet. In such a case, simply restart your Windows computer. When you restart your computer, the alg.exe service will be automatically restored.

Alg.exe – Can you trust the file?

The true alg.exe is a safe Windows file and its default location is C:\Windows\System32\alg.exe. However, many malware programs, such as virus, spyware, and trojans are known to use a process by a similar name.

Typically, if alg.exe is present in its default location then it is a safe file. In case you notice instances of alg.exe in other locations, chances are your PC is infected.

If you are concerned that a rogue alg.exe might be running on your system, then run a malware scan on your entire computer using reliable antimalware tools, such as STOPzilla Antivirus and Spyware Cease. If instances of malicious alg.exe are found, then promptly remove them.

At this point, it is recommended that you also clean your registry using advanced registry cleaning software, such as RegServe. Often, malicious programs add invalid and corrupt entries into the registry. These invalid or corrupt registry entries, in turn, may cause various errors or issues if they are not removed. 

For your reference, we have listed the name of internet threats that are known to use alg.exe:

Generic.dx [McAfee]
Backdoor.Bifrose [Symantec]
Backdoor.Graybird [Symantec]
Backdoor.Trojan [Symantec]
Backdoor.Win32.Hupigon.axbr [Kaspersky Lab]
Backdoor.Win32.Hupigon.nqr [Kaspersky Lab]
Backdoor:Win32/Bifrose.gen!E [Microsoft]
Downloader [Symantec]
BackDoor-AWQ.g [McAfee]
Downloader-BLE!a [McAfee]
Exploit.IMG-WMF [PC Tools]
Exploit.IMG-WMF!sd6 [PC Tools]
Mal/Hupig-E [Sophos]
Mal/Generic-A [Sophos]
Mal/Bifrose-I [Sophos]
Mal/Behav-204 [Sophos]
Mal/Behav-009 [Sophos]
Hacktool [Symantec]
Generic Dropper.ex [McAfee]
Generic Dropper [McAfee]
Trojan Horse [Symantec]
Troj/PWS-AXY [Sophos]
Suspicious.MH690 [Symantec]
PWS-Mmorpg.gen [McAfee]
PWS:Win32/Hupigon.gen!F [Microsoft]
Packed.Generic.181 [Symantec]
Mal/Packer [Sophos]
Exploit:Win32/MS08067 [Microsoft]
Exploit.Win32.IMG-WMF.fk [Kaspersky Lab]
Exploit.Win32.IMG-WMF.ex [Kaspersky Lab]
Exploit.Win32.IMG-WMF [Ikarus]
Trojan.StartPage.AKF [PC Tools]
Trojan.VBS.StartPage.bv [Ikarus]
Trojan.Win32.StartPage [Ikarus]
Trojan.Zlob [Ikarus]
Trojan:Win32/Meredrop [Microsoft]
Trojan-Downloader.Win32.Agent.mis [Kaspersky Lab]
Trojan-Dropper.Agent [Ikarus]
Trojan-Dropper.Agent [PC Tools]
Trojan-Dropper.Agent!sd6 [PC Tools]
Trojan-Dropper.Win32.Agent.aeok [Kaspersky Lab]
Trojan-GameThief.Win32.OnLineGames [Ikarus]
Win-Trojan/Xema.variant [AhnLab]
Win-Trojan/StartPage.21192 [AhnLab]
Win-Trojan/ExploitTool.3740 [AhnLab]
Win-Trojan/Agent.18829.C [AhnLab]
Win32.DL.Agent.CXPL [PC Tools]
W32/Tufik [McAfee]
W32.SillyFDC [Symantec]
W32.IRCBot [Symantec]
Trojan-PWS.Win32.Delf [Ikarus]
Trojan-GameThief.Win32.OnLineGames.uqkb [Kaspersky Lab]
Trojan-GameThief.Win32.OnLineGames.upyj [Kaspersky Lab]
Trojan-GameThief.Win32.OnLineGames.bkrt [Kaspersky Lab]