mssyncr.exe - Dangerous
%sysdir%\mssyncr.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
Copy his body to files:
%System%\mssyncr.exe
%Windir%\services.exe
Uses Active Setup key to autostartup.
"StubPath = %system%\mssyncr.exe"
Key:
HKM\SOFTWARE\Microsoft\Active Setup\Installed Components\{44AC6201-B203-10CC-1f32-A0BC12E2014D}
Adds the value:
"LoginSessionDisable" = "1"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RAS Autodial\Control
to prevent the Trojan from causing the system to dial to an ISP.
- Downloads a web page from the domain, microsoft.com, to verify that it is connected to the Internet.
Next, the Trojan attempts to download and execute files from the following domains:
geocities.com
cruel-intentionz.net
Remove it from startup,
go to the
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RAS Autodial\Control\"LoginSessionDisable".
Set default value to "".