sysinit.exe - Dangerous
%sysdir%\sysinit.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
Spreads through file-sharing networks and by e-mail.
1. Adds to Windows startup.
"Syskey" = "%System%\sysinit.exe"
2.Creates the following files:
%System%\sysinit.exe
%System%\sysinit.exeopen
%System%\sysinit.exeopenopen
%System%\sysinit.exeopenopenopen
%System%\sysinit.exeopenopenopenopen
3. Kills antiviruses.
4.Opens a backdoor on TCP port 2002.
5.Sends an HTTP GET request via TCP port 80 to the domain, webnomey.net, where it attempts to contact a .php script.
6.Attempts to download a file from the domain sash.cc and save it as 1.exe. This file is then executed.
Remove it from startup using RegRun Startup Optimizer.