test.exe - Dangerous
%sysdir%\test.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
Test.exe opens a back door on TCP port 6677.
Test.exe spreads via open network shares.
Test.exe tries to terminate antiviral programs installed on a user computer.
Test.exe monitors user Internet activity and private information.
It sends stolen data to a hacker site.
Related files:
%System%\svthx.exe
%System%\Test
%System%\Test.exe
%System%\Test.pif
%System%\haha.pif
%System%\Details.pif
%System%\Decrypted_mail.pif
%System%\Instructions-howtofix.txt.pif
%System%\Protected.Storage.Encrypted.XOR.34h.pif
Adds the value:
"Windows Update Center" = "%System%\svthx.exe"
"Shell" = "Explorer.exe svthx.exe"
to the Windows startup registry keys.
Removal:
Kill Test.exe process and remove Test.exe from Windows startup.