tskmgr32.vbs - Dangerous
%sysdir%\tskmgr32.vbs
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
1. Uninstalls any process that contains the strings "Script" and "Block" in its name.
2.Drops and executes %System%\Tskmgr32.vbs to terminate any process named Taskmgr.exe.
3.Drops and executes the following files:
* %System%\User32.reg
* %System%\SysReg.reg
4. Creates the following copies of itself:
* %System%\MsNews.vbs
* %Windir% \SysLogs\Syslog32.vbs
* %ProgramFiles%\WindowsUpdate\Wupdmgr.tmp\Wupdscn.vbs
5. Adds the value:
"Spore" = "%System%\MsNews.vbs"
to Windows startup registry keys.
6. Adds the value:
"DisallowRun" = "1"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Adds the values:
"1" = "regedit.exe"
"2" = "notepad.exe"
"3" = "wordpad.exe"
"4" = "write.exe"
"5" = "wuauclt.exe"
to the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
to block execution of this files.
Remove it using Startup Optimizer.