kgzgjkpcw.exe - Dangerous

kgzgjkpcw.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

kgzgjkpcw.exe
Backdoor.Sdbot.T is a backdoor Trojan horse that is similar to Backdoor.Sdbot.S.
It allows an attacker to control an infected computer.

Copies itself as %System%\kgzgjkpcw.exe and %System%\zonealarm.exe.

Adds the value: "Winsock2 driver"="kgzgjkpcw.exe"
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Adds the value: "Winsock2 driver"="ZONEALARM.EXE" (It is not valid file name of ZONEALARM antiviral program)
to the registry keys:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Attempts to end the following processes: Netstat.exe; Msconfig.exe; Regedit.exe
Uses its own IRC client to connect to a specified IRC channel and wait for the commands to perform different actions.

Use RegRun Startup Optimizer to automatically remove this trojan.

Remove kgzgjkpcw.exe now!